Commit graph

10 commits

Author SHA1 Message Date
20797a98f1
Run on Bun: bun install, bun --bun next, both dev2 sites on Bun (#222)
Some checks are pending
CI / build (push) Waiting to run
Deploy to dev2 / deploy (push) Waiting to run
test / test (push) Waiting to run
* Run on Bun: bun install, bun --bun next, both dev2 sites on Bun

Moves logicsrc.com and app.logicsrc.com (one image) off Node + npm onto Bun,
following the fleet recipe (phonenumbers.bot pilot).

- Package manager: bun.lock migrated from package-lock.json, so every resolved
  version is unchanged; packageManager bun@1.4.2. Root scripts run each
  workspace with `bun run --cwd <dir>` instead of `npm --workspace`.
- Bun 1.4.2, not the fleet's 1.4.0: 1.4.0 re-resolves this workspace's `file:`
  cross-references differently on every install, so its own lockfile never
  passes --frozen-lockfile. 1.4.2 is stable on it.
- Runtime: logicsrc-web runs `bun --bun next build/start`; apps/pwa (Express,
  app.logicsrc.com) runs `bun src/server.mjs`.
- Image: .nixpacks/Dockerfile (the path both dev2 compose stacks build) is now
  a hand-written oven/bun image carrying the whole workspace, run as the
  non-root bun user. ENTRYPOINT stays `bash -l -c` so a compose `command:` is
  one string, as before; app.logicsrc.com's compose starts it with
  "npm --workspace @logicsrc/pwa run start", which .nixpacks/npm (the image's
  only `npm`) turns into `bun run start` in apps/pwa. Port 3000, the PUBLIC_URL
  build arg and the / health path are unchanged. The nixpacks .nix and
  build.sh are gone.
- CI: both workflows install with bun and run every script through bun (Node
  stays only as the interpreter for vitest/tsc/node --test/Playwright, as
  before), and CI now boots the site under Bun.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* ci: boot check on port 3100 and stop it before Playwright needs 3000

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): keep next dev on port 5174, which Playwright waits on

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 08:14:40 -07:00
587c073f72
ops: deploy app.logicsrc.com to dev2 on merge (#216)
* ops: deploy app.logicsrc.com to dev2 on merge

Railway deployed this on push; dev2 does not by itself. The workflow ssh's
to the box and runs /home/anthony/www/app.logicsrc.com/deploy-app.sh, which builds
the image from this checkout and restarts the compose stack. Generated by
cli-tools dev2/dev2-site scaffold.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* ops: stop committing the nixpacks build plan

`railway up` writes .nixpacks/ into the working tree: a Dockerfile, a
nixpkgs pin, and a build.sh that hard-codes the absolute path of the
worktree it ran in plus a one-off image tag. None of it is reusable and
no workflow reads it, so every branch that deploys regenerates it and
conflicts with the last one -- which is exactly how this branch ended up
CONFLICTING against master.

Drop it and ignore it.

* ops: drop the nixpacks build plan master picked up in #215

Same detritus, same stale absolute path (a worktree that no longer
exists). Now ignored, so it will not come back.

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-25 05:52:37 -07:00
f4780259fd
ops: deploy logicsrc.com to dev2 on merge (#215)
Railway deployed this on push; dev2 does not by itself. The workflow ssh's
to the box and runs /home/anthony/www/logicsrc.com/deploy-app.sh, which builds
the image from this checkout and restarts the compose stack. Generated by
cli-tools dev2/dev2-site scaffold.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-25 03:49:38 -07:00
bfb536c894
ci: remove the vu1nz security scan (#127)
vu1nz reviews a diff by calling Claude, which needs ANTHROPIC_API_KEY
supplied through the ENV_FILE secret. That key is not present on this
repository, so the scanner has never reviewed a pull request. On pack
1.0.0 and 1.0.1 that failure was silent: the job reported "0 finding(s),
no high/critical issues" on a diff nothing had read, which is worse than
no scanner at all.

threatcrush-scan covers the same ground deterministically - credentials,
injection, SSRF, unsafe deserialisation, XXE, dependency tampering - with
no API key and no per-pull-request cost.

Reinstallable from the sh1pt Actions Store if the key is ever provisioned.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-03 07:16:41 -07:00
d2abd201a6
ci: add ThreatCrush security scan (#122)
Installs threatcrush-scan@1.1.0 from the sh1pt Actions Store.
Scans pull requests for hardcoded credentials, injection, SSRF, unsafe
deserialisation and dependency tampering; uploads SARIF to the Security
tab.

Report-only — it will not fail a pull request. Set the pack's failOn
input to critical,high once the existing findings are triaged.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-03 06:36:30 -07:00
d0c6752194 ci: build workspaces before running tests; set PUBLIC_URL=https://logicsrc.com
The 'test' workflow ran 'npm test' without building, so dependents could not
resolve @logicsrc/plugin-core / @logicsrc/validators (they publish from dist/).
Build first. Also document PUBLIC_URL (canonical site URL) in .env.example.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-07 03:51:00 +00:00
254233c3ab Add contract and Playwright PR checks 2026-06-06 11:30:12 +00:00
sh1pt-actions-fleet[bot]
447974dbba
Add .github/workflows/test.yml via sh1pt node-pnpm-test@1.0.0 (#2)
Co-authored-by: sh1pt-actions-fleet[bot] <287014002+sh1pt-actions-fleet[bot]@users.noreply.github.com>
2026-06-06 04:27:46 -07:00
sh1pt-actions-fleet[bot]
c0ec761c98
Add .github/workflows/vu1nz-scan.yml via sh1pt vu1nz-scan@1.0.0 (#1)
Co-authored-by: sh1pt-actions-fleet[bot] <287014002+sh1pt-actions-fleet[bot]@users.noreply.github.com>
2026-06-06 04:27:34 -07:00
sh1pt-actions-fleet[bot]
5c01318cc9
Add .github/workflows/ci.yml via sh1pt node-pnpm-ci@1.0.0 (#3)
Co-authored-by: sh1pt-actions-fleet[bot] <287014002+sh1pt-actions-fleet[bot]@users.noreply.github.com>
2026-06-06 04:27:19 -07:00