|
34 | 34 | # payload deserialization and it touches NO source directory, so without |
35 | 35 | # these two entries the only suites that would catch it never start. They |
36 | 36 | # are the files a bump actually edits: exact pins (`protect-ffi`, |
37 | | - # `@cipherstash/eql`) live in the package manifest, `catalog:` ones |
38 | | - # (`@cipherstash/auth`) in the workspace catalog. |
| 37 | + # `@cipherstash/eql`) live in the package manifest, `catalog:` ones in |
| 38 | + # the workspace catalog. |
39 | 39 | # |
40 | 40 | # `pnpm-lock.yaml` is deliberately NOT listed. It changes on roughly every |
41 | 41 | # dependency bump in the monorepo — far more often than either file here — |
42 | 42 | # and these are credentialed, database-backed jobs. Nothing is lost: a |
43 | | - # protect-ffi or auth version change cannot reach the lockfile without |
44 | | - # editing one of the two manifests below first. |
| 43 | + # protect-ffi version change cannot reach the lockfile without editing |
| 44 | + # one of the two manifests below first, and an auth one edits its own |
| 45 | + # manifest, under the auth paths below. |
45 | 46 | - 'languages/typescript/packages/stack/package.json' |
46 | 47 | - 'pnpm-workspace.yaml' |
47 | 48 | - 'languages/typescript/packages/test-kit/**' |
|
52 | 53 | - '.github/actions/integration-setup/**' |
53 | 54 | - '.github/actions/integration-db/**' |
54 | 55 | - '.github/actions/build-ffi-binding/**' |
| 56 | + - '.github/actions/build-auth-binding/**' |
| 57 | + # `@cipherstash/auth` is a workspace package, and the SDK loads its napi |
| 58 | + # module (and, for `wasm-inline`, its wasm) on import, so a change to what |
| 59 | + # it ships arrives here rather than in `pnpm-workspace.yaml`. The paths of |
| 60 | + # require-auth-npm-changeset.yml. |
| 61 | + - 'packages/stack-auth/Cargo.toml' |
| 62 | + - 'packages/stack-auth/src/**' |
| 63 | + - 'languages/typescript/packages/auth/**' |
| 64 | + - 'languages/typescript/packages/stack-auth-wasm/**' |
55 | 65 | # The Rust that produces every EQL payload these suites round-trip. |
56 | 66 | # Absorbing protect-ffi put it in-tree, so a crate change can now |
57 | 67 | # break them in a PR that touches no TypeScript at all. |
@@ -104,14 +114,15 @@ on: |
104 | 114 | # payload deserialization and it touches NO source directory, so without |
105 | 115 | # these two entries the only suites that would catch it never start. They |
106 | 116 | # are the files a bump actually edits: exact pins (`protect-ffi`, |
107 | | - # `@cipherstash/eql`) live in the package manifest, `catalog:` ones |
108 | | - # (`@cipherstash/auth`) in the workspace catalog. |
| 117 | + # `@cipherstash/eql`) live in the package manifest, `catalog:` ones in |
| 118 | + # the workspace catalog. |
109 | 119 | # |
110 | 120 | # `pnpm-lock.yaml` is deliberately NOT listed. It changes on roughly every |
111 | 121 | # dependency bump in the monorepo — far more often than either file here — |
112 | 122 | # and these are credentialed, database-backed jobs. Nothing is lost: a |
113 | | - # protect-ffi or auth version change cannot reach the lockfile without |
114 | | - # editing one of the two manifests below first. |
| 123 | + # protect-ffi version change cannot reach the lockfile without editing |
| 124 | + # one of the two manifests below first, and an auth one edits its own |
| 125 | + # manifest, under the auth paths below. |
115 | 126 | - 'languages/typescript/packages/stack/package.json' |
116 | 127 | - 'pnpm-workspace.yaml' |
117 | 128 | - 'languages/typescript/packages/test-kit/**' |
|
122 | 133 | - '.github/actions/integration-setup/**' |
123 | 134 | - '.github/actions/integration-db/**' |
124 | 135 | - '.github/actions/build-ffi-binding/**' |
| 136 | + - '.github/actions/build-auth-binding/**' |
| 137 | + # `@cipherstash/auth` is a workspace package, and the SDK loads its napi |
| 138 | + # module (and, for `wasm-inline`, its wasm) on import, so a change to what |
| 139 | + # it ships arrives here rather than in `pnpm-workspace.yaml`. The paths of |
| 140 | + # require-auth-npm-changeset.yml. |
| 141 | + - 'packages/stack-auth/Cargo.toml' |
| 142 | + - 'packages/stack-auth/src/**' |
| 143 | + - 'languages/typescript/packages/auth/**' |
| 144 | + - 'languages/typescript/packages/stack-auth-wasm/**' |
125 | 145 | # The Rust that produces every EQL payload these suites round-trip. |
126 | 146 | # Absorbing protect-ffi put it in-tree, so a crate change can now |
127 | 147 | # break them in a PR that touches no TypeScript at all. |
@@ -227,6 +247,9 @@ jobs: |
227 | 247 | - name: Build the protect-ffi binding |
228 | 248 | uses: ./.github/actions/build-ffi-binding |
229 | 249 |
|
| 250 | + - name: Build the @cipherstash/auth binding |
| 251 | + uses: ./.github/actions/build-auth-binding |
| 252 | + |
230 | 253 | # No pre-`up` cleanup step any more: the project name is unique per job, so |
231 | 254 | # a container leaked by a hard-killed prior run cannot hold this job's |
232 | 255 | # name or its (ephemeral) port. Blanket-pruning would now be actively |
|
0 commit comments