Skip to content

ci: improve ci release - #715

Merged
Brentlok merged 2 commits into
mainfrom
fix/ci-release
Oct 5, 2026
Merged

Brentlok merged 2 commits into
mainfrom
fix/ci-release

Conversation

@Brentlok

@Brentlok Brentlok commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • Bug Fixes
    • Deferred stylesheet scans now stop safely if the document is no longer available, preventing subscriber notifications during teardown.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (2)
AGENTS.md — auto-discovered
CONTEXT.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c86721a3-fbae-4b53-abdc-e17b23a32f0d
📥 Commits

Reviewing files that changed from the base of the PR and between 9224f71 and 93e80c7.

📒 Files selected for processing (4)
  • .github/workflows/release.yaml
  • CONTEXT.md
  • packages/uniwind/src/core/web/cssListener.ts
  • packages/uniwind/tests/web/core/css-listener.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The changes guard deferred CSSListener scans when document is unavailable. They also update the release workflow’s linting, formatting, and release commands, and document the release process.

Changes

CSSListener document-removal guard

Layer / File(s) Summary
Guard deferred scans when document is unavailable
packages/uniwind/src/core/web/cssListener.ts, packages/uniwind/tests/web/core/css-listener.test.ts, CONTEXT.md
CSSListenerBuilder.initialize returns when document is unavailable. Tests cover pending scans scheduled by timeout and idle callback. The documentation describes this behavior.

Release workflow updates

Layer / File(s) Summary
Update release checks and command
.github/workflows/release.yaml, CONTEXT.md
The workflow runs linting and formatting as separate steps, invokes the release command with Bun, and disables Husky for that step. The documentation describes the release checks and process.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: jpudysz

Merge Risk: ⚪ Minimal · up to 93e80

Deferred scans exit safely after document teardown, and the release command resolves to the package’s release script. No concrete merge-blocking risk remains in the reviewed changes.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 93e80

The release retains the same publisher and permissions, with explicit validation before publishing. The CSS change stops deferred work when the document is unavailable. No material security risk was found to be introduced or worsened by these changes.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The release path retains authority to publish the public npm package and write GitHub releases and issue state. Its npm-publish environment and contents, identity-token, issues and pull-request permissions are unchanged by the workflow diff.

Security Findings and Attack Paths

  • inferred — The compared CSS change does not expand attacker-controlled stylesheet reachability: it adds an early exit without changing stylesheet discovery, rule processing or public callers.

Trust Boundaries and Controls

  • observed — HUSKY is disabled only for the release step. The tracked pre-commit hook runs repository validation tasks; explicit workflow gates cover their lint, type, circular-dependency, test and formatting dependencies before publishing. This removes commit-time repetition, not those pre-release gates.

Resilience and Maintainability Implications

  • inferred — The teardown guard improves containment of deferred work without introducing a new state transition or ownership transfer. Later observer-driven scheduling remains possible, but automatic recovery after document restoration without another observed mutation is not established.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title identifies the release workflow changes, but it does not mention the CSSListener fix. It still describes a real part of the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium risk] Adjusts CI release workflow and adds document teardown safety.

The PR appears safe to merge based on the paths reviewed.

What we checked:

  • Release script resolves in the package: The step runs in packages/uniwind, whose release script invokes release-it.

Summary

The release workflow now checks formatting separately and runs the package release script through Bun with Husky disabled. Delayed CSS scans also stop when document is gone, with coverage for both timeout and idle-callback scheduling.

  • The release-flow notes now describe the release steps and when pending issues are closed.
  • The CSS listener returns before scanning stylesheets if teardown has removed document.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Stylesheet changes] --> B[Schedule CSS scan]
  B --> C{Document exists?}
  C -- No --> D[Stop scan]
  C -- Yes --> E[Scan stylesheets]
  E --> F[Notify subscribers when new styles arrive]
Loading

Reviews (1) · Last reviewed commit: "chore: guard css listener failing in uni..."

@Brentlok
Brentlok merged commit 228093c into main Oct 5, 2026
3 checks passed
@Brentlok
Brentlok deleted the fix/ci-release branch October 5, 2026 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant