Skip to content

CI: catch a dependency that the Docker image would drop, before the merge - #825

Merged
keysersoft merged 2 commits into
mainfrom
keysersoft/ci-runtime-deps-guard
Oct 2, 2026
Merged

keysersoft merged 2 commits into
mainfrom
keysersoft/ci-runtime-deps-guard

Conversation

@keysersoft

Copy link
Copy Markdown
Contributor

Follow-up to #824. js-yaml 5 (#809) passed every PR check and then crash-looped the image, because the runtime stage ships only the hoisted node_modules and npm had nested the backend's copy under packages/backend/node_modules. Three layers so it can't happen quietly again:

  1. scripts/check-runtime-deps.mjs (+ node test), run in the backend job on every PR. It fails when package-lock.json nests a backend production dependency. On main it passes; on the chore(deps): bump js-yaml from 4.3.2 to 5.4.1 #809 lockfile it fails with [email protected].
  2. Dockerfile: the backend-prod-deps stage fails the build when anything other than .bin lands in packages/backend/node_modules. Checked locally: the stage builds with main's lockfile and stops with "Nested backend dependencies would be missing from the image: js-yaml" with chore(deps): bump js-yaml from 4.3.2 to 5.4.1 #809's.
  3. The "Docker build" job (build + boot + /health) now also runs on pull requests that change package.json, package-lock.json, Dockerfile, .dockerignore, start.sh or the Prisma schema/config. Other PRs skip it in the first step, so they don't pay the extra ten minutes. This PR changes the Dockerfile, so the job runs on it.

Also fixes a flaky test: server-picker.spec checked that the rendered form doesn't contain the test user id u1, but the search included the random CSRF token, which contains u1 in about 1% of runs. It failed main's CI on #824 that way.

…erge

js-yaml 5 (#809) passed every PR check and crash-looped the image: the
runtime stage ships only the hoisted node_modules, and npm had nested the
backend's copy under packages/backend/node_modules.

- scripts/check-runtime-deps.mjs (+ test), run in the backend job on
  every PR: fails when the lockfile nests a backend production dependency.
- Dockerfile: the prod-deps stage fails the build on a nested package,
  instead of producing an image that cannot boot.
- The Docker build + boot job now also runs on pull requests that change
  package.json, package-lock.json, the Dockerfile, start.sh or Prisma.
- server-picker.spec: the 'no user id in the form' check also searched the
  random CSRF token, which contains 'u1' in about 1% of runs.
@keysersoft
keysersoft merged commit dea17ce into main Oct 2, 2026
13 checks passed
@keysersoft
keysersoft deleted the keysersoft/ci-runtime-deps-guard branch October 2, 2026 17:03
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 2, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant