Skip to content

Eliminate setup-time @actions/artifact install by inlining required artifact client features - #38684

Merged
pelikhan merged 4 commits into
mainfrom
copilot/remove-actions-artifacts-installation
Jun 11, 2026
Merged

Eliminate setup-time @actions/artifact install by inlining required artifact client features#38684
pelikhan merged 4 commits into
mainfrom
copilot/remove-actions-artifacts-installation

Conversation

CopilotAI commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

This change removes the setup action’s runtime dependency on @actions/artifact by reimplementing the specific artifact operations used in this repo. The setup flow no longer installs npm packages at runtime to support artifact upload/download/list paths.

  • What changed

    • Added actions/setup/js/artifact_client.cjs with an internal DefaultArtifactClient implementing:
      • artifact listing via Actions REST API
      • artifact download via Actions redirect + blob fetch
      • artifact upload via Results Twirp (CreateArtifact/FinalizeArtifact) + signed blob upload
    • Switched existing consumers to the internal client:
      • actions/setup/js/upload_artifact.cjs
      • actions/setup/js/check_daily_aic_workflow_guardrail.cjs
  • Setup action integration cleanup

    • Removed runtime @actions/artifact installation logic from actions/setup/setup.sh.
    • Removed SAFE_OUTPUT_ARTIFACT_CLIENT env wiring from actions/setup/index.js.
    • Kept action input compatibility but marked safe-output-artifact-client as deprecated no-op in actions/setup/action.yml.
  • Dependency surface reduction

    • Removed @actions/artifact from actions/setup/js/package.json and lockfile.
// Before: dynamic npm dependency at runtimeconst{ DefaultArtifactClient }=awaitimport("@actions/artifact");// After: repo-local implementationconst{ DefaultArtifactClient }=require("./artifact_client.cjs");

Changeset

  • Type: patch
  • Description: Removed the setup-time @actions/artifact install by inlining the artifact client features needed for upload, download, and listing.

Generated by 📋 Changeset Generator for issue #38684 · 7.82 AIC · ⊞ 21.8K ·



✨ PR Review Safe Output Test - Run 27369159684

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · 87.6 AIC · ⌖ 33 AIC ·

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
CopilotAI changed the title Reimplement setup artifact client without npm installEliminate setup-time @actions/artifact install by inlining required artifact client featuresJun 11, 2026
CopilotAI requested a review from pelikhanJune 11, 2026 17:41
@pelikhan
pelikhan marked this pull request as ready for review June 11, 2026 17:49
CopilotAI review requested due to automatic review settings June 11, 2026 17:49

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the setup action’s runtime dependency on @actions/artifact by introducing a repo-local artifact client and switching existing safe-output consumers to use it, eliminating setup-time npm installs and reducing the dependency surface of actions/setup/js.

Changes:

  • Added actions/setup/js/artifact_client.cjs implementing artifact list/download via GitHub REST and upload via Results Twirp + signed blob upload.
  • Updated upload_artifact.cjs and check_daily_aic_workflow_guardrail.cjs to use the internal DefaultArtifactClient.
  • Removed the setup-time @actions/artifact install path and deprecated the related action input as a no-op; removed @actions/artifact from package.json/lockfile.
Show a summary per file
FileDescription
actions/setup/setup.shRemoves setup-time @actions/artifact installation logic and related input wiring.
actions/setup/js/upload_artifact.cjsSwitches artifact uploads from @actions/artifact to the internal client.
actions/setup/js/check_daily_aic_workflow_guardrail.cjsSwitches artifact listing/downloading to the internal client.
actions/setup/js/artifact_client.cjsNew internal artifact client implementing list/download/upload operations.
actions/setup/index.jsRemoves env propagation for the deprecated artifact-client flag.
actions/setup/action.ymlKeeps input compatibility while marking safe-output-artifact-client as deprecated no-op.
actions/setup/js/package.jsonRemoves @actions/artifact dependency.
actions/setup/js/package-lock.jsonRemoves @actions/artifact (and transitive) lockfile entries.

Copilot's findings

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Files not reviewed (1)
  • actions/setup/js/package-lock.json: Language not supported
  • Files reviewed: 7/8 changed files
  • Comments generated: 4

Comment on lines +317 to +324
if (options.skipArchive) {
if (files.length !== 1) {
throw new Error("skipArchive option is only supported when uploading a single file");
}
uploadPath = files[0];
artifactName = path.basename(uploadPath);
contentType = "application/octet-stream";
} else {
Comment threadactions/setup/js/artifact_client.cjs Outdated
Comment on lines +271 to +273
if (redirectResponse.status !== 302) {
throw new Error(`unable to download artifact: unexpected status ${redirectResponse.status}`);
}
Comment on lines +349 to +351
const uploadSize = await uploadFileToSignedURL(uploadPath, createResponse.signed_upload_url, contentType);
const sha256 = crypto.createHash("sha256").update(fs.readFileSync(uploadPath)).digest("hex");

Comment on lines +204 to +210
class DefaultArtifactClient {
async listArtifacts(options = {}) {
const findBy = options.findBy;
if (!findBy?.token || !findBy?.repositoryOwner || !findBy?.repositoryName || !findBy?.workflowRunId) {
throw new Error("listArtifacts requires findBy.token, findBy.repositoryOwner, findBy.repositoryName, and findBy.workflowRunId");
}

@github-actions

Copy link
Copy Markdown
Contributor

Hey @Copilot 👋 — great work inlining the artifact client logic and cutting the @actions/artifact runtime install! Removing 1,747 lines from the lockfile is a meaningful dependency surface reduction, and the PR description clearly explains the before/after.

One thing that would strengthen this before merge:

  • Add tests for artifact_client.cjs — the new file is 375 lines covering three distinct code paths (list, download via redirect + blob fetch, and upload via Twirp CreateArtifact/FinalizeArtifact + signed blob PUT). These paths involve HTTP interactions that are straightforward to unit-test with mocked fetch responses. Without tests, regressions in the artifact API flow would be silent.

If you'd like a hand, you can assign this prompt to your coding agent:

Add unit tests for actions/setup/js/artifact_client.cjs.
Cover the following scenarios using mocked fetch (e.g. with jest or a lightweight node test runner already used in this project):
1. listArtifacts — mock a successful Actions REST API response and assert the returned artifact list matches.
2. downloadArtifact — mock a 302 redirect response followed by a successful blob fetch and assert the file is written correctly.
3. uploadArtifact — mock CreateArtifact Twirp response, the signed blob PUT, and FinalizeArtifact, then assert the artifact ID is returned.
4. Error paths — assert that a non-2xx response from any step throws or rejects with a descriptive error.
Use only test tooling already present in the repo (check actions/setup/js/package.json for existing devDependencies).

Generated by ✅ Contribution Check · 287.3 AIC · ⌖ 12.9 AIC · ⊞ 24.7K ·

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot run pr-finisher skill

…t codes, stream SHA-256, add tests
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented Jun 11, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot run pr-finisher skill

Addressed all four review findings in commit Fix artifact client: preserve name on skipArchive, accept all redirect codes, stream SHA-256, add tests:

  • skipArchive name overwrite — removed artifactName = path.basename(uploadPath) so the caller-provided name is always used.
  • Redirect status codes — replaced the !== 302 check with ![301, 302, 303, 307, 308].includes(...) to accept all standard redirect codes.
  • SHA-256 memory usage — replaced fs.readFileSync with a streaming hashFile() helper that pipes through a crypto.Hash transform, avoiding loading the full file into memory.
  • Unit tests — added artifact_client.test.cjs with 13 tests covering listArtifacts (REST pagination, latest dedup, error), downloadArtifact (missing findBy, non-redirect rejection, all five redirect codes, missing location), and uploadArtifact (empty files, skipArchive multi-file, name preservation vs basename, non-skipArchive name).

@github-actions

github-actionsBot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke AntigravityMISSION COMPLETE! Antigravity has spoken. ✨

@github-actions

github-actionsBot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke PiMISSION COMPLETE! Pi delivered. 🥧

@github-actions

github-actionsBot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions

github-actionsBot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

✅ All tools validated successfully! Agent Container Smoke Test confirms agent container is ready.

@github-actions

github-actionsBot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

⚠️Smoke Gemini failed. Gemini encountered unexpected challenges...

@github-actions

github-actionsBot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

🎬 THE ENDSmoke ClaudeMISSION: ACCOMPLISHED! The hero saves the day! ✨

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot - AOAI (apikey) is now investigating this pull request. Sources say the story is developing...

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing...

@github-actions

Copy link
Copy Markdown
Contributor

Commit pushed: 334e623

Generated by Changeset Generator · 7.82 AIC · ⊞ 21.8K

@github-actions

Copy link
Copy Markdown
Contributor

Agent Container Tool Check

ToolStatusVersion
bash5.2.21
shavailable
git2.54.0
jq1.7
yqv4.53.3
curl8.5.0
gh2.93.0
nodev22.22.3
python33.11.15 (PyPy 7.3.23)
go1.24.13
java21.0.11 (Temurin)
dotnet10.0.300

Result: 12/12 tools available ✅

Overall Status: PASS

🔧 Tool validation by Agent Container Smoke Test · 41.7 AIC · ⌖ 13.3 AIC ·

@github-actions

Copy link
Copy Markdown
Contributor

Eliminate setup-time @actions/artifact install by inlining required artifact client features
PASS: 7 | FAIL: 0 | SKIP: 2
✅ Serena, Playwright, build, file, bash, memory
⚪ web-fetch, issue-field
Overall: PASS

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex · 36.4 AIC · ⌖ 4.14 AIC ·

@github-actions

Copy link
Copy Markdown
Contributor

💥 Smoke Test: Claude — Run 27369159684

Core #1-12: ✅✅✅✅✅✅✅✅✅✅✅✅
PR Review #13-19: ✅ Update ✅ Comments ✅ Submit ✅ Resolve ✅ Reviewer ✅ Push ⚠️ Close(skipped)

Overall: PARTIAL (1 skipped, 0 failed) — Claude engine nominal! 🚀

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · 87.6 AIC · ⌖ 33 AIC ·

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Automated smoke test review - all systems nominal!

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · 87.6 AIC · ⌖ 33 AIC

workflowRunBackendId: ids[1],
workflowJobRunBackendId: ids[2],
};
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Smoke test: nice work inlining the artifact client! Consider a brief comment documenting the expected redirect behavior here.

}
}

throw lastError || new Error(`artifact twirp ${method} failed`);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Smoke test: streaming SHA-256 looks solid — worth a unit test asserting hash on empty input too.

@github-actions

Copy link
Copy Markdown
Contributor

PR: Eliminate setup-time @actions/artifact install by inlining required artifact client features
1✅ 2✅ 3✅ 4✅ 5✅
6✅ 7✅ 8✅ 9✅ 10✅
11✅ 12✅ 13✅ 14✅ 15✅
PASS. Author: @app/copilot-swe-agent. Assignees: @pelikhan@Copilot.

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · 188.9 AIC · ⌖ 16.1 AIC ·

@github-actions

Copy link
Copy Markdown
Contributor

@copilot review all comments and address unresolved review feedback. Please refresh the branch and rerun checks once that is done.

Generated by 👨‍🍳 PR Sous Chef · 65.7 AIC · ⌖ 1.82 AIC · ⊞ 17.3K ·

@pelikhan
pelikhan merged commit 69a8ed7 into mainJun 11, 2026
12 of 14 checks passed
@pelikhan
pelikhan deleted the copilot/remove-actions-artifacts-installation branch June 11, 2026 20:10
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@pelikhan