Skip to content

fix!: require Node.js 22.22 and repair CI - #58

Merged
mldangelo-oai merged 5 commits into
mainfrom
mdangelo/codex/node22-ci-dependency-audit
Sep 18, 2026
Merged

mldangelo-oai merged 5 commits into
mainfrom
mdangelo/codex/node22-ci-dependency-audit

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Enforce the official npm package's Node.js floor (22.22.0) before delegating through either global npm or npx; document and recommend Node 24 LTS, with tests for missing, broken, older, minimum, and newer runtimes.
  • Run Python CI for every PR, require every dependency job to succeed, and exercise the exact minimum and Node 24 on both Linux and Windows. Resolve the published CLI once per run, assert which delegation path is being tested, isolate Windows npm directories, and launch smoke tests through the actual Python console script with isolated settings and outputs.
  • Make CI enforce the uv lockfile without changing any dependency version, teach release-please to bump the wrapper's entry in uv.lock, lint both workflows, and let a dedicated release token start eligible pull_request CI automatically. With the default token GitHub requires a maintainer to approve workflow execution; historical manual re-publications preserve their existing lock-repair behavior.

The previous main and release-please dependency PR runs failed in different Windows smoke jobs; their detailed logs have expired. A manual workflow dispatch on the existing release PR confirmed that GitHub runs against its head but excludes those checks from branch protection, as documented in GitHub's required checks troubleshooting guide. This PR therefore uses the standard pull request workflow instead.

Validation

  • Ruff lint and format; mypy; pyright; GitHub actionlint 1.7.12
  • Unit suite with CI's pinned upstream version in the environment: 214 passed, 10 platform-specific skips on macOS
  • Real published [email protected] smoke suite on macOS: 20 passed through a global installation on Node 24; 20 passed through npx on exactly Node 22.22.0
  • Real Node 20.20.2 was rejected before promptfoo runs; wheel and sdist built; verified the wheel includes the new runtime module
  • Compared all 28 lock records with a fresh resolution through the configured registry: package versions, artifacts/hashes, and dependencies match; tested the exact [email protected] updater against the full lockfile and verified only the root package version changes

Breaking change: the Python wrapper no longer supports Node 20 or Node 22 releases older than 22.22.0, including when an older promptfoo CLI is pinned.

@mldangelo-oai
mldangelo-oai marked this pull request as ready for review September 18, 2026 17:35
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-18T18:36:44.536816Z 3bda89c New commits
🔒 Security Review ✅ Completed 2026-09-18T18:33:45.077867Z 3bda89c New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1ad16d23dd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/promptfoo/instructions.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3bda89c3cd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/promptfoo/instructions.py
Comment thread release-please-config.json
@mldangelo-oai
mldangelo-oai merged commit c64ea92 into main Sep 18, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant