Skip to content

build: move the pinned Bun toolchain from 1.3.14 to 1.4.2 - #249

Merged
mbeacom merged 1 commit into
mainfrom
chore/bun-1-4-2
Oct 1, 2026
Merged

mbeacom merged 1 commit into
mainfrom
chore/bun-1-4-2

Conversation

@mbeacom

@mbeacom mbeacom commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

What and why

Contributors' machines are already on Bun 1.4.2, while every pin said 1.3.14. A 1.4.2 build rewrites packages/ci/dist with about 30k lines of bundler-helper churn, which looks like a real bundle change and fails the git diff --exit-code packages/ci/dist gate. This moves every pin to 1.4.2 together.

  • Pins: packageManager; all 17 bun-version: steps across 9 workflows; the Containerfile's BUN_VERSION and BUN_DIGEST (the oven/bun:1.4.2-alpine multi-arch index, sha256:d888c0ae…, the same kind of digest the 1.3.14 pin used).
  • Docs: CONTRIBUTING (install instructions and the linux/amd64 rebuild recipe), the PR template, the dependabot.yml comment, and docs/RELEASING.md.
  • Constitution: Principle II named 1.3.14 literally. It now defers to the packageManager pin (PATCH 1.0.2 → 1.0.3), so the next bump cannot leave it stale.
  • packages/ci/dist: regenerated under linux/amd64 oven/bun:1.4.2. The bundles are about 25% smaller (2.0 MB → 1.5 MB for index.js). Correction: an earlier version of this description said the diff was runtime helpers. It is mostly zod tree-shaking. @adrkit/core imports zod through zod/v4, which re-exports the whole library. 1.3.14 kept everything it pulled in; 1.4.2 drops what nothing calls. Zod goes from 95 bundled modules to 18. Dropped: 63 non-English locales/* (en.js is kept); unused classic/{coerce,iso,compat,deep-partial,from-json-schema,in-out,checks,external}; unused core/{compile,json-schema,json-schema-generator,visit,index}. Every other dependency bundles the same modules (undici 96, yaml 72, semver 46, @actions/*, @octokit/*). The validation path (classic/schemas, core/{schemas,checks,parse,errors,regexes,doc}) is kept, and