From aa0ae5feb1b8c4429130e9d4909a840b7bb48466 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Thu, 8 Oct 2026 22:26:55 +0000 Subject: [PATCH 1/2] ci: run prebuilds on pull requests Move the native prebuild jobs into a Build workflow that runs on every pull request and on master and backport pushes. Publish calls that workflow for release tags, then publishes the artifacts. Name the Build, Publish, and Tests workflows so they show up in the Actions list. Co-authored-by: Jon Ursenbach --- .github/workflows/build.yml | 112 ++++++++++++++++++++++++++++++++++ .github/workflows/publish.yml | 108 ++------------------------------ .github/workflows/tests.yml | 2 + CLAUDE.md | 5 +- 4 files changed, 122 insertions(+), 105 deletions(-) create mode 100644 .github/workflows/build.yml diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml new file mode 100644 index 000000000..aa26ba33f --- /dev/null +++ b/.github/workflows/build.yml @@ -0,0 +1,112 @@ +name: Build + +on: + pull_request: + push: + branches: + - master + - backport/* + workflow_call: + +jobs: + build: + name: build + strategy: + matrix: + node: [22, 24, 26] + os: + # https://github.com/actions/runner-images#available-images + - name: darwin + host: macos-26 #arm64 + + # macos-15-intel is the last intel image and will go out of service + # in fall 2027 + - name: mac-x64 + host: macos-15-intel + + # ubuntu-22.04 is x86 + - name: linux + host: ubuntu-22.04 + + - name: linux-arm + host: ubuntu-22.04-arm + env: + CC: clang + CXX: clang++ + npm_config_clang: 1 + GYP_DEFINES: use_obsolete_asm=true + runs-on: ${{ matrix.os.host }} + steps: + - uses: actions/checkout@v5 + with: + submodules: true + - uses: actions/setup-node@v6 + with: + node-version: ${{ matrix.node }} + check-latest: true + - name: Prebuildify + run: | + if [[ $(uname -o) == *Linux ]]; then + sudo apt-get update + sudo apt-get install -y software-properties-common git build-essential clang libssl-dev libkrb5-dev libc++-dev wget python3 zlib1g-dev lsb-release gnupg + # Node 24+ headers use C++20 std::source_location, which needs + # clang >= 16; ubuntu 22.04 ships clang 14. Stay on 22.04 (rather + # than a newer runner) to keep the glibc 2.35 prebuild baseline. + wget https://apt.llvm.org/llvm.sh + chmod +x llvm.sh + sudo ./llvm.sh 18 + export CC=clang-18 + export CXX=clang++-18 + fi + + npm ci + JOBS=2 npx prebuildify --strip --napi=false --tag-libc -t "$(node --version | tr -d 'v')" + - uses: actions/upload-artifact@v4 + with: + name: prebuild-${{ runner.os }}-${{ runner.arch }}-node${{ matrix.node }} + path: ./prebuilds + retention-days: 14 + + # musl build still needs QEMU since there are no native Alpine/musl runners + cross-compile-musl-amd64: + name: "cross compile linux/amd64-musl" + runs-on: ubuntu-22.04 + strategy: + matrix: + node: [22, 24, 26] + steps: + - uses: actions/checkout@v5 + - uses: docker/setup-qemu-action@v3 + - name: build linux musl amd64 + run: | + docker build --platform=linux/amd64 --build-arg NODE_VERSION=${{ matrix.node }} --tag nodegit-linux-musl-amd64-node${{ matrix.node }} -f scripts/Dockerfile.alpine . + docker create --platform=linux/amd64 --name nodegit-linux-musl-amd64-node${{ matrix.node }} nodegit-linux-musl-amd64-node${{ matrix.node }} + docker cp "nodegit-linux-musl-amd64-node${{ matrix.node }}:/app/prebuilds" . + - name: "list the generated files" + run: find prebuilds + - uses: actions/upload-artifact@v4 + with: + name: prebuild-linux-musl-amd64-node${{ matrix.node }} + path: ./prebuilds + retention-days: 14 + + cross-compile-musl-arm64: + name: "build linux/arm64-musl" + runs-on: ubuntu-22.04-arm + strategy: + matrix: + node: [22, 24, 26] + steps: + - uses: actions/checkout@v5 + - name: build linux musl arm64 + run: | + docker build --platform=linux/arm64 --build-arg NODE_VERSION=${{ matrix.node }} --tag nodegit-linux-musl-arm64-node${{ matrix.node }} -f scripts/Dockerfile.alpine . + docker create --platform=linux/arm64 --name nodegit-linux-musl-arm64-node${{ matrix.node }} nodegit-linux-musl-arm64-node${{ matrix.node }} + docker cp "nodegit-linux-musl-arm64-node${{ matrix.node }}:/app/prebuilds" . + - name: "list the generated files" + run: find prebuilds + - uses: actions/upload-artifact@v4 + with: + name: prebuild-linux-musl-arm64-node${{ matrix.node }} + path: ./prebuilds + retention-days: 14 diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index e4cb0afbb..e4a19ff35 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,3 +1,5 @@ +name: Publish + on: push: tags: @@ -6,113 +8,13 @@ on: jobs: build: - # TODO: should we run the tests, or can we assume that a v* tag ought to - # get published? - name: build - strategy: - matrix: - node: [22, 24, 26] - os: - # https://github.com/actions/runner-images#available-images - - name: darwin - host: macos-26 #arm64 - - # macos-15-intel is the last intel image and will go out of service - # in fall 2027 - - name: mac-x64 - host: macos-15-intel - - # ubuntu-22.04 is x86 - - name: linux - host: ubuntu-22.04 - - - name: linux-arm - host: ubuntu-22.04-arm - env: - CC: clang - CXX: clang++ - npm_config_clang: 1 - GYP_DEFINES: use_obsolete_asm=true - runs-on: ${{ matrix.os.host }} - steps: - - uses: actions/checkout@v5 - with: - submodules: true - - uses: actions/setup-node@v6 - with: - node-version: ${{ matrix.node }} - check-latest: true - - name: Prebuildify - run: | - if [[ $(uname -o) == *Linux ]]; then - sudo apt-get update - sudo apt-get install -y software-properties-common git build-essential clang libssl-dev libkrb5-dev libc++-dev wget python3 zlib1g-dev lsb-release gnupg - # Node 24+ headers use C++20 std::source_location, which needs - # clang >= 16; ubuntu 22.04 ships clang 14. Stay on 22.04 (rather - # than a newer runner) to keep the glibc 2.35 prebuild baseline. - wget https://apt.llvm.org/llvm.sh - chmod +x llvm.sh - sudo ./llvm.sh 18 - export CC=clang-18 - export CXX=clang++-18 - fi - - npm ci - JOBS=2 npx prebuildify --strip --napi=false --tag-libc -t "$(node --version | tr -d 'v')" - - uses: actions/upload-artifact@v4 - with: - name: prebuild-${{ runner.os }}-${{ runner.arch }}-node${{ matrix.node }} - path: ./prebuilds - retention-days: 14 - - # musl build still needs QEMU since there are no native Alpine/musl runners - cross-compile-musl-amd64: - name: "cross compile linux/amd64-musl" - runs-on: ubuntu-22.04 - strategy: - matrix: - node: [22, 24, 26] - steps: - - uses: actions/checkout@v5 - - uses: docker/setup-qemu-action@v3 - - name: build linux musl amd64 - run: | - docker build --platform=linux/amd64 --build-arg NODE_VERSION=${{ matrix.node }} --tag nodegit-linux-musl-amd64-node${{ matrix.node }} -f scripts/Dockerfile.alpine . - docker create --platform=linux/amd64 --name nodegit-linux-musl-amd64-node${{ matrix.node }} nodegit-linux-musl-amd64-node${{ matrix.node }} - docker cp "nodegit-linux-musl-amd64-node${{ matrix.node }}:/app/prebuilds" . - - name: "list the generated files" - run: find prebuilds - - uses: actions/upload-artifact@v4 - with: - name: prebuild-linux-musl-amd64-node${{ matrix.node }} - path: ./prebuilds - retention-days: 14 - - cross-compile-musl-arm64: - name: "build linux/arm64-musl" - runs-on: ubuntu-22.04-arm - strategy: - matrix: - node: [22, 24, 26] - steps: - - uses: actions/checkout@v5 - - name: build linux musl arm64 - run: | - docker build --platform=linux/arm64 --build-arg NODE_VERSION=${{ matrix.node }} --tag nodegit-linux-musl-arm64-node${{ matrix.node }} -f scripts/Dockerfile.alpine . - docker create --platform=linux/arm64 --name nodegit-linux-musl-arm64-node${{ matrix.node }} nodegit-linux-musl-arm64-node${{ matrix.node }} - docker cp "nodegit-linux-musl-arm64-node${{ matrix.node }}:/app/prebuilds" . - - name: "list the generated files" - run: find prebuilds - - uses: actions/upload-artifact@v4 - with: - name: prebuild-linux-musl-arm64-node${{ matrix.node }} - path: ./prebuilds - retention-days: 14 + uses: ./.github/workflows/build.yml # https://docs.npmjs.com/generating-provenance-statements#publishing-packages-with-provenance-via-github-actions publish: + name: publish runs-on: ubuntu-latest - needs: [build, cross-compile-musl-amd64, cross-compile-musl-arm64] + needs: build permissions: id-token: write contents: read diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 8823031fd..3ed6f4f0e 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -1,3 +1,5 @@ +name: Tests + on: push: branches: diff --git a/CLAUDE.md b/CLAUDE.md index 907ada858..2c37f0893 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -101,8 +101,9 @@ Tests are located in: ## CI/CD GitHub Actions workflows: -- **tests.yml**: Runs tests on Ubuntu 22.04 and macOS-26 across Node 22, 24, and 26 -- **publish.yml**: Handles package publishing +- **build.yml** (Build): Builds native prebuilds for Node 22, 24, and 26 on every pull request and on pushes to `master` and `backport/*` +- **tests.yml** (Tests): Runs tests on Ubuntu 22.04 and macOS-26 across Node 22, 24, and 26 +- **publish.yml** (Publish): Publishes the package for `v*` tags, using the prebuilds from the Build workflow ## Architecture From aea1a1d9acdb56a02beec4a36d088b98904ae46e Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Thu, 8 Oct 2026 22:36:34 +0000 Subject: [PATCH 2/2] ci: upload prebuilds only for publish Pull request and branch builds compile the native binaries and discard them. Publish opts in to artifact upload, so a release cannot pick up a prebuild produced by another run. Co-authored-by: Jon Ursenbach --- .github/workflows/build.yml | 8 ++++++++ .github/workflows/publish.yml | 2 ++ CLAUDE.md | 4 ++-- 3 files changed, 12 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index aa26ba33f..99db278a9 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -7,6 +7,11 @@ on: - master - backport/* workflow_call: + inputs: + upload-artifacts: + description: Upload prebuilds for a release. Pull request runs only compile. + type: boolean + default: false jobs: build: @@ -62,6 +67,7 @@ jobs: npm ci JOBS=2 npx prebuildify --strip --napi=false --tag-libc -t "$(node --version | tr -d 'v')" - uses: actions/upload-artifact@v4 + if: ${{ inputs.upload-artifacts }} with: name: prebuild-${{ runner.os }}-${{ runner.arch }}-node${{ matrix.node }} path: ./prebuilds @@ -85,6 +91,7 @@ jobs: - name: "list the generated files" run: find prebuilds - uses: actions/upload-artifact@v4 + if: ${{ inputs.upload-artifacts }} with: name: prebuild-linux-musl-amd64-node${{ matrix.node }} path: ./prebuilds @@ -106,6 +113,7 @@ jobs: - name: "list the generated files" run: find prebuilds - uses: actions/upload-artifact@v4 + if: ${{ inputs.upload-artifacts }} with: name: prebuild-linux-musl-arm64-node${{ matrix.node }} path: ./prebuilds diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index e4a19ff35..13b7ca622 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -9,6 +9,8 @@ on: jobs: build: uses: ./.github/workflows/build.yml + with: + upload-artifacts: true # https://docs.npmjs.com/generating-provenance-statements#publishing-packages-with-provenance-via-github-actions publish: diff --git a/CLAUDE.md b/CLAUDE.md index 2c37f0893..45a8d8e06 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -101,9 +101,9 @@ Tests are located in: ## CI/CD GitHub Actions workflows: -- **build.yml** (Build): Builds native prebuilds for Node 22, 24, and 26 on every pull request and on pushes to `master` and `backport/*` +- **build.yml** (Build): Compiles native prebuilds for Node 22, 24, and 26 on every pull request and on pushes to `master` and `backport/*`. Those runs do not upload artifacts. - **tests.yml** (Tests): Runs tests on Ubuntu 22.04 and macOS-26 across Node 22, 24, and 26 -- **publish.yml** (Publish): Publishes the package for `v*` tags, using the prebuilds from the Build workflow +- **publish.yml** (Publish): Calls the Build workflow with artifact upload enabled, then publishes the package for `v*` tags ## Architecture