From 53f7793b4539516d6761ea9ff794820d528d7df7 Mon Sep 17 00:00:00 2001 From: Jonathan Payne Date: Mon, 28 Sep 2026 14:05:39 -0400 Subject: [PATCH] OpenConceptLab/ocl_issues#2838 | Pull requests run the Eslint job, and npm run eslint lints .jsx Lint ran only in build.yml, which runs on manual dispatch, so a pull request showed no lint result before it merged. - .github/workflows/pr.yml runs build.yml's Eslint job steps unchanged on every pull_request (Node 14; read-only token; a newer push cancels the older run). build.yml is untouched. - package.json's eslint script adds --ext .jsx,.js; without it ESLint lints only .js files, so npm run eslint skipped every .jsx. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01Lkm1wDY1zKSDTm2apzPJLi --- .github/workflows/pr.yml | 38 ++++++++++++++++++++++++++++++++++++++ package.json | 2 +- 2 files changed, 39 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/pr.yml diff --git a/.github/workflows/pr.yml b/.github/workflows/pr.yml new file mode 100644 index 00000000..ef155c5d --- /dev/null +++ b/.github/workflows/pr.yml @@ -0,0 +1,38 @@ +name: PR checks + +# Runs build.yml's "Eslint" job on every pull request, so a PR shows the +# result before it merges (OpenConceptLab/ocl_issues#2838). Keep these steps +# the same as that job's. + +on: + pull_request: + +permissions: + contents: read + +concurrency: + group: pr-checks-${{ github.event.pull_request.number }} + cancel-in-progress: true + +jobs: + eslint: + name: Eslint + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v3 + - name: Fail if start-prod.sh writes a secret-shaped variable into env-config.js + run: | + ALLOWLIST="RECAPTCHA_SITE_KEY|ERRBIT_KEY" + LEAKS=$(grep -oE 'var [A-Za-z_]+' start-prod.sh | awk '{print $2}' | grep -E 'SECRET|PASSWORD|_KEY' | grep -vE "^(${ALLOWLIST})$" || true) + if [ -n "$LEAKS" ]; then + echo "::error::start-prod.sh writes secret-shaped variable(s) into the publicly-served env-config.js: $LEAKS" + echo "If this is intentionally public (like a DSN-style key), add it to ALLOWLIST above. Otherwise remove it." + exit 1 + fi + - name: Run linting rules + uses: actions/setup-node@v3 + with: + node-version: 14 + cache: 'npm' + - run: npm ci + - run: ./node_modules/eslint/bin/eslint.js --ext .jsx,.js src/ diff --git a/package.json b/package.json index 12c2ad91..baf1b539 100644 --- a/package.json +++ b/package.json @@ -46,7 +46,7 @@ "scripts": { "start": "./node_modules/webpack-dev-server/bin/webpack-dev-server.js --progress --host 0.0.0.0 --port ${WEB_PORT} --env.API_URL=${API_URL} --env.NODE_ENV=${NODE_ENV} --env.RECAPTCHA_SITE_KEY=${RECAPTCHA_SITE_KEY} --env.GA_ACCOUNT_ID=${GA_ACCOUNT_ID} --env.HOTJAR_ID=${HOTJAR_ID} --env.ERRBIT_URL=${ERRBIT_URL} --env.ERRBIT_KEY=${ERRBIT_KEY} --env.LOGIN_REDIRECT_URL=${LOGIN_REDIRECT_URL} --env.OIDC_RP_CLIENT_ID=${OIDC_RP_CLIENT_ID} --mode ${NODE_ENV} --hot", "build": "node --max-old-space-size=1536 ./node_modules/webpack/bin/webpack.js --progress --host 0.0.0.0 --port 443 --env.API_URL=${API_URL} --env.NODE_ENV=${NODE_ENV} --env.RECAPTCHA_SITE_KEY=${RECAPTCHA_SITE_KEY} --env.GA_ACCOUNT_ID=${GA_ACCOUNT_ID} --env.HOTJAR_ID=${HOTJAR_ID} --env.ERRBIT_URL=${ERRBIT_URL} --env.ERRBIT_KEY=${ERRBIT_KEY} --env.LOGIN_REDIRECT_URL=${LOGIN_REDIRECT_URL} --env.OIDC_RP_CLIENT_ID=${OIDC_RP_CLIENT_ID} --mode ${NODE_ENV}", - "eslint": "./node_modules/.bin/eslint ./src" + "eslint": "./node_modules/.bin/eslint ./src --ext .jsx,.js" }, "devDependencies": { "@babel/core": "^7.29.7",