mirror of
https://github.com/tiennm99/store-scraper-bot.git
synced 2026-10-11 03:13:50 +00:00
- pin form-data/qs/tough-cookie via package.json overrides; clears 3 of 4 Dependabot alerts (request SSRF risk-accepted, no upstream fix) - add GitHub Actions CI (lint + syntax check) on push/PR - add /settings and /setdayswarning to setMyCommands - new npm run describe sets bot profile description via Bot API - README: drop stale preview warning, add Operations section
2.1 KiB
2.1 KiB
phase, title, status, priority, effort, dependencies
| phase | title | status | priority | effort | dependencies |
|---|---|---|---|---|---|
| 2 | CI workflow on PR/push | completed | P2 | 30m |
Phase 2: CI workflow on PR/push
Overview
Add a single GitHub Actions workflow running on PR + push: npm ci, secret-leak lint, and node --check on every .js file. No tests exist yet so no test job. Cheap signal that someone's commit at least parses + doesn't add secrets.
Architecture
One workflow file, single job, two minutes max runtime. Use Node 20 (matches engines.node in package.json). Cache npm via actions/setup-node@v4's built-in cache.
Related Code Files
Create
.github/workflows/ci.yml
Implementation Steps
- Create
.github/workflows/ci.yml:name: CI on: push: branches: [main] pull_request: jobs: verify: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 20 cache: npm - run: npm ci - run: npm run lint - name: Syntax check all JS run: find api scripts src -name '*.js' -print0 | xargs -0 -n1 node --check - Commit + push → confirm green run in Actions tab.
- Add a status badge to README (optional, low value — skip unless trivial).
Success Criteria
- Workflow file present at
.github/workflows/ci.yml - First run on push to
mainis green - PRs show CI status check
- Job completes < 2 minutes
Risk Assessment
- Bundle-size gate dropped: original todo asked for "lint + bundle-size as PR check". Bundle size mattered when target was Cloudflare Workers (1MB script limit). On Vercel serverless, 250MB unzipped limit makes bundle size irrelevant. Skipped — YAGNI.
findpath coverage: if a future top-level dir is added, the syntax check misses it. Mitigation: documented in workflow comment to update the find roots when adding new dirs. Acceptable — no current dynamism in repo layout.npm cislowness: mitigated by built-in npm cache. Cold runs ~30s, warm <10s.