Install hygiene #22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Daily zero-warning-install watch on the PUBLISHED package. | |
| # | |
| # The published tarball ships no lockfile, so even with exact-pinned direct | |
| # dependencies the registry can drift under us after a release: a transitive | |
| # dependency gets deprecated (npm prints the deprecation on every user | |
| # install), a platform-specific optional package (@vscode/ripgrep-*) changes, | |
| # or a new npm version alters behavior. None of that touches a file in this | |
| # repo, so no PR or release gate can catch it — only re-verifying the real | |
| # `npm install -g @gitlawb/openclaude@latest` against the live registry does. | |
| # | |
| # The OS matrix matters: each platform resolves a different ripgrep optional | |
| # package, so a Linux-only check is blind to what macOS/Windows users install. | |
| name: Install hygiene | |
| on: | |
| schedule: | |
| - cron: '17 6 * * *' # daily, off the top-of-hour rush | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| verify-published-install: | |
| name: ${{ matrix.os }} / Node ${{ matrix.node-version }} | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, macos-latest, windows-latest] | |
| node-version: [22, 24] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - name: Set up Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| with: | |
| node-version: ${{ matrix.node-version }} | |
| - name: Set up Bun | |
| uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0 | |
| with: | |
| bun-version-file: .bun-version | |
| # The verify script only uses node builtins + scripts/externalsValidation | |
| # (relative import) — no bun install needed, keeping the matrix cheap. | |
| - name: Verify published package installs clean | |
| run: bun run scripts/verify-clean-install.ts --published |