build: move the pinned Bun toolchain from 1.3.14 to 1.4.2 - #249
Merged
Merged
Conversation
5 of 6 tasks
Decisions governing this change
|
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The large generated bundle changes and currently failing audit and gate-integrity checks require final human review.
Review effort: Balanced
Findings: None
What changed in this PR
Updates the repository’s pinned Bun toolchain to 1.4.2 and regenerates Bun-produced Action bundles.
Changes:
- Aligns active Bun pins across CI, containers, package metadata, and documentation.
- Amends the constitution to reference the root
packageManagerpin. - Regenerates committed CI bundles with Bun 1.4.2.
| File | Description |
|---|---|
.github/PULL_REQUEST_TEMPLATE.md |
Updates bundle regeneration guidance. |
.github/dependabot.yml |
Updates regeneration instructions. |
.github/workflows/action-tag-recovery.yml |
Uses Bun 1.4.2. |
.github/workflows/ci.yml |
Updates seven Bun setup steps. |
.github/workflows/container-release.yml |
Uses Bun 1.4.2. |
.github/workflows/regenerate-artifacts.yml |
Updates both Bun setup steps. |
.github/workflows/release.yml |
Uses Bun 1.4.2. |
.github/workflows/site.yml |
Uses Bun 1.4.2. |
.github/workflows/trusted-gates.yml |
Updates both Bun setup steps. |
.specify/memory/constitution.md |
References the canonical package-manager pin. |
CONTRIBUTING.md |
Updates installation and rebuild guidance. |
Containerfile |
Pins Bun 1.4.2 and its image digest. |
docs/RELEASING.md |
Updates release toolchain documentation. |
package.json |
Sets packageManager to Bun 1.4.2. |
packages/ci/dist/index.js |
Regenerates the governing-decisions Action bundle. |
packages/ci/dist/queue-action.js |
Regenerates the queue Action bundle. |
4 of 6 tasks
Every pin moves together: packageManager, all 17 setup-bun steps across nine workflows, the Containerfile build stage (BUN_VERSION plus the oven/bun:1.4.2-alpine multi-arch index digest), and the rebuild instructions in CONTRIBUTING.md, the PR template, and dependabot.yml. packages/ci/dist is regenerated under linux/amd64 oven/bun:1.4.2, as CONTRIBUTING.md requires. The bundles are about 25% smaller; the diff is bundler runtime helpers, not source. Both bundles behave the same as the 1.3.14 ones under Node: index.js exits early outside a pull_request event, and queue-action.js loads the corpus and reaches the GitHub API. The Spec Kit constitution named Bun 1.3.14 literally in Principle II. It now names the packageManager pin instead (PATCH, 1.0.2 -> 1.0.3), so the next bump will not leave it stale. docs/RELEASING.md keeps npm CLI as the publish transport: `bun publish` in 1.4.2 still has no OIDC or provenance option. bun.lock is unchanged: 1.4.2 accepts it under --frozen-lockfile. Mentions of 1.3.14 in ADRs, specs, the changelog, and comments recording where something was observed are history and are left as they are. Signed-off-by: Mark Beacom <m@beacom.dev>
mbeacom
force-pushed
the
chore/bun-1-4-2
branch
from
October 1, 2026 01:07
1210ba3 to
460e706
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Contributors' machines are already on Bun 1.4.2, while every pin said 1.3.14. A 1.4.2 build rewrites
packages/ci/distwith about 30k lines of bundler-helper churn, which looks like a real bundle change and fails thegit diff --exit-code packages/ci/distgate. This moves every pin to 1.4.2 together.packageManager; all 17bun-version:steps across 9 workflows; the Containerfile'sBUN_VERSIONandBUN_DIGEST(theoven/bun:1.4.2-alpinemulti-arch index,sha256:d888c0ae…, the same kind of digest the 1.3.14 pin used).docs/RELEASING.md.packageManagerpin (PATCH 1.0.2 → 1.0.3), so the next bump cannot leave it stale.packages/ci/dist: regenerated underlinux/amd64 oven/bun:1.4.2. The bundles are about 25% smaller (2.0 MB → 1.5 MB forindex.js). Correction: an earlier version of this description said the diff was runtime helpers. It is mostly zod tree-shaking.@adrkit/coreimports zod throughzod/v4, which re-exports the whole library. 1.3.14 kept everything it pulled in; 1.4.2 drops what nothing calls. Zod goes from 95 bundled modules to 18. Dropped: 63 non-Englishlocales/*(en.jsis kept); unusedclassic/{coerce,iso,compat,deep-partial,from-json-schema,in-out,checks,external}; unusedcore/{compile,json-schema,json-schema-generator,visit,index}. Every other dependency bundles the same modules (undici96,yaml72,semver46,@actions/*,@octokit/*). The validation path (classic/schemas,core/{schemas,checks,parse,errors,regexes,doc}) is kept, andaction-dogfood/self-dogfoodrun the new bundle against the real corpus.Checklist
packages/ci/distregenerated under linux/amd64 bun 1.4.2.bun run typecheck && bun run build && bun test && bun run lintpass locally on 1.4.2.bun install --frozen-lockfileaccepts the existingbun.lockunchanged.Notes for reviewers
main. They produce identical output:index.jsexits early outside apull_requestevent, andqueue-action.jsloads the corpus, builds the report, and fails at the same GitHub API 401. CI runs the governing-decisions bundle end to end (uses: ./packages/ci) and builds every Containerfile target. Nothing in CI runs the queue-action bundle, so the local run above is the only evidence for it until the next release.bun publish --helpin 1.4.2 still shows no OIDC or provenance option, so RELEASING.md's reason stands, re-worded for the new version.path.relativereproduction). Those are history.adr acceptPR goes last.