Repository navigation
chore: post-wave cleanup — fix CI, remove dead code, repair tests - #892
Merged
Merged
Conversation
…indings package-lock.json was mangled by a bad merge (124 duplicate package keys, esbuild's `os: ["sunos"]` spliced into safe-buffer), so `npm ci` failed with EBADPLATFORM on every CI run since the wave merged. Regenerated it cleanly. - Resolve the vite peer conflict properly instead of --legacy-peer-deps: pin vite ^7, keep @vitejs/plugin-react ^4.7 (supports vite 7) - vitest/@vitest/coverage-v8 2.x -> 4.1.11 (critical path traversal advisories) - next 16.2.6 -> 16.3.8 (critical advisory) - lint-staged 15 -> 17 (drops vulnerable micromatch/braces) - shadcn moved to devDependencies: only its CSS is imported at build time Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- ci.yml: single `npm ci` (the extra `npm ci --legacy-peer-deps` step was redundant). Drop `playwright test --update-snapshots` + the auto-commit/push step: it overwrote baselines on every run (so visual tests could never fail) and pushed from CI. Screenshot assertions are skipped only while no baseline PNGs are committed; generate them with the Update Playwright Snapshots workflow. - update-snapshots.yml: grant contents: write, and drop the manual `npm run start &` that collided with Playwright's own webServer on :3000. - security.yml: give the frontend job pull-requests: write and make the summary comments best-effort (they failed with "Resource not accessible by integration", failing the scan). Gate npm audit on high+ in production deps and critical anywhere; dev tooling carries a braces advisory with no patch. - staging.yml: skip Vercel steps when VERCEL_TOKEN is unavailable (fork and Dependabot PRs) so the build check still runs instead of always failing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A contributor added `nativeButton={false}` to every `<Button asChild><Link>`
to silence a Base UI dev warning, which gave all those links role="button"
(an accessibility regression that broke ~25 tests). Instead, the asChild path
now applies the button styles to the child directly, so links stay links and
there is nothing for Base UI to warn about. Removes the workaround everywhere.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…t APIs - Delete 4 test files under components/ written for Jest (jest.fn, no imports). Vitest only collects __tests__/**, so they never ran, and they contributed ~270 TypeScript errors. Navbar is already covered in __tests__. - Delete stories for AccessibleUnlockAmount, FeeEstimateDialog and Select: they pass props those components don't have, so they rendered broken. - Fix type errors in the remaining stories (default `target` arg for the countdown metas, real CreateStreamInput/TokenInfo shapes). TypeScript errors: 346 -> 0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CI never got past `npm ci`, so these were merged failing: - dashboard: mock useHiddenStreams with the new pinnedIds - stream-detail: page unwraps params with use(); render inside Suspense with an awaited act() - analytics: the dynamic() stub JSON.stringified BigInt props; pin Date to the fixtures' NOW_SEC; locate stat cards via data-slot="card" - qr-share-dialog: vi.hoisted for mock fns; query portal content via screen - webhook-settings: partial-mock stream-utils; fixtures need `secret` - settings: mock UsdToggle at its real path; disambiguate heading - hero / gantt: scope queries to avoid duplicate matches - dropdown-menu: a render-prop <a> menu item correctly has role="menuitem" - live-stream-preview: progress is quantized to 0.01%; advance 1h not 10s Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…secret - The @sentry/nextjs 8 -> 10 upgrade stopped loading sentry.server/edge configs (v10 only initialises through instrumentation.ts), silently disabling server error reporting. Add the standard instrumentation hook. - Webhooks saved before HMAC signing have no `secret`, so deliveries were signed with the literal key "undefined". Backfill a generated secret on load. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Renumber colliding ADRs (two 008s, three 009s) to 011-013 and update refs - Document Node.js 22.22+ (required by Next 16, vitest 4, lint-staged 17) - Stop tracking tsconfig.tsbuildinfo (build cache, already gitignored) - Un-ignore test snapshot files: ignoring them makes snapshot tests regenerate silently and never fail - ESLint: ignore coverage/ output Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
🛡️ Frontend Security Scannpm auditESLintHardcoded secrets check |
🔐 Contract Security Scancargo auditSoroban pattern check |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CI has failed on every merge since the Sep 24–28 contribution wave. A bad merge corrupted
package-lock.json, sonpm cidied before tests, build or audits could run. Broken code went in unnoticed as a result. This PR fixes that and cleans up what the wave left behind.Why CI was red
os: ["sunos"]was spliced intosafe-buffer, which causedEBADPLATFORMin every job. I regenerated the lockfile. The vite peer conflict is now resolved properly (vite ^7,@vitejs/plugin-react^4.7), so nothing needs--legacy-peer-deps.Harmful / incorrect changes reverted or fixed
<Button asChild><Link>gotrole="button".nativeButton={false}was added everywhere to silence a Base UI warning, an accessibility regression.Buttonnow styles the child directly instead.playwright test --update-snapshotsand then committed and pushed from CI, so visual regression tests could never fail.instrumentation.ts."undefined". They have nosecret, so a secret is now backfilled on load..gitignoreignored test snapshot files, so snapshot tests would regenerate silently instead of failing.Dead code removed
components/(jest.fn, no imports). Vitest only runs__tests__/**, so they never executed, and they caused ~270 type errors.tsconfig.tsbuildinfo, a build cache.Dependencies
shadcnmoved to devDependencies, since only its CSS is imported at build time.Workflow changes
npm ci. Screenshot assertions are skipped only while no baseline PNGs are committed.contents: writeand removed a duplicate server start that collided with Playwright'swebServeron :3000.bracesadvisory with no patched release upstream, so the old gate couldn't pass.VERCEL_TOKENis unavailable (fork and Dependabot PRs), so the build check still runs.Other
Verification (local, clean
npm ci)tsc --noEmit: 0 errors (was 346)npm test: 106 files, 1368 tests passingnpm run lint: 0 errorsnpm run build: passesnpm audit --omit=dev --audit-level=highandnpm audit --audit-level=critical: passscripts/check-secrets.mjs: passesFollow-ups for the maintainer
VERCEL_TOKEN/VERCEL_ORG_ID/VERCEL_PROJECT_IDif staging deploys are wanted.useActivityFeed,useBatchCreateanduseTokenVerificationare unused outside tests. This predates the wave, so I left them in.🤖 Generated with Claude Code