Skip to content

chore: test conditional installs to speed up CI - #1809

Closed
SwenSchaeferjohann wants to merge 24 commits into
mainfrom
ci-3
Closed

chore: test conditional installs to speed up CI#1809
SwenSchaeferjohann wants to merge 24 commits into
mainfrom
ci-3

Conversation

@SwenSchaeferjohann

@SwenSchaeferjohannSwenSchaeferjohann commented Jun 15, 2025

Copy link
Copy Markdown
Contributor
  1. use robust caching. isolated per workflow
  2. reduces to 20min CI time (if cache found)
  3. we now run CI builds and tests for both JS v1 and v2 endpoints. gated by featureFlag. Note that both JS versions interact only with the V2 programs, V2 indexer, and V2 prover.
  4. splits JS-related CI into sdk/cli and V1/V2
  5. adds skip option for install.sh because CI does not need local install of Redis. It uses Docker already.
  6. more robust ci and devenv.sh

SwenSchaeferjohannand others added 14 commits June 14, 2025 14:11
* stateless.js add treeinfos
* wip
* add getTokenPoolInfos
* wip
* wip
* wip - storageoptions
* wip
* wip
* wip
* wip - known bug in rpc-interop.test.ts if using random trees
* debugged test-rpc in ctoken
* all ctoken tests working
* rm logs
* clean
* ctxs to infos, removed redundant getMintProgramId calls
* rm deadcode, storageoptions
* fix cli getMindProgramId use
* fix tokenpool
* fix test
stateless.js add treeinfos
wip
add getTokenPoolInfos
wip
wip
wip - storageoptions
wip
wip
wip
wip - known bug in rpc-interop.test.ts if using random trees
debugged test-rpc in ctoken
all ctoken tests working
rm logs
clean
ctxs to infos, removed redundant getMintProgramId calls
rm deadcode, storageoptions
fix cli getMindProgramId use
fix tokenpool
fix test
update CHANGELOG.md files
update changelog
update CHANGELOG.md
export get-token-pool-infos.ts
wip
clean
wip
refactor merklecontext
refactor StateTreeInfo
wip
wip
debug test-rpc getCompressedTokenAccountsByOwner
fix unit test
wip
wip
wip
debug .readUIntLE
wip
wip
wip
fix buffer conversion at test-rpc decode
wip
tests working
compressedProof -> validityProof
update changelog
wip
refactor: do not allow output trees for decompress, transfer
fmt
wip
rename getCachedStateTreeInfos
upd changelog
use with getCachedStateTreeInfos
getStateTreeInfos
wip
wip
delegate test
wip
added transfer-delegated.test.ts
added transfer-delegated test cases. all green
add tests for decompress-delegated
fix
rm logs from program
update changelog
update err msg
fix state-tree-luts
wip
getActiveStateTreeInfos -> getAllStateTreeInfos
wip
fix sigs for nullifyStateTree
wip
wip
cleanup
add getCachedActiveStateTreeInfos mock
revert to compressedProof
add tokenpools tests
update comment
update CHANGELOG.md
update changelog
0.21.0
update changelog
fix
fix event parsing post rebase
stateless js refactor
dedupe types
link to computebudgetprogram
wip
fix DX for instructions: add docstrings to call signatures
wip
dont break mergeTokenAccounts
wip
wip
add v2 trees to test-rpc
v1 mergeable
test-rpc tests working
rpc-interop tests working with v2
all stateless.js tests working with v2
compressed-token tests working
rebase to main
fixup cargo lock
wip
wip (#1794)
wip (#1781)
chore: backport breaking api changes to v1 js SDKs (#1661)
* stateless.js add treeinfos
* wip
* add getTokenPoolInfos
* wip
* wip
* wip - storageoptions
* wip
* wip
* wip
* wip - known bug in rpc-interop.test.ts if using random trees
* debugged test-rpc in ctoken
* all ctoken tests working
* rm logs
* clean
* ctxs to infos, removed redundant getMintProgramId calls
* rm deadcode, storageoptions
* fix cli getMindProgramId use
* fix tokenpool
* fix test
stateless.js add treeinfos
wip
add getTokenPoolInfos
wip
wip
wip - storageoptions
wip
wip
wip
wip - known bug in rpc-interop.test.ts if using random trees
debugged test-rpc in ctoken
all ctoken tests working
rm logs
clean
ctxs to infos, removed redundant getMintProgramId calls
rm deadcode, storageoptions
fix cli getMindProgramId use
fix tokenpool
fix test
update CHANGELOG.md files
update changelog
update CHANGELOG.md
export get-token-pool-infos.ts
wip
clean
wip
refactor merklecontext
refactor StateTreeInfo
wip
wip
debug test-rpc getCompressedTokenAccountsByOwner
fix unit test
wip
wip
wip
