Skip to content

ci: share development and CI tool version pins (ALIEN-1211) - #845

Merged
lilienblum merged 6 commits into
mainfrom
lilienblum/alien-1211-ci-tool-versions
Oct 4, 2026
Merged

lilienblum merged 6 commits into
mainfrom
lilienblum/alien-1211-ci-tool-versions

Conversation

@lilienblum

@lilienblum lilienblum commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

CI currently repeats JavaScript versions and installs floating Rust channels, allowing development and CI to use different tools. Add repository mise configuration, read pnpm from package.json, and pin the default Rust compiler to nightly-2026-10-03 in rust-toolchain.toml. CI reads these same files. Named profiles retain stable Python-wheel builds and the Rust 1.97.1 permission compiler.

Cache Node/pnpm/Bun tools separately from Rust installation records, keep Rust tool installation uncached, and include compiler configuration in compiled-binary cache keys. Use exported tool paths without shims so later steps retain the selected compiler profile. Mise installs Node once; setup-node only supplies pnpm dependency caching or npm registry authentication.

Tool configuration changes trigger the relevant Rust, TypeScript, example, and Python checks. Release and npm dev jobs read pins from the workflow revision when packaging an older source commit, and pass the stable compiler explicitly to manylinux wheel builds.

Validation: installed and executed the configured tools and every Rust profile, checked environment export and cache directory separation, parsed all workflow/composite/config files, and ran actionlint with no new findings compared with main. Existing application and compilation caches remain in place. Verified setup-node v4 and v7 preserve mise Node 22/24 without downloading Node or changing PATH, while registry authentication still works. All existing cache and registry inputs remain intact. Hosted CI exercises the full builds.

ALIEN-1211

Use jdx/mise-action@v5 by explicit maintainer choice, allowing upstream v5 updates. Tool versions remain pinned in repository configuration.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T04:52:43.056804Z eea8967 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Replaces tool version management across CI and local development.

The PR appears safe to merge based on the reviewed changes.

Summary

The PR moves CI and development tool selection into shared mise and Rust configuration, separates tool caches, and uses the workflow revision’s pins for release builds.

  • The latest changes pin mise-action to an immutable commit and stop setup-node from installing Node a second time.
  • All four previous Greptile threads are resolved; no new actionable issue was established.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  Config["mise.toml and Rust profiles"] --> Mise["mise-action"]
  Mise --> Tools["Node, pnpm, Bun and Rust on PATH"]
  Tools --> CI["CI checks and release builds"]
  Tools --> SetupNode["setup-node: pnpm cache and npm authentication"]
Loading

Reviews (3) · Last reviewed commit: "ci: pin mise-action to its reviewed rele..."

Comment thread mise.stable.toml Outdated
Comment thread .github/workflows/release.yml
Comment thread .github/workflows/python-bindings.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eea896725d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/publish-npm-dev.yml Outdated
@lilienblum

Copy link
Copy Markdown
Contributor Author

@greptile review

Please review the current head c80030f. The earlier findings have fixing-commit and validation replies, and their threads are resolved.

Comment thread .github/workflows/egress-deny-guard.yml
@lilienblum

Copy link
Copy Markdown
Contributor Author

@greptile review

Please review the prepared head 8454d97. The action-pinning finding is fixed and its thread has a fixing-commit and validation reply.

Use the v5 action tag as explicitly requested.
Keep shared tool-version pins and existing cache settings.
@lilienblum
lilienblum merged commit 43d439e into main Oct 4, 2026
28 checks passed
@lilienblum
lilienblum deleted the lilienblum/alien-1211-ci-tool-versions branch October 4, 2026 09:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant