Contributions are welcome! Open an issue or pull request against
cncf/prow-github-actions.
All commits must be signed off (git commit -s) to satisfy the DCO check.
Node 24 or newer is required.
npm ci
npm run all # build, lint, pack the dist/ bundle, and testNote that npm run all runs lint:fix first, which rewrites files in place.
The action runs from the committed dist/index.js (an ncc bundle of src/).
Any change to src/ must be followed by npm run pack, and the resulting
dist/index.js committed alongside it; CI fails if dist/ is out of date.
tsc compiles src/ to ES modules under lib/ (which is gitignored), and
ncc bundles those into the CommonJS dist/index.js that the runner executes;
package.json intentionally has no "type": "module", since Node would then
refuse to load the bundle. Never import from @actions/github/lib/* (only .
and ./lib/utils are exported); the Context type lives in
src/utils/context.ts.
Dependabot keeps npm dependencies and pinned actions up to date on a weekly schedule.
This repository runs the bot on itself through the reusable workflow
(prow.yml) from a single caller,
prow-bot.yml, in the
pull_request install mode: fork pull requests
are handled by the scheduled sweep job (every 20 minutes). A pull request that touches
either file is exercised by its own bot run. __tests__/workflows.test.ts checks
that the reusable workflow, its callers and the install templates
stay in step with action.yml and the label catalogue.
| Command | What it runs |
|---|---|
npm test |
The whole Vitest suite |
npm run test:coverage |
The suite with v8 coverage; CI enforces the thresholds in vitest.config.mjs (lines 85, branches 83, functions 91, statements 85) |
npx vitest run __tests__/bundle |
Only the bundle acceptance harness |
npm run test:coverage:e2e |
Only the bundle acceptance harness, run against a source-mapped bundle built from __tests__/bundle/coverageEntry/ into .coverage-bundle/ so its hits are reported against src/. This is end-to-end-only coverage and is deliberately reported separately from test:coverage: the unit run already reaches every line, so a union would say nothing about what the bundle exercises, and the two runs' statement and branch maps come from different transforms (vite vs. tsc+webpack) and do not combine |
Unit tests under __tests__/ import src/ directly and mock the GitHub API
with msw. The acceptance harness in __tests__/bundle/
instead executes the committed dist/index.js as a child process against a
fake GitHub API on loopback (via GITHUB_API_URL), asserting on the HTTP
requests it makes, its exit code, and its ::error:: output. Because it tests
the committed bundle, run npm run pack before it (npm run all does this).
In CI the suite runs before the dist/ freshness check, which is fine: the
check then proves that the bundle the harness just exercised matches src/.