debug .readUIntLE
wip
wip
wip
fix buffer conversion at test-rpc decode
wip
tests working
compressedProof -> validityProof
update changelog
wip
refactor: do not allow output trees for decompress, transfer
fmt
wip
rename getCachedStateTreeInfos
upd changelog
use with getCachedStateTreeInfos
getStateTreeInfos
wip
wip
delegate test
wip
added transfer-delegated.test.ts
added transfer-delegated test cases. all green
add tests for decompress-delegated
fix
rm logs from program
update changelog
update err msg
fix state-tree-luts
wip
getActiveStateTreeInfos -> getAllStateTreeInfos
wip
fix sigs for nullifyStateTree
wip
wip
cleanup
add getCachedActiveStateTreeInfos mock
revert to compressedProof
add tokenpools tests
update comment
update CHANGELOG.md
update changelog
0.21.0
update changelog
fix
fix event parsing post rebase
stateless js refactor
dedupe types
link to computebudgetprogram
wip
fix DX for instructions: add docstrings to call signatures
wip
dont break mergeTokenAccounts
wip
wip
add v2 trees to test-rpc
v1 mergeable
test-rpc tests working
rpc-interop tests working with v2
all stateless.js tests working with v2
compressed-token tests working
rebase to main
fixup cargo lock
wip
chore: backport breaking api changes to v1 js SDKs (#1661)
* stateless.js add treeinfos
* wip
* add getTokenPoolInfos
* wip
* wip
* wip - storageoptions
* wip
* wip
* wip
* wip - known bug in rpc-interop.test.ts if using random trees
* debugged test-rpc in ctoken
* all ctoken tests working
* rm logs
* clean
* ctxs to infos, removed redundant getMintProgramId calls
* rm deadcode, storageoptions
* fix cli getMindProgramId use
* fix tokenpool
* fix test
stateless.js add treeinfos
wip
add getTokenPoolInfos
wip
wip
wip - storageoptions
wip
wip
wip
wip - known bug in rpc-interop.test.ts if using random trees
debugged test-rpc in ctoken
all ctoken tests working
rm logs
clean
ctxs to infos, removed redundant getMintProgramId calls
rm deadcode, storageoptions
fix cli getMindProgramId use
fix tokenpool
fix test
update CHANGELOG.md files
update changelog
update CHANGELOG.md
export get-token-pool-infos.ts
wip
clean
wip
refactor merklecontext
refactor StateTreeInfo
wip
wip
debug test-rpc getCompressedTokenAccountsByOwner
fix unit test
wip
wip
wip
debug .readUIntLE
wip
wip
wip
fix buffer conversion at test-rpc decode
wip
tests working
compressedProof -> validityProof
update changelog
wip
refactor: do not allow output trees for decompress, transfer
fmt
wip
rename getCachedStateTreeInfos
upd changelog
use with getCachedStateTreeInfos
getStateTreeInfos
wip
wip
delegate test
wip
added transfer-delegated.test.ts
added transfer-delegated test cases. all green
add tests for decompress-delegated
fix
rm logs from program
update changelog
update err msg
fix state-tree-luts
wip
getActiveStateTreeInfos -> getAllStateTreeInfos
wip
fix sigs for nullifyStateTree
wip
wip
cleanup
add getCachedActiveStateTreeInfos mock
revert to compressedProof
add tokenpools tests
update comment
update CHANGELOG.md
update changelog
0.21.0
update changelog
fix
fix event parsing post rebase
stateless js refactor
dedupe types
link to computebudgetprogram
wip
fix DX for instructions: add docstrings to call signatures
wip
dont break mergeTokenAccounts
wip
wip
add v2 trees to test-rpc
v1 mergeable
test-rpc tests working
rpc-interop tests working with v2
all stateless.js tests working with v2
compressed-token tests working
rebase to main
fixup cargo lock
wip
wip
rename statetreeinfo -> treeinfo
wip
wip
wip
cli test works
wip
wip
wip
wip
wip
wip
wip
wip
wip
wip
wip
wip
rm logs
fix lint
clean
upd comment
chore: backport breaking api changes to v1 js SDKs (#1661) (#1790)
* stateless.js add treeinfos
* wip
* add getTokenPoolInfos
* wip
* wip
* wip - storageoptions
* wip
* wip
* wip
* wip - known bug in rpc-interop.test.ts if using random trees
* debugged test-rpc in ctoken
* all ctoken tests working
* rm logs
* clean
* ctxs to infos, removed redundant getMintProgramId calls
* rm deadcode, storageoptions
* fix cli getMindProgramId use
* fix tokenpool
* fix test
stateless.js add treeinfos
wip
add getTokenPoolInfos
wip
wip
wip - storageoptions
wip
wip
wip
wip - known bug in rpc-interop.test.ts if using random trees
debugged test-rpc in ctoken
all ctoken tests working
rm logs
clean
ctxs to infos, removed redundant getMintProgramId calls
rm deadcode, storageoptions
fix cli getMindProgramId use
fix tokenpool
fix test
update CHANGELOG.md files
update changelog
update CHANGELOG.md
export get-token-pool-infos.ts
wip
clean
wip
refactor merklecontext
refactor StateTreeInfo
wip
wip
debug test-rpc getCompressedTokenAccountsByOwner
fix unit test
wip
wip
wip
debug .readUIntLE
wip
wip
wip
fix buffer conversion at test-rpc decode
wip
tests working
compressedProof -> validityProof
update changelog
wip
refactor: do not allow output trees for decompress, transfer
fmt
wip
rename getCachedStateTreeInfos
upd changelog
use with getCachedStateTreeInfos
getStateTreeInfos
wip
wip
delegate test
wip
added transfer-delegated.test.ts
added transfer-delegated test cases. all green
add tests for decompress-delegated
fix
rm logs from program
update changelog
update err msg
fix state-tree-luts
wip
getActiveStateTreeInfos -> getAllStateTreeInfos
wip
fix sigs for nullifyStateTree
wip
wip
cleanup
add getCachedActiveStateTreeInfos mock
revert to compressedProof
add tokenpools tests
update comment
update CHANGELOG.md
update changelog
0.21.0
update changelog
fix
fix event parsing post rebase
stateless js refactor
dedupe types
link to computebudgetprogram
wip
fix DX for instructions: add docstrings to call signatures
wip
dont break mergeTokenAccounts
wip
wip
add v2 trees to test-rpc
v1 mergeable
test-rpc tests working
rpc-interop tests working with v2
all stateless.js tests working with v2
compressed-token tests working
rebase to main
fixup cargo lock
wip
chore: backport breaking api changes to v1 js SDKs (#1661)
* stateless.js add treeinfos
* wip
* add getTokenPoolInfos
* wip
* wip
* wip - storageoptions
* wip
* wip
* wip
* wip - known bug in rpc-interop.test.ts if using random trees
* debugged test-rpc in ctoken
* all ctoken tests working
* rm logs
* clean
* ctxs to infos, removed redundant getMintProgramId calls
* rm deadcode, storageoptions
* fix cli getMindProgramId use
* fix tokenpool
* fix test
stateless.js add treeinfos
wip
add getTokenPoolInfos
wip
wip
wip - storageoptions
wip
wip
wip
wip - known bug in rpc-interop.test.ts if using random trees
debugged test-rpc in ctoken
all ctoken tests working
rm logs
clean
ctxs to infos, removed redundant getMintProgramId calls
rm deadcode, storageoptions
fix cli getMindProgramId use
fix tokenpool
fix test
update CHANGELOG.md files
update changelog
update CHANGELOG.md
export get-token-pool-infos.ts
wip
clean
wip
refactor merklecontext
refactor StateTreeInfo
wip
wip
debug test-rpc getCompressedTokenAccountsByOwner
fix unit test
wip
wip
wip
debug .readUIntLE
wip
wip
wip
fix buffer conversion at test-rpc decode
wip
tests working
compressedProof -> validityProof
update changelog
wip
refactor: do not allow output trees for decompress, transfer
fmt
wip
rename getCachedStateTreeInfos
upd changelog
use with getCachedStateTreeInfos
getStateTreeInfos
wip
wip
delegate test
wip
added transfer-delegated.test.ts
added transfer-delegated test cases. all green
add tests for decompress-delegated
fix
rm logs from program
update changelog
update err msg
fix state-tree-luts
wip
getActiveStateTreeInfos -> getAllStateTreeInfos
wip
fix sigs for nullifyStateTree
wip
wip
cleanup
add getCachedActiveStateTreeInfos mock
revert to compressedProof
add tokenpools tests
update comment
update CHANGELOG.md
update changelog
0.21.0
update changelog
fix
fix event parsing post rebase
stateless js refactor
dedupe types
link to computebudgetprogram
wip
fix DX for instructions: add docstrings to call signatures
wip
dont break mergeTokenAccounts
wip
wip
add v2 trees to test-rpc
v1 mergeable
test-rpc tests working
rpc-interop tests working with v2
all stateless.js tests working with v2
compressed-token tests working
rebase to main
fixup cargo lock
wip
wip
rename statetreeinfo -> treeinfo
wip
wip
wip
cli test works
wip
wip
wip
wip
wip
wip
wip
wip
wip
wip
wip
wip
rm logs
fix lint
clean
upd comment
wip
stateless.js tests working
ctoken tests working
lint
address comments
selective installs
fmt
v1 and v2 builds and tests working
ctoken v1,v2 working
rm logs
ci
@coderabbitai

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are limited to specific labels.

🏷️ Labels to auto review (1)
  • ai-review

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Explain this complex logic.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai explain this code block.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and explain its main purpose.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Support

Need help? Create a ticket on our support page for assistance with any issues or questions.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

Comment on lines +22 to +91
name: cli-v1
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest

services:
redis:
image: redis:8.0.1
ports:
- 6379:6379
options: >-
--health-cmd "redis-cli ping"
--health-interval 10s
--health-timeout 5s
--health-retries 5

env:
LIGHT_PROTOCOL_VERSION: V1
REDIS_URL: redis://localhost:6379
CI: true

steps:
- name: Checkout sources
uses: actions/checkout@v4

- name: Cache nx
uses: actions/cache@v4
with:
path: |
.nx/cache
node_modules/.cache/nx
js/stateless.js/node_modules/.cache/nx
js/compressed-token/node_modules/.cache/nx
cli/node_modules/.cache/nx
key: nx-cli-v1-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'js/**/package.json', 'cli/package.json') }}-${{ github.sha }}
restore-keys: |
nx-cli-v1-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'js/**/package.json', 'cli/package.json') }}-
nx-cli-v1-${{ runner.os }}-

- name: Setup and build
uses: ./.github/actions/setup-and-build
with:
components: "node,pnpm,solana,anchor,jq,dependencies"

- name: Build stateless.js with V1
run: |
source ./scripts/devenv.sh
cd js/stateless.js
pnpm build:v1

- name: Build compressed-token with V1
run: |
source ./scripts/devenv.sh
cd js/compressed-token
pnpm build:v1

- name: Build CLI with V1
run: |
source ./scripts/devenv.sh
npx nx build @lightprotocol/zk-compression-cli

- name: Run CLI tests with V1
run: |
source ./scripts/devenv.sh
npx nx test @lightprotocol/zk-compression-cli

- name: Display prover logs on failure
if: failure()
run: |
echo "=== Displaying prover logs ==="
find cli/test-ledger -name "*prover*.log" -type f -exec echo "=== Contents of {} ===" \; -exec cat {} \; -exec echo "=== End of {} ===" \; || echo "No prover logs found"

Check warning

Code scanning / CodeQL

Workflow does not contain permissions

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{contents: read}}

Copilot Autofix

AI about 1 year ago

To fix the issue, add a permissions block to the workflow file. This block should be placed at the root level of the workflow to apply to all jobs unless overridden. Based on the workflow's operations, the minimal required permissions are contents: read. This ensures that the GITHUB_TOKEN has only read access to repository contents, reducing the risk of unintended write operations.

Suggested changeset 1
.github/workflows/cli-v1.yml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/cli-v1.yml b/.github/workflows/cli-v1.yml
--- a/.github/workflows/cli-v1.yml
+++ b/.github/workflows/cli-v1.yml
@@ -14,2 +14,4 @@
name: cli-tests-v1
+permissions:
+ contents: read
EOF
@@ -14,2 +14,4 @@
name: cli-tests-v1
permissions:
contents: read

Copilot is powered by AI and may make mistakes. Always verify output.
Comment on lines +22 to +91
name: cli-v2
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest

services:
redis:
image: redis:8.0.1
ports:
- 6379:6379
options: >-
--health-cmd "redis-cli ping"
--health-interval 10s
--health-timeout 5s
--health-retries 5

env:
LIGHT_PROTOCOL_VERSION: V2
REDIS_URL: redis://localhost:6379
CI: true

steps:
- name: Checkout sources
uses: actions/checkout@v4

- name: Cache nx
uses: actions/cache@v4
with:
path: |
.nx/cache
node_modules/.cache/nx
js/stateless.js/node_modules/.cache/nx
js/compressed-token/node_modules/.cache/nx
cli/node_modules/.cache/nx
key: nx-cli-v2-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'js/**/package.json', 'cli/package.json') }}-${{ github.sha }}
restore-keys: |
nx-cli-v2-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'js/**/package.json', 'cli/package.json') }}-
nx-cli-v2-${{ runner.os }}-

- name: Setup and build
uses: ./.github/actions/setup-and-build
with:
components: "node,pnpm,solana,anchor,jq,dependencies"

- name: Build stateless.js with V2
run: |
source ./scripts/devenv.sh
cd js/stateless.js
pnpm build:v2

- name: Build compressed-token with V2
run: |
source ./scripts/devenv.sh
cd js/compressed-token
pnpm build:v2

- name: Build CLI with V2
run: |
source ./scripts/devenv.sh
npx nx build @lightprotocol/zk-compression-cli

- name: Run CLI tests with V2
run: |
source ./scripts/devenv.sh
npx nx test @lightprotocol/zk-compression-cli

- name: Display prover logs on failure
if: failure()
run: |
echo "=== Displaying prover logs ==="
find . -path "*/test-ledger/*prover*.log" -type f -exec echo "=== Contents of {} ===" \; -exec cat {} \; -exec echo "=== End of {} ===" \; || echo "No prover logs found"

Check warning

Code scanning / CodeQL

Workflow does not contain permissions

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{contents: read}}

Copilot Autofix

AI about 1 year ago

To fix the issue, we need to add a permissions block to the workflow. This block should specify the minimal permissions required for the workflow to function correctly. Based on the actions performed in the workflow (e.g., checking out code, caching dependencies, and running tests), the contents: read permission is sufficient. This ensures the workflow has only read access to the repository contents, reducing the risk of unintended modifications.

