initial commit of new reusable gha stub - #107

Open
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha
Open

initial commit of new reusable gha stub#107
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha

Conversation

@sarasvoss

Copy link
Copy Markdown
Contributor

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-XXXX

Description of Changes

Adding reusable GHA for running npm scripts for CI

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untrackedonly if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

tested in internal_ GHA runs for this repo's CI

@sarasvoss
sarasvoss requested a review from a team as a code ownerJanuary 17, 2026 18:13
@github-actions

github-actionsBot commented Jan 17, 2026

Copy link
Copy Markdown

✅ Semgrep Security Scan Passed

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from 5657f62 to 5c1be5bCompareJanuary 17, 2026 21:54
@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from b27a09b to aac3911CompareJanuary 17, 2026 22:58
CopilotAI review requested due to automatic review settings February 26, 2026 20:04

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a reusable GitHub Actions workflow for running common npm CI steps, and introduces two composite actions (audit-npm and run-npm-script) to standardize/DRY npm auditing and script execution across workflows.

Changes:

  • Added reusable workflow .github/workflows/run_npm_ci_scripts.yml to run npm install/audit/build/lint/format/test with a job summary and gating.
  • Refactored internal push CI to call the new reusable workflow.
  • Added composite actions audit-npm and run-npm-script with initial documentation and changelogs.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 16 comments.

Show a summary per file
FileDescription
.github/workflows/run_npm_ci_scripts.ymlNew reusable npm CI workflow (currently has working-directory + versioning/permissions issues).
.github/workflows/internal_on_push_ci.ymlSwitches internal CI job to call the new reusable workflow.
.github/actions/run-npm-script/action.ymlNew composite action to conditionally run an npm script and emit status.
.github/actions/run-npm-script/README.mdDocumentation for run-npm-script (currently has input + version tag format mismatches).
.github/actions/run-npm-script/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).
.github/actions/audit-npm/action.ymlNew composite action to run/parse npm audit (currently not parameterized for working directory).
.github/actions/audit-npm/README.mdDocumentation for audit-npm (currently has version tag format mismatch).
.github/actions/audit-npm/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +24 to +26
env:
NODE_AUTH_TOKEN: ${{ secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN }}
WORKING_DIRECTORY: ${{ inputs.working_directory }}

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reusable workflow uses secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN but does not declare it under on.workflow_call.secrets. In this repo, reusable workflows that need org secrets declare them explicitly (e.g. .github/workflows/deploy_feature_branch.yml).

Suggestion: add on.workflow_call.secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN (required: true) so callers can pass it reliably.

Copilot uses AI. Check for mistakes.
id: build
uses: ./.github/actions/run-npm-script
with:
working-directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The usage example sets working-directory, but the action input is working_directory (underscore) in action.yml. As written, the example won’t apply the input.

Suggestion: update the example to use working_directory.

Suggested change
working-directory: '.'
working_directory: '.'

Copilot uses AI. Check for mistakes.
Comment on lines +74 to +77
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/run-npm-script/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z (and changelog headings must be ## X.Y.Z).

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Suggested change
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.
```text
action/run-npm-script/vX.Y.Z
This action uses namespaced tags for versioning and is tracked in the CHANGELOG under headings of the form `## X.Y.Z`.
```text
actions/run-npm-script/X.Y.Z

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so tests run in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.
Comment on lines +28 to +32
- name: Change to working directory
run: |
echo "Changing to working directory: $WORKING_DIRECTORY"
cd "$WORKING_DIRECTORY"

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Change to working directory step won’t affect later steps (each step runs in a fresh shell), and it also runs before actions/checkout, so the target directory likely doesn’t exist yet. As a result, npm ci and the composite actions will execute from the repo root instead of inputs.working_directory.

Suggestion: remove this step and instead set defaults.run.working-directory: ${{ inputs.working_directory }} for run: steps (or add working-directory: on each run:), and pass ${{ inputs.working_directory }} through to the composite actions that need it.

Copilot uses AI. Check for mistakes.
Comment on lines +1 to +5
name: NPM CI

on:
workflow_call:
inputs:

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per VERSIONING.md, reusable workflows under .github/workflows are versioned and require an entry under .github/workflows/CHANGELOGS/<workflow-name>.md. This PR adds a new reusable workflow but does not add the corresponding workflow changelog, which will likely break automated version validation.

Suggestion: add the missing changelog file with a ## 1.0.0 entry (no v prefix).

Copilot uses AI. Check for mistakes.
Comment on lines +72 to +76

This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/audit-npm/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z and changelog headings must be ## X.Y.Z.

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so lint runs in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.

All notable changes to the **run-npm-script** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.

