Skip to content

Fix GitHub Actions CI and package/site publishing - #161

Merged
rickmark merged 1 commit into
mainfrom
claude/loving-einstein-agzeu3
Oct 5, 2026
Merged

rickmark merged 1 commit into
mainfrom
claude/loving-einstein-agzeu3

Conversation

@rickmark

@rickmark rickmark commented Oct 5, 2026

Copy link
Copy Markdown
Member

Summary

Fixes the workflows that have been failing on main. Each fix below is matched to the error in its run logs.

Workflow Failure Fix
Periodic Updates idn-ruby failed to build because libidn-dev was missing. The cron * 8 * * * ran every minute of hour 8. On a schedule inputs.ref was empty, and the $GITHUB_OUTPUT syntax was broken. Install libidn-dev/cmake. Use the cron 17 8 * * *. Default the branch to auto-update-bot and fix the step outputs. Replace the archived repo-sync/pull-request and git-auto-commit-action with peter-evans/create-pull-request. Remove the trailing CI jobs, which only re-tested main. Give the tmp cache a rolling key.
Static Website asn_parser failed with cmake: No such file inside the jekyll-action container Build the site with the reusable build-jekyll.yml on the runner, then deploy the artifact to gh-pages with peaceiris/actions-gh-pages (keeps the CNAME)
Publish NPM Caching for 'bun' is not supported; it also used GITHUB_TOKEN against npmjs.org Drop the cache. Run npm publish on the packed tgz with --provenance, using trusted publishing (id-token: write) or secrets.NPM_TOKEN
Publish PyPI Poetry ran at the repo root. No package-python artifact was ever uploaded. The job didn't depend on the build. build-python.yml now uploads dist/. The publish job needs the build and only downloads and publishes, with id-token: write for trusted publishing.
Python package build = "build.py" produced a linux_x86_64 wheel, which PyPI rejects, and the wheel had no data files Remove the build script (CI already runs build.py). Include share/** in both the sdist and the wheel. The result is a py3-none-any wheel (about 18 MB).
Labeler actions/labeler@v2 runs on Node 12 Move to v5 and the v5 config format

Other changes:

  • The reusable workflows are now called through ./.github/workflows/... instead of hack-different/apple-knowledge/...@main, so a PR's CI runs that PR's own workflow changes.
  • Actions are bumped to their Node 24 majors (checkout/cache/setup-node/upload/download v5, setup-python v6). Redundant manual bundle caches are removed; bundler-cache already covers them.

Setup needed outside the repo

  • PyPI: add a trusted publisher for publish-pypi.yml, environment pypi-push.
  • npm: add a trusted publisher for publish-npm.yml, environment node-push, or add an NPM_TOKEN secret.
  • Update PRs: turn on Settings → Actions → Allow GitHub Actions to create and approve pull requests. PRs opened with GITHUB_TOKEN don't trigger CI on their own.

Testing

  • actionlint passes on every workflow.
  • Python locally: update_version.py, poetry install, build.py, pytest (3 passed) and poetry build all ran. The wheel installs into a clean venv and apple_data.get_data('apns') loads.
  • Node locally: bun install, bun run build, bun run test (4 passed) and bun pm pack all ran.

🤖 Generated with Claude Code

https://claude.ai/code/session_01A7iNWzEEZrwfmb3a8J3F7L


Generated by Claude Code

- Use local reusable workflow refs so PRs test their own workflow changes
- Periodic update: run once daily (cron was every minute of hour 8), install
  libidn-dev, fix broken step outputs / empty ref on schedule, replace archived
  repo-sync/pull-request with peter-evans/create-pull-request
- Site: build with setup-ruby on the runner (jekyll-action container lacked
  cmake for asn_parser) and deploy the build artifact to gh-pages
- NPM: drop unsupported `cache: bun`, publish the packed tgz with npm using
  trusted publishing / NPM_TOKEN instead of GITHUB_TOKEN
- PyPI: upload the built dist from CI, depend on the build job, grant
  id-token for trusted publishing; produce a pure wheel that includes data
- Labeler v5 config, bump actions to Node 24 majors

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A7iNWzEEZrwfmb3a8J3F7L
@rickmark
rickmark marked this pull request as ready for review October 5, 2026 16:11
@rickmark
rickmark merged commit 07d13a1 into main Oct 5, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants