Conversation
CatarinaGamboa
left a comment
There was a problem hiding this comment.
Publishing now waits for the checks. One gap between what's checked and what ships:
Reviewed with Claude Code (reviewer + adversarial agents per PR, findings checked against the code before posting).
| uses: ./.github/workflows/test.yml | ||
|
|
||
| publish: | ||
| needs: checks |
There was a problem hiding this comment.
The published VSIX is rebuilt differently from the one the checks tested. After needs: checks, the publish job builds again with JDK 20 (checks use 21), npm install instead of npm ci, and vsce package --no-dependencies instead of vsce package. So the shipped artifact isn't the one that passed: a lockfile drift, a JDK difference or a dependency-bundling difference would only show up in the release.
Suggest either aligning the steps (same JDK, npm ci, same vsce flags), or uploading the VSIX from the checks job as an artifact and publishing exactly that file.
(As the PR description says, requiring Checks on main is still a repo-settings step. See also the skipped-job note on #138, which affects that required check.)
There was a problem hiding this comment.
Fixed in 00fd1f4: checks upload the validated VSIX, and both marketplaces publish that exact downloaded file without rebuilding. Workflow/artifact checks, packaged runtime checks, and extension installation passed.
…nto codex/issue-126-required-checks
Co-authored-by: Codex <noreply@openai.com>
Part of #126. Depends on #138.
Publishing runs the reusable checks workflow first and proceeds only after it passes. A repository administrator still needs to require the
Checksstatus onmain.Validated workflow syntax and dependencies; extension installation passed.
Generated by Codex.