All notable changes to the **audit-npm** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sarasvoss@rebonat0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

initial commit of new reusable gha stub - #107

Open
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha
Open

initial commit of new reusable gha stub#107
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha

Conversation

@sarasvoss

Copy link
Copy Markdown
Contributor

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-XXXX

Description of Changes

Adding reusable GHA for running npm scripts for CI

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untrackedonly if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

tested in internal_ GHA runs for this repo's CI

@sarasvoss
sarasvoss requested a review from a team as a code ownerJanuary 17, 2026 18:13
@github-actions

github-actionsBot commented Jan 17, 2026

Copy link
Copy Markdown

✅ Semgrep Security Scan Passed

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from 5657f62 to 5c1be5bCompareJanuary 17, 2026 21:54
@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from b27a09b to aac3911CompareJanuary 17, 2026 22:58
CopilotAI review requested due to automatic review settings February 26, 2026 20:04

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a reusable GitHub Actions workflow for running common npm CI steps, and introduces two composite actions (audit-npm and run-npm-script) to standardize/DRY npm auditing and script execution across workflows.

Changes:

  • Added reusable workflow .github/workflows/run_npm_ci_scripts.yml to run npm install/audit/build/lint/format/test with a job summary and gating.
  • Refactored internal push CI to call the new reusable workflow.
  • Added composite actions audit-npm and run-npm-script with initial documentation and changelogs.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 16 comments.

Show a summary per file
FileDescription
.github/workflows/run_npm_ci_scripts.ymlNew reusable npm CI workflow (currently has working-directory + versioning/permissions issues).
.github/workflows/internal_on_push_ci.ymlSwitches internal CI job to call the new reusable workflow.
.github/actions/run-npm-script/action.ymlNew composite action to conditionally run an npm script and emit status.
.github/actions/run-npm-script/README.mdDocumentation for run-npm-script (currently has input + version tag format mismatches).
.github/actions/run-npm-script/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).
.github/actions/audit-npm/action.ymlNew composite action to run/parse npm audit (currently not parameterized for working directory).
.github/actions/audit-npm/README.mdDocumentation for audit-npm (currently has version tag format mismatch).
.github/actions/audit-npm/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +24 to +26
env:
NODE_AUTH_TOKEN: ${{ secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN }}
WORKING_DIRECTORY: ${{ inputs.working_directory }}

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reusable workflow uses secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN but does not declare it under on.workflow_call.secrets. In this repo, reusable workflows that need org secrets declare them explicitly (e.g. .github/workflows/deploy_feature_branch.yml).

Suggestion: add on.workflow_call.secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN (required: true) so callers can pass it reliably.

Copilot uses AI. Check for mistakes.
id: build
uses: ./.github/actions/run-npm-script
with:
working-directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The usage example sets working-directory, but the action input is working_directory (underscore) in action.yml. As written, the example won’t apply the input.

Suggestion: update the example to use working_directory.

Suggested change
working-directory: '.'
working_directory: '.'

Copilot uses AI. Check for mistakes.
Comment on lines +74 to +77
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/run-npm-script/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z (and changelog headings must be ## X.Y.Z).

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Suggested change
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.
```text
action/run-npm-script/vX.Y.Z
This action uses namespaced tags for versioning and is tracked in the CHANGELOG under headings of the form `## X.Y.Z`.
```text
actions/run-npm-script/X.Y.Z

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so tests run in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.
Comment on lines +28 to +32
- name: Change to working directory
run: |
echo "Changing to working directory: $WORKING_DIRECTORY"
cd "$WORKING_DIRECTORY"

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Change to working directory step won’t affect later steps (each step runs in a fresh shell), and it also runs before actions/checkout, so the target directory likely doesn’t exist yet. As a result, npm ci and the composite actions will execute from the repo root instead of inputs.working_directory.

Suggestion: remove this step and instead set defaults.run.working-directory: ${{ inputs.working_directory }} for run: steps (or add working-directory: on each run:), and pass ${{ inputs.working_directory }} through to the composite actions that need it.

Copilot uses AI. Check for mistakes.
Comment on lines +1 to +5
name: NPM CI

on:
workflow_call:
inputs:

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per VERSIONING.md, reusable workflows under .github/workflows are versioned and require an entry under .github/workflows/CHANGELOGS/<workflow-name>.md. This PR adds a new reusable workflow but does not add the corresponding workflow changelog, which will likely break automated version validation.

Suggestion: add the missing changelog file with a ## 1.0.0 entry (no v prefix).

Copilot uses AI. Check for mistakes.
Comment on lines +72 to +76

This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/audit-npm/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z and changelog headings must be ## X.Y.Z.

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so lint runs in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.

All notable changes to the **run-npm-script** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.

All notable changes to the **audit-npm** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sarasvoss@rebonat0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

initial commit of new reusable gha stub - #107

Open
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha
Open

initial commit of new reusable gha stub#107
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha

Conversation

@sarasvoss

Copy link
Copy Markdown
Contributor

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-XXXX

Description of Changes

Adding reusable GHA for running npm scripts for CI

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untrackedonly if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

tested in internal_ GHA runs for this repo's CI

@sarasvoss
sarasvoss requested a review from a team as a code ownerJanuary 17, 2026 18:13
@github-actions

github-actionsBot commented Jan 17, 2026

Copy link
Copy Markdown

✅ Semgrep Security Scan Passed

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from 5657f62 to 5c1be5bCompareJanuary 17, 2026 21:54
@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from b27a09b to aac3911CompareJanuary 17, 2026 22:58
CopilotAI review requested due to automatic review settings February 26, 2026 20:04

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a reusable GitHub Actions workflow for running common npm CI steps, and introduces two composite actions (audit-npm and run-npm-script) to standardize/DRY npm auditing and script execution across workflows.