The permissions block can be added at the root level of the workflow to apply to all jobs, or it can be added specifically to the cli-v2 job. In this case, adding it at the root level is more concise and ensures consistency across all jobs.

Suggested changeset 1
.github/workflows/cli-v2.yml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/cli-v2.yml b/.github/workflows/cli-v2.yml
--- a/.github/workflows/cli-v2.yml
+++ b/.github/workflows/cli-v2.yml
@@ -15,2 +15,5 @@
+permissions:
+ contents: read
+
concurrency:
EOF
@@ -15,2 +15,5 @@

permissions:
contents: read

concurrency:
Copilot is powered by AI and may make mistakes. Always verify output.
Comment on lines +22 to +96
name: stateless-js-v2
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest

services:
redis:
image: redis:8.0.1
ports:
- 6379:6379
options: >-
--health-cmd "redis-cli ping"
--health-interval 10s
--health-timeout 5s
--health-retries 5

env:
LIGHT_PROTOCOL_VERSION: V2
REDIS_URL: redis://localhost:6379
CI: true

steps:
- name: Checkout sources
uses: actions/checkout@v4

- name: Cache nx
uses: actions/cache@v4
with:
path: |
.nx/cache
node_modules/.cache/nx
js/stateless.js/node_modules/.cache/nx
js/compressed-token/node_modules/.cache/nx
cli/node_modules/.cache/nx
key: nx-js-v2-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'js/**/package.json', 'cli/package.json') }}-${{ github.sha }}
restore-keys: |
nx-js-v2-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'js/**/package.json', 'cli/package.json') }}-
nx-js-v2-${{ runner.os }}-

- name: Setup and build
uses: ./.github/actions/setup-and-build
with:
components: "node,pnpm,solana,anchor,jq,dependencies"

- name: Build stateless.js with V2
run: |
source ./scripts/devenv.sh
cd js/stateless.js
pnpm build:v2

- name: Build compressed-token with V2
run: |
source ./scripts/devenv.sh
cd js/compressed-token
pnpm build:v2

- name: Build CLI
run: |
source ./scripts/devenv.sh
npx nx build @lightprotocol/zk-compression-cli

- name: Run stateless.js tests with V2
run: |
source ./scripts/devenv.sh
npx nx test @lightprotocol/stateless.js

- name: Run compressed-token tests with V2
run: |
source ./scripts/devenv.sh
npx nx test @lightprotocol/compressed-token

- name: Display prover logs on failure
if: failure()
run: |
echo "=== Displaying prover logs ==="
find . -path "*/test-ledger/*prover*.log" -type f -exec echo "=== Contents of {} ===" \; -exec cat {} \; -exec echo "=== End of {} ===" \; || echo "No prover logs found"

Check warning

Code scanning / CodeQL

Workflow does not contain permissions

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{contents: read}}

Copilot Autofix

AI about 1 year ago

To fix the issue, we need to add a permissions block to the workflow or job to explicitly limit the access granted to the GITHUB_TOKEN. Since the workflow primarily interacts with repository contents (e.g., checking out code and caching files), the contents: read permission is sufficient. This ensures the workflow has only the minimal access required to complete its tasks.

The permissions block can be added at the root level of the workflow to apply to all jobs or at the job level for more granular control. In this case, adding it at the job level ensures the permissions are scoped specifically to the stateless-js-v2 job.


Suggested changeset 1
.github/workflows/js-v2.yml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/js-v2.yml b/.github/workflows/js-v2.yml
--- a/.github/workflows/js-v2.yml
+++ b/.github/workflows/js-v2.yml
@@ -24,2 +24,4 @@
runs-on: ubuntu-latest
+ permissions:
+ contents: read
EOF
@@ -24,2 +24,4 @@
runs-on: ubuntu-latest
permissions:
contents: read

Copilot is powered by AI and may make mistakes. Always verify output.
Comment threadscripts/INSTALL.md Outdated
@SwenSchaeferjohann

Copy link
Copy Markdown
ContributorAuthor

closing in favor of #1822

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@SwenSchaeferjohann@github-advanced-security