-
-
Notifications
You must be signed in to change notification settings - Fork 30
ci: skip native matrices for docs-only changes #363
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
21 commits
Select commit
Hold shift + click to select a range
89b67e0
ci: skip native matrices for docs-only changes
hyochan 217f142
docs(kit): reconcile the IAPKit surface with OpenIAP
hyochan f568614
feat(kit): sunset email sign-in on 2026-09-30
hyochan def1bbe
docs(agents): guard production data and keep agent surfaces in sync
hyochan 11d60e5
docs: correct the alternative billing dialog migration target
hyochan 1621426
fix: address CodeRabbit review on PR #363 and hide announcement thumb…
hyochan cc39276
fix(kit): bind the Apple verify response to the requesting JWS
hyochan 3047861
test(kit): move email sign-in gates into pure, fully covered functions
hyochan d81929b
ci: cancel superseded PR runs of the main CI workflow
hyochan d4d6299
ci: route four mac lanes to a self-hosted runner behind a heartbeat gate
hyochan 78c9aa4
ci: run the mac-runner gate from runner.temp
hyochan 0bf24fb
ci: raise the pinned Xcode toolchain to 26.6 and gate mac routing to PRs
hyochan d816166
ci: move the react-native release lane to Xcode 26.6 as well
hyochan f9b4cdd
ci: let the Mac take the SPM-heavy CodeQL legs as a sixth slot
hyochan ba39e80
ci: restrict Mac routing to the owner's own pull requests
hyochan bb6afd7
test: teach the CodeQL runner guard the owner-gated Mac policy
hyochan 45454ef
ci: keep the CodeQL Swift legs on hosted runners
hyochan 2fe7b11
ci: run Swift CodeQL legs on the Mac by tracing builds, not tests
hyochan 708faa9
ci: send every Swift CodeQL leg to the Mac when it is alive
hyochan 6854111
ci: keep the Mac runner for CodeQL only
hyochan 8ecd30f
ci: run the react-native CodeQL leg with the Mac's own Ruby
hyochan File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,130 @@ | ||
| --- | ||
| name: audit-iapkit | ||
| description: Audit the IAPKit product surface against OpenIAP as the source of truth, then fix the drift it finds. Use when the user asks to check whether IAPKit reflects OpenIAP updates, audit kit docs, or reconcile kit.openiap.dev with openiap.dev. | ||
| --- | ||
|
|
||
| # Audit IAPKit Against OpenIAP | ||
|
|
||
| IAPKit is a deployable SaaS, not a library, so it sits outside the GQL type-sync | ||
| chain that keeps the SDKs aligned. Nothing regenerates its site copy when the | ||
| spec, the stores, or the SDKs move, so its documentation drifts silently. This | ||
| workflow finds that drift and fixes it. | ||
|
|
||
| Read `packages/kit/CONVENTION.md` before editing anything under `packages/kit`. | ||
|
|
||
| ## Direction of truth | ||
|
|
||
| ```text | ||
| OpenIAP spec + packages/kit implementation → IAPKit site copy | ||
| (authoritative) (must follow) | ||
| ``` | ||
|
|
||
| Precedence when surfaces disagree: implementation > `packages/docs` > | ||
| `packages/kit` prose. `packages/docs` outranks kit prose only where the code | ||
| does not decide the question (product positioning, support claims). Never | ||
| "fix" the code to match a doc without saying so explicitly. | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
|
|
||
| ## Workflow | ||
|
|
||
| ```text | ||
| 1. Establish what changed upstream | ||
| ↓ | ||
| 2. Check every prose claim against the implementation | ||
| ↓ | ||
| 3. Check kit against packages/docs for contradictions | ||
| ↓ | ||
| 4. Apply mechanical fixes; escalate product calls | ||
| ↓ | ||
| 5. Verify | ||
| ``` | ||
|
|
||
| ## Steps | ||
|
|
||
| ### 1. Establish what changed upstream | ||
|
|
||
| ```bash | ||
| # Spec and SDK movement since the kit surface was last reviewed. | ||
| git log --oneline -20 -- packages/gql/src/type.graphql openiap-versions.json | ||
| # Least recently reviewed kit files first — that is where drift concentrates. | ||
| for f in $(git ls-files packages/kit/src/pages/docs/sections packages/kit/src/content); do | ||
| echo "$(git log -1 --format='%ad' --date=short -- "$f") $f" | ||
| done | sort | ||
| ``` | ||
|
|
||
| Also check upstream store documentation for anything the kit pages describe: | ||
| App Store Server API, Google Play Developer API, Amazon RVS, Meta Horizon, and | ||
| the Vega SDK release notes. | ||
|
|
||
| ### 2. Check prose against the implementation | ||
|
|
||
| This is the highest-value pass. For every checkable claim on the kit site, find | ||
| the code that implements it and confirm the claim matches. Cite `file:line` for | ||
| both sides. | ||
|
|
||
| Highest-yield targets, in order: | ||
|
|
||
| - **Verification order and cryptography** — `packages/kit/convex/purchases/*.ts`. | ||
| A page saying IAPKit verifies something it does not verify is the worst class | ||
| of error. | ||
| - **Error codes** — confirm each documented code can actually reach a caller. | ||
| Codes raised internally and re-wrapped before the response must not be listed. | ||
| - **Endpoints, fields, and limits** — `packages/kit/server/api/v1/**`, | ||
| especially `route-input-schemas.ts` for which fields are required. A field the | ||
| server requires but the docs call optional makes every following example 400. | ||
| - **Negative verdicts that return 200** — outcomes that are not errors but are | ||
| documented as if they were, or not documented at all. | ||
| - **Numbers** — retry counts, rate limits, size caps, file sizes, retention | ||
| windows. These rot silently; recompute rather than trusting the page. | ||
|
|
||
| ### 3. Check kit against `packages/docs` | ||
|
|
||
| The two sites describe one product. Find statements that contradict each other | ||
| and decide which side is right from the code, then fix the wrong side. | ||
|
|
||
| ```bash | ||
| bun run audit:docs | ||
| ``` | ||
|
|
||
| ### 4. Apply fixes, escalate decisions | ||
|
|
||
| Fix mechanically when the correct text is determined by the code: a wrong fact, | ||
| an unreachable error code, a stale number, a broken link, a naming violation. | ||
|
|
||
| Escalate to the user, do not guess, when the fix requires a product call: | ||
| what the product officially claims to support, support channels, pricing or | ||
| plan statements, legal document content, restructuring a page, or consolidating | ||
| pages that have published URLs. | ||
|
|
||
| Constraints that override any finding: | ||
|
|
||
| - **Production is read-only.** Never run a mutation or action against the | ||
| production Convex deployment, from the dashboard runner or anywhere else, and | ||
| never hand-edit production documents. Reads are fine when the user asks; | ||
| report aggregates, not customer emails. Full rule in the root `AGENTS.md`. | ||
| - **Webhook direction.** The only supported direction is store → IAPKit. Never | ||
| document an IAPKit → SDK/mobile webhook, SSE, WebSocket, push relay, or | ||
| long-poll feed. See the root `AGENTS.md`. | ||
| - **Brand.** `OpenIAP` and `IAPKit`, never `Open IAP`, `IAP Kit`, or bare `Kit`. | ||
| - **Reader-first standard.** `knowledge/internal/05-docs-patterns.md`. Remove | ||
| filler and state each fact once; do not restyle prose that is already clear. | ||
| - **Screenshots.** A figure that contradicts corrected text is worse than no | ||
| figure. Open the image before trusting its caption. | ||
|
|
||
| ### 5. Verify | ||
|
|
||
| ```bash | ||
| bun run --filter @hyodotdev/openiap-kit lint | ||
| bun run --filter @hyodotdev/openiap-kit test | ||
| bun run --filter @hyodotdev/openiap-kit smoke:server | ||
| bun run audit:kit-contract | ||
| bun run audit:docs | ||
| ``` | ||
|
|
||
| `packages/kit` changes also trigger the CI-equivalent gate in | ||
| `.husky/pre-commit`, which mirrors `deploy-kit.yml`. | ||
|
|
||
| ## Report | ||
|
|
||
| Group findings as **fixed** (with file:line), **needs a decision** (with the | ||
| options and your recommendation), and **rejected** (with the reason). Say | ||
| plainly when a surface is in good shape rather than manufacturing work. | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.