Changes:

  • Added reusable workflow .github/workflows/run_npm_ci_scripts.yml to run npm install/audit/build/lint/format/test with a job summary and gating.
  • Refactored internal push CI to call the new reusable workflow.
  • Added composite actions audit-npm and run-npm-script with initial documentation and changelogs.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 16 comments.

Show a summary per file
FileDescription
.github/workflows/run_npm_ci_scripts.ymlNew reusable npm CI workflow (currently has working-directory + versioning/permissions issues).
.github/workflows/internal_on_push_ci.ymlSwitches internal CI job to call the new reusable workflow.
.github/actions/run-npm-script/action.ymlNew composite action to conditionally run an npm script and emit status.
.github/actions/run-npm-script/README.mdDocumentation for run-npm-script (currently has input + version tag format mismatches).
.github/actions/run-npm-script/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).
.github/actions/audit-npm/action.ymlNew composite action to run/parse npm audit (currently not parameterized for working directory).
.github/actions/audit-npm/README.mdDocumentation for audit-npm (currently has version tag format mismatch).
.github/actions/audit-npm/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +24 to +26
env:
NODE_AUTH_TOKEN: ${{ secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN }}
WORKING_DIRECTORY: ${{ inputs.working_directory }}

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reusable workflow uses secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN but does not declare it under on.workflow_call.secrets. In this repo, reusable workflows that need org secrets declare them explicitly (e.g. .github/workflows/deploy_feature_branch.yml).

Suggestion: add on.workflow_call.secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN (required: true) so callers can pass it reliably.

Copilot uses AI. Check for mistakes.
id: build
uses: ./.github/actions/run-npm-script
with:
working-directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The usage example sets working-directory, but the action input is working_directory (underscore) in action.yml. As written, the example won’t apply the input.

Suggestion: update the example to use working_directory.

Suggested change
working-directory: '.'
working_directory: '.'

Copilot uses AI. Check for mistakes.
Comment on lines +74 to +77
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/run-npm-script/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z (and changelog headings must be ## X.Y.Z).

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Suggested change
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.
```text
action/run-npm-script/vX.Y.Z
This action uses namespaced tags for versioning and is tracked in the CHANGELOG under headings of the form `## X.Y.Z`.
```text
actions/run-npm-script/X.Y.Z

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so tests run in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.
Comment on lines +28 to +32
- name: Change to working directory
run: |
echo "Changing to working directory: $WORKING_DIRECTORY"
cd "$WORKING_DIRECTORY"

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Change to working directory step won’t affect later steps (each step runs in a fresh shell), and it also runs before actions/checkout, so the target directory likely doesn’t exist yet. As a result, npm ci and the composite actions will execute from the repo root instead of inputs.working_directory.

Suggestion: remove this step and instead set defaults.run.working-directory: ${{ inputs.working_directory }} for run: steps (or add working-directory: on each run:), and pass ${{ inputs.working_directory }} through to the composite actions that need it.

Copilot uses AI. Check for mistakes.
Comment on lines +1 to +5
name: NPM CI

on:
workflow_call:
inputs:

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per VERSIONING.md, reusable workflows under .github/workflows are versioned and require an entry under .github/workflows/CHANGELOGS/<workflow-name>.md. This PR adds a new reusable workflow but does not add the corresponding workflow changelog, which will likely break automated version validation.

Suggestion: add the missing changelog file with a ## 1.0.0 entry (no v prefix).

Copilot uses AI. Check for mistakes.
Comment on lines +72 to +76

This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/audit-npm/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z and changelog headings must be ## X.Y.Z.

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so lint runs in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.

All notable changes to the **run-npm-script** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.

All notable changes to the **audit-npm** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sarasvoss@rebonat0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

initial commit of new reusable gha stub - #107

Open
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha
Open

initial commit of new reusable gha stub#107
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha

Conversation

@sarasvoss

Copy link
Copy Markdown
Contributor

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-XXXX

Description of Changes

Adding reusable GHA for running npm scripts for CI

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untrackedonly if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

tested in internal_ GHA runs for this repo's CI

@sarasvoss
sarasvoss requested a review from a team as a code ownerJanuary 17, 2026 18:13
@github-actions

github-actionsBot commented Jan 17, 2026

Copy link
Copy Markdown

✅ Semgrep Security Scan Passed

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from 5657f62 to 5c1be5bCompareJanuary 17, 2026 21:54
@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from b27a09b to aac3911CompareJanuary 17, 2026 22:58
CopilotAI review requested due to automatic review settings February 26, 2026 20:04

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a reusable GitHub Actions workflow for running common npm CI steps, and introduces two composite actions (audit-npm and run-npm-script) to standardize/DRY npm auditing and script execution across workflows.

Changes:

  • Added reusable workflow .github/workflows/run_npm_ci_scripts.yml to run npm install/audit/build/lint/format/test with a job summary and gating.
  • Refactored internal push CI to call the new reusable workflow.
  • Added composite actions audit-npm and run-npm-script with initial documentation and changelogs.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 16 comments.

Show a summary per file
FileDescription
.github/workflows/run_npm_ci_scripts.ymlNew reusable npm CI workflow (currently has working-directory + versioning/permissions issues).
.github/workflows/internal_on_push_ci.ymlSwitches internal CI job to call the new reusable workflow.
.github/actions/run-npm-script/action.ymlNew composite action to conditionally run an npm script and emit status.
.github/actions/run-npm-script/README.mdDocumentation for run-npm-script (currently has input + version tag format mismatches).
.github/actions/run-npm-script/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).
.github/actions/audit-npm/action.ymlNew composite action to run/parse npm audit (currently not parameterized for working directory).
.github/actions/audit-npm/README.mdDocumentation for audit-npm (currently has version tag format mismatch).
.github/actions/audit-npm/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +24 to +26
env:
NODE_AUTH_TOKEN: ${{ secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN }}
WORKING_DIRECTORY: ${{ inputs.working_directory }}

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reusable workflow uses secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN but does not declare it under on.workflow_call.secrets. In this repo, reusable workflows that need org secrets declare them explicitly (e.g. .github/workflows/deploy_feature_branch.yml).

Suggestion: add on.workflow_call.secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN (required: true) so callers can pass it reliably.

Copilot uses AI. Check for mistakes.
id: build
uses: ./.github/actions/run-npm-script
with:
working-directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The usage example sets working-directory, but the action input is working_directory (underscore) in action.yml. As written, the example won’t apply the input.

Suggestion: update the example to use working_directory.

Suggested change
working-directory: '.'
working_directory: '.'

Copilot uses AI. Check for mistakes.
Comment on lines +74 to +77
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/run-npm-script/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z (and changelog headings must be ## X.Y.Z).

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Suggested change
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.
```text
action/run-npm-script/vX.Y.Z
This action uses namespaced tags for versioning and is tracked in the CHANGELOG under headings of the form `## X.Y.Z`.
```text
actions/run-npm-script/X.Y.Z

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so tests run in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.
Comment on lines +28 to +32
- name: Change to working directory
run: |
echo "Changing to working directory: $WORKING_DIRECTORY"
cd "$WORKING_DIRECTORY"

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Change to working directory step won’t affect later steps (each step runs in a fresh shell), and it also runs before actions/checkout, so the target directory likely doesn’t exist yet. As a result, npm ci and the composite actions will execute from the repo root instead of inputs.working_directory.

Suggestion: remove this step and instead set defaults.run.working-directory: ${{ inputs.working_directory }} for run: steps (or add working-directory: on each run:), and pass ${{ inputs.working_directory }} through to the composite actions that need it.

Copilot uses AI. Check for mistakes.
Comment on lines +1 to +5
name: NPM CI

on:
workflow_call:
inputs:

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per VERSIONING.md, reusable workflows under .github/workflows are versioned and require an entry under .github/workflows/CHANGELOGS/<workflow-name>.md. This PR adds a new reusable workflow but does not add the corresponding workflow changelog, which will likely break automated version validation.

Suggestion: add the missing changelog file with a ## 1.0.0 entry (no v prefix).

Copilot uses AI. Check for mistakes.
Comment on lines +72 to +76

This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/audit-npm/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z and changelog headings must be ## X.Y.Z.

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so lint runs in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.

All notable changes to the **run-npm-script** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.

All notable changes to the **audit-npm** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sarasvoss@rebonat0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

initial commit of new reusable gha stub - #107

Open
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha
Open

initial commit of new reusable gha stub#107
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha

Conversation

@sarasvoss

Copy link
Copy Markdown
Contributor

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-XXXX

Description of Changes

Adding reusable GHA for running npm scripts for CI

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untrackedonly if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

tested in internal_ GHA runs for this repo's CI

@sarasvoss
sarasvoss requested a review from a team as a code ownerJanuary 17, 2026 18:13
@github-actions

github-actionsBot commented Jan 17, 2026

Copy link
Copy Markdown

✅ Semgrep Security Scan Passed

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from 5657f62 to 5c1be5bCompareJanuary 17, 2026 21:54
@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from b27a09b to aac3911CompareJanuary 17, 2026 22:58
CopilotAI review requested due to automatic review settings February 26, 2026 20:04

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a reusable GitHub Actions workflow for running common npm CI steps, and introduces two composite actions (audit-npm and run-npm-script) to standardize/DRY npm auditing and script execution across workflows.

Changes:

  • Added reusable workflow .github/workflows/run_npm_ci_scripts.yml to run npm install/audit/build/lint/format/test with a job summary and gating.
  • Refactored internal push CI to call the new reusable workflow.
  • Added composite actions audit-npm and run-npm-script with initial documentation and changelogs.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 16 comments.

Show a summary per file
FileDescription
.github/workflows/run_npm_ci_scripts.ymlNew reusable npm CI workflow (currently has working-directory + versioning/permissions issues).
.github/workflows/internal_on_push_ci.ymlSwitches internal CI job to call the new reusable workflow.
.github/actions/run-npm-script/action.ymlNew composite action to conditionally run an npm script and emit status.
.github/actions/run-npm-script/README.mdDocumentation for run-npm-script (currently has input + version tag format mismatches).
.github/actions/run-npm-script/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).
.github/actions/audit-npm/action.ymlNew composite action to run/parse npm audit (currently not parameterized for working directory).
.github/actions/audit-npm/README.mdDocumentation for audit-npm (currently has version tag format mismatch).
.github/actions/audit-npm/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +24 to +26
env:
NODE_AUTH_TOKEN: ${{ secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN }}
WORKING_DIRECTORY: ${{ inputs.working_directory }}

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reusable workflow uses secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN but does not declare it under on.workflow_call.secrets. In this repo, reusable workflows that need org secrets declare them explicitly (e.g. .github/workflows/deploy_feature_branch.yml).

Suggestion: add on.workflow_call.secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN (required: true) so callers can pass it reliably.

Copilot uses AI. Check for mistakes.
id: build
uses: ./.github/actions/run-npm-script
with:
working-directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The usage example sets working-directory, but the action input is working_directory (underscore) in action.yml. As written, the example won’t apply the input.

Suggestion: update the example to use working_directory.

Suggested change
working-directory: '.'
working_directory: '.'

Copilot uses AI. Check for mistakes.
Comment on lines +74 to +77
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/run-npm-script/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z (and changelog headings must be ## X.Y.Z).

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Suggested change
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.
```text
action/run-npm-script/vX.Y.Z
This action uses namespaced tags for versioning and is tracked in the CHANGELOG under headings of the form `## X.Y.Z`.
```text
actions/run-npm-script/X.Y.Z

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so tests run in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.
Comment on lines +28 to +32
- name: Change to working directory
run: |
echo "Changing to working directory: $WORKING_DIRECTORY"
cd "$WORKING_DIRECTORY"

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Change to working directory step won’t affect later steps (each step runs in a fresh shell), and it also runs before actions/checkout, so the target directory likely doesn’t exist yet. As a result, npm ci and the composite actions will execute from the repo root instead of inputs.working_directory.

Suggestion: remove this step and instead set defaults.run.working-directory: ${{ inputs.working_directory }} for run: steps (or add working-directory: on each run:), and pass ${{ inputs.working_directory }} through to the composite actions that need it.

Copilot uses AI. Check for mistakes.
Comment on lines +1 to +5
name: NPM CI

on:
workflow_call:
inputs:

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per VERSIONING.md, reusable workflows under .github/workflows are versioned and require an entry under .github/workflows/CHANGELOGS/<workflow-name>.md. This PR adds a new reusable workflow but does not add the corresponding workflow changelog, which will likely break automated version validation.

Suggestion: add the missing changelog file with a ## 1.0.0 entry (no v prefix).

Copilot uses AI. Check for mistakes.
Comment on lines +72 to +76

This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/audit-npm/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z and changelog headings must be ## X.Y.Z.

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so lint runs in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.

All notable changes to the **run-npm-script** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.

All notable changes to the **audit-npm** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sarasvoss@rebonat0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

initial commit of new reusable gha stub - #107

Open
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha
Open

initial commit of new reusable gha stub#107
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha

Conversation

@sarasvoss

Copy link
Copy Markdown
Contributor

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-XXXX

Description of Changes

Adding reusable GHA for running npm scripts for CI

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untrackedonly if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

tested in internal_ GHA runs for this repo's CI

@sarasvoss
sarasvoss requested a review from a team as a code ownerJanuary 17, 2026 18:13
@github-actions

github-actionsBot commented Jan 17, 2026

Copy link
Copy Markdown

✅ Semgrep Security Scan Passed

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from 5657f62 to 5c1be5bCompareJanuary 17, 2026 21:54
@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from b27a09b to aac3911CompareJanuary 17, 2026 22:58
CopilotAI review requested due to automatic review settings February 26, 2026 20:04

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a reusable GitHub Actions workflow for running common npm CI steps, and introduces two composite actions (audit-npm and run-npm-script) to standardize/DRY npm auditing and script execution across workflows.

Changes:

  • Added reusable workflow .github/workflows/run_npm_ci_scripts.yml to run npm install/audit/build/lint/format/test with a job summary and gating.
  • Refactored internal push CI to call the new reusable workflow.
  • Added composite actions audit-npm and run-npm-script with initial documentation and changelogs.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 16 comments.

Show a summary per file
FileDescription
.github/workflows/run_npm_ci_scripts.ymlNew reusable npm CI workflow (currently has working-directory + versioning/permissions issues).
.github/workflows/internal_on_push_ci.ymlSwitches internal CI job to call the new reusable workflow.
.github/actions/run-npm-script/action.ymlNew composite action to conditionally run an npm script and emit status.
.github/actions/run-npm-script/README.mdDocumentation for run-npm-script (currently has input + version tag format mismatches).
.github/actions/run-npm-script/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).
.github/actions/audit-npm/action.ymlNew composite action to run/parse npm audit (currently not parameterized for working directory).
.github/actions/audit-npm/README.mdDocumentation for audit-npm (currently has version tag format mismatch).
.github/actions/audit-npm/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +24 to +26
env:
NODE_AUTH_TOKEN: ${{ secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN }}
WORKING_DIRECTORY: ${{ inputs.working_directory }}

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reusable workflow uses secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN but does not declare it under on.workflow_call.secrets. In this repo, reusable workflows that need org secrets declare them explicitly (e.g. .github/workflows/deploy_feature_branch.yml).

Suggestion: add on.workflow_call.secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN (required: true) so callers can pass it reliably.

Copilot uses AI. Check for mistakes.
id: build
uses: ./.github/actions/run-npm-script
with:
working-directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The usage example sets working-directory, but the action input is working_directory (underscore) in action.yml. As written, the example won’t apply the input.

Suggestion: update the example to use working_directory.

Suggested change
working-directory: '.'
working_directory: '.'

Copilot uses AI. Check for mistakes.
Comment on lines +74 to +77
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/run-npm-script/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z (and changelog headings must be ## X.Y.Z).

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Suggested change
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.
```text
action/run-npm-script/vX.Y.Z
This action uses namespaced tags for versioning and is tracked in the CHANGELOG under headings of the form `## X.Y.Z`.
```text
actions/run-npm-script/X.Y.Z

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so tests run in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.
Comment on lines +28 to +32
- name: Change to working directory
run: |
echo "Changing to working directory: $WORKING_DIRECTORY"
cd "$WORKING_DIRECTORY"

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Change to working directory step won’t affect later steps (each step runs in a fresh shell), and it also runs before actions/checkout, so the target directory likely doesn’t exist yet. As a result, npm ci and the composite actions will execute from the repo root instead of inputs.working_directory.

Suggestion: remove this step and instead set defaults.run.working-directory: ${{ inputs.working_directory }} for run: steps (or add working-directory: on each run:), and pass ${{ inputs.working_directory }} through to the composite actions that need it.

Copilot uses AI. Check for mistakes.
Comment on lines +1 to +5
name: NPM CI

on:
workflow_call:
inputs:

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per VERSIONING.md, reusable workflows under .github/workflows are versioned and require an entry under .github/workflows/CHANGELOGS/<workflow-name>.md. This PR adds a new reusable workflow but does not add the corresponding workflow changelog, which will likely break automated version validation.

Suggestion: add the missing changelog file with a ## 1.0.0 entry (no v prefix).

Copilot uses AI. Check for mistakes.
Comment on lines +72 to +76

This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/audit-npm/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z and changelog headings must be ## X.Y.Z.

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so lint runs in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.

All notable changes to the **run-npm-script** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.

All notable changes to the **audit-npm** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sarasvoss@rebonat0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

initial commit of new reusable gha stub - #107

Open
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha
Open

initial commit of new reusable gha stub#107
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha

Conversation

@sarasvoss

Copy link
Copy Markdown
Contributor

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-XXXX

Description of Changes

Adding reusable GHA for running npm scripts for CI

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untrackedonly if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

tested in internal_ GHA runs for this repo's CI

@sarasvoss
sarasvoss requested a review from a team as a code ownerJanuary 17, 2026 18:13
@github-actions

github-actionsBot commented Jan 17, 2026

Copy link
Copy Markdown

✅ Semgrep Security Scan Passed

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from 5657f62 to 5c1be5bCompareJanuary 17, 2026 21:54
@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from b27a09b to aac3911CompareJanuary 17, 2026 22:58
CopilotAI review requested due to automatic review settings February 26, 2026 20:04

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a reusable GitHub Actions workflow for running common npm CI steps, and introduces two composite actions (audit-npm and run-npm-script) to standardize/DRY npm auditing and script execution across workflows.

Changes:

  • Added reusable workflow .github/workflows/run_npm_ci_scripts.yml to run npm install/audit/build/lint/format/test with a job summary and gating.
  • Refactored internal push CI to call the new reusable workflow.
  • Added composite actions audit-npm and run-npm-script with initial documentation and changelogs.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 16 comments.

Show a summary per file
FileDescription
.github/workflows/run_npm_ci_scripts.ymlNew reusable npm CI workflow (currently has working-directory + versioning/permissions issues).
.github/workflows/internal_on_push_ci.ymlSwitches internal CI job to call the new reusable workflow.
.github/actions/run-npm-script/action.ymlNew composite action to conditionally run an npm script and emit status.
.github/actions/run-npm-script/README.mdDocumentation for run-npm-script (currently has input + version tag format mismatches).
.github/actions/run-npm-script/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).
.github/actions/audit-npm/action.ymlNew composite action to run/parse npm audit (currently not parameterized for working directory).
.github/actions/audit-npm/README.mdDocumentation for audit-npm (currently has version tag format mismatch).
.github/actions/audit-npm/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +24 to +26
env:
NODE_AUTH_TOKEN: ${{ secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN }}
WORKING_DIRECTORY: ${{ inputs.working_directory }}

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reusable workflow uses secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN but does not declare it under on.workflow_call.secrets. In this repo, reusable workflows that need org secrets declare them explicitly (e.g. .github/workflows/deploy_feature_branch.yml).

Suggestion: add on.workflow_call.secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN (required: true) so callers can pass it reliably.

Copilot uses AI. Check for mistakes.
id: build
uses: ./.github/actions/run-npm-script
with:
working-directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The usage example sets working-directory, but the action input is working_directory (underscore) in action.yml. As written, the example won’t apply the input.

Suggestion: update the example to use working_directory.

Suggested change
working-directory: '.'
working_directory: '.'

Copilot uses AI. Check for mistakes.
Comment on lines +74 to +77
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/run-npm-script/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z (and changelog headings must be ## X.Y.Z).

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Suggested change
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.
```text
action/run-npm-script/vX.Y.Z
This action uses namespaced tags for versioning and is tracked in the CHANGELOG under headings of the form `## X.Y.Z`.
```text
actions/run-npm-script/X.Y.Z

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so tests run in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.
Comment on lines +28 to +32
- name: Change to working directory
run: |
echo "Changing to working directory: $WORKING_DIRECTORY"
cd "$WORKING_DIRECTORY"

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Change to working directory step won’t affect later steps (each step runs in a fresh shell), and it also runs before actions/checkout, so the target directory likely doesn’t exist yet. As a result, npm ci and the composite actions will execute from the repo root instead of inputs.working_directory.

Suggestion: remove this step and instead set defaults.run.working-directory: ${{ inputs.working_directory }} for run: steps (or add working-directory: on each run:), and pass ${{ inputs.working_directory }} through to the composite actions that need it.

Copilot uses AI. Check for mistakes.
Comment on lines +1 to +5
name: NPM CI

on:
workflow_call:
inputs:

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per VERSIONING.md, reusable workflows under .github/workflows are versioned and require an entry under .github/workflows/CHANGELOGS/<workflow-name>.md. This PR adds a new reusable workflow but does not add the corresponding workflow changelog, which will likely break automated version validation.

Suggestion: add the missing changelog file with a ## 1.0.0 entry (no v prefix).

Copilot uses AI. Check for mistakes.
Comment on lines +72 to +76

This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/audit-npm/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z and changelog headings must be ## X.Y.Z.

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so lint runs in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.

All notable changes to the **run-npm-script** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.

All notable changes to the **audit-npm** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sarasvoss@rebonat0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

initial commit of new reusable gha stub - #107

Open
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha
Open

initial commit of new reusable gha stub#107
sarasvoss wants to merge 12 commits into
mainfrom
add-run-npm-ci-gha

Conversation

@sarasvoss

Copy link
Copy Markdown
Contributor

PR Summary

Jira: https://opensesame.atlassian.net/browse/CORE-XXXX

Description of Changes

Adding reusable GHA for running npm scripts for CI

Versioning

⚠️ Components in this repo are used by multiple repos and teams. Breaking changes to non-versioned components are high-risk. Always apply correct versioning to versioned components to ensure safe, controlled updates.

Versioned components live under ./github/actions

Does this PR modify a versioned component?

  • No — label this PR with version:untracked
  • Yes
    • Add a version label: version:<component-name>/X.Y.Z
    • Ensure the component’s CHANGELOG.md includes a ## X.Y.Z entry
    • Use version:untrackedonly if changes do not alter behavior, inputs, or outputs

If version labels are incorrect or missing, automated version validation will fail and block merge.

Dependencies of PR

N/A

Testing

tested in internal_ GHA runs for this repo's CI

@sarasvoss
sarasvoss requested a review from a team as a code ownerJanuary 17, 2026 18:13
@github-actions

github-actionsBot commented Jan 17, 2026

Copy link
Copy Markdown

✅ Semgrep Security Scan Passed

🎉 No security issues found!

View run
🤖 Powered by Semgrep + reviewdog

@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from 5657f62 to 5c1be5bCompareJanuary 17, 2026 21:54
@sarasvoss
sarasvossforce-pushed the add-run-npm-ci-gha branch 2 times, most recently from b27a09b to aac3911CompareJanuary 17, 2026 22:58
CopilotAI review requested due to automatic review settings February 26, 2026 20:04

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a reusable GitHub Actions workflow for running common npm CI steps, and introduces two composite actions (audit-npm and run-npm-script) to standardize/DRY npm auditing and script execution across workflows.

Changes:

  • Added reusable workflow .github/workflows/run_npm_ci_scripts.yml to run npm install/audit/build/lint/format/test with a job summary and gating.
  • Refactored internal push CI to call the new reusable workflow.
  • Added composite actions audit-npm and run-npm-script with initial documentation and changelogs.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 16 comments.

Show a summary per file
FileDescription
.github/workflows/run_npm_ci_scripts.ymlNew reusable npm CI workflow (currently has working-directory + versioning/permissions issues).
.github/workflows/internal_on_push_ci.ymlSwitches internal CI job to call the new reusable workflow.
.github/actions/run-npm-script/action.ymlNew composite action to conditionally run an npm script and emit status.
.github/actions/run-npm-script/README.mdDocumentation for run-npm-script (currently has input + version tag format mismatches).
.github/actions/run-npm-script/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).
.github/actions/audit-npm/action.ymlNew composite action to run/parse npm audit (currently not parameterized for working directory).
.github/actions/audit-npm/README.mdDocumentation for audit-npm (currently has version tag format mismatch).
.github/actions/audit-npm/CHANGELOG.mdInitial changelog (currently uses an invalid version header format for this repo).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +24 to +26
env:
NODE_AUTH_TOKEN: ${{ secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN }}
WORKING_DIRECTORY: ${{ inputs.working_directory }}

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This reusable workflow uses secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN but does not declare it under on.workflow_call.secrets. In this repo, reusable workflows that need org secrets declare them explicitly (e.g. .github/workflows/deploy_feature_branch.yml).

Suggestion: add on.workflow_call.secrets.ORG_GITHUB_PACKAGES_READ_ONLY_TOKEN (required: true) so callers can pass it reliably.

Copilot uses AI. Check for mistakes.
id: build
uses: ./.github/actions/run-npm-script
with:
working-directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The usage example sets working-directory, but the action input is working_directory (underscore) in action.yml. As written, the example won’t apply the input.

Suggestion: update the example to use working_directory.

Suggested change
working-directory: '.'
working_directory: '.'

Copilot uses AI. Check for mistakes.
Comment on lines +74 to +77
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/run-npm-script/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z (and changelog headings must be ## X.Y.Z).

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Suggested change
This action uses namespaced tags for versioning and is tracked in the CHANGELOG.
```text
action/run-npm-script/vX.Y.Z
This action uses namespaced tags for versioning and is tracked in the CHANGELOG under headings of the form `## X.Y.Z`.
```text
actions/run-npm-script/X.Y.Z

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so tests run in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.
Comment on lines +28 to +32
- name: Change to working directory
run: |
echo "Changing to working directory: $WORKING_DIRECTORY"
cd "$WORKING_DIRECTORY"

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Change to working directory step won’t affect later steps (each step runs in a fresh shell), and it also runs before actions/checkout, so the target directory likely doesn’t exist yet. As a result, npm ci and the composite actions will execute from the repo root instead of inputs.working_directory.

Suggestion: remove this step and instead set defaults.run.working-directory: ${{ inputs.working_directory }} for run: steps (or add working-directory: on each run:), and pass ${{ inputs.working_directory }} through to the composite actions that need it.

Copilot uses AI. Check for mistakes.
Comment on lines +1 to +5
name: NPM CI

on:
workflow_call:
inputs:

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per VERSIONING.md, reusable workflows under .github/workflows are versioned and require an entry under .github/workflows/CHANGELOGS/<workflow-name>.md. This PR adds a new reusable workflow but does not add the corresponding workflow changelog, which will likely break automated version validation.

Suggestion: add the missing changelog file with a ## 1.0.0 entry (no v prefix).

Copilot uses AI. Check for mistakes.
Comment on lines +72 to +76

This action uses namespaced tags for versioning and is tracked in the CHANGELOG.

```text
action/audit-npm/vX.Y.Z

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The versioning section uses a tag format of action/.../vX.Y.Z, but this repo’s policy uses namespaced tags like actions/<component-name>/X.Y.Z and changelog headings must be ## X.Y.Z.

Suggestion: update this section to match VERSIONING.md so consumers use the correct tag format.

Copilot uses AI. Check for mistakes.
Comment on lines +58 to +79
working_directory: '.'
script: build

- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check

- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check

- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

run-npm-script is invoked with working_directory: '.', which ignores inputs.working_directory.

Suggestion: pass ${{ inputs.working_directory }} so lint runs in the intended package directory.

Suggested change
working_directory: '.'
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: '.'
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: '.'
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: '.'
working_directory: ${{ inputs.working_directory }}
script: build
- name: Lint
uses: ./.github/actions/run-npm-script
id: lint
with:
working_directory: ${{ inputs.working_directory }}
script: lint:check
- name: Format
uses: ./.github/actions/run-npm-script
id: format
with:
working_directory: ${{ inputs.working_directory }}
script: format:check
- name: Test
uses: ./.github/actions/run-npm-script
id: test
with:
working_directory: ${{ inputs.working_directory }}

Copilot uses AI. Check for mistakes.

All notable changes to the **run-npm-script** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.

All notable changes to the **audit-npm** action are documented in this file.

## v1.0.0

CopilotAIFeb 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changelog uses ## v1.0.0, but the repo’s version validation expects headings to be exactly ## X.Y.Z (no v prefix). Using v1.0.0 will cause automated version/changelog validation to fail.

Suggestion: change the heading to ## 1.0.0 and ensure the PR label matches that version format.

Suggested change
## v1.0.0
## 1.0.0

Copilot uses AI. Check for mistakes.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@sarasvoss@rebonat0