CI: catch a dependency that the Docker image would drop, before the merge - #825
Merged
Merged
Conversation
…erge js-yaml 5 (#809) passed every PR check and crash-looped the image: the runtime stage ships only the hoisted node_modules, and npm had nested the backend's copy under packages/backend/node_modules. - scripts/check-runtime-deps.mjs (+ test), run in the backend job on every PR: fails when the lockfile nests a backend production dependency. - Dockerfile: the prod-deps stage fails the build on a nested package, instead of producing an image that cannot boot. - The Docker build + boot job now also runs on pull requests that change package.json, package-lock.json, the Dockerfile, start.sh or Prisma. - server-picker.spec: the 'no user id in the form' check also searched the random CSRF token, which contains 'u1' in about 1% of runs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #824. js-yaml 5 (#809) passed every PR check and then crash-looped the image, because the runtime stage ships only the hoisted
node_modulesand npm had nested the backend's copy underpackages/backend/node_modules. Three layers so it can't happen quietly again:scripts/check-runtime-deps.mjs(+ node test), run in the backend job on every PR. It fails whenpackage-lock.jsonnests a backend production dependency. On main it passes; on the chore(deps): bump js-yaml from 4.3.2 to 5.4.1 #809 lockfile it fails with[email protected].Dockerfile: thebackend-prod-depsstage fails the build when anything other than.binlands inpackages/backend/node_modules. Checked locally: the stage builds with main's lockfile and stops with "Nested backend dependencies would be missing from the image: js-yaml" with chore(deps): bump js-yaml from 4.3.2 to 5.4.1 #809's./health) now also runs on pull requests that changepackage.json,package-lock.json,Dockerfile,.dockerignore,start.shor the Prisma schema/config. Other PRs skip it in the first step, so they don't pay the extra ten minutes. This PR changes the Dockerfile, so the job runs on it.Also fixes a flaky test:
server-picker.specchecked that the rendered form doesn't contain the test user idu1, but the search included the random CSRF token, which containsu1in about 1% of runs. It failed main's CI on #824 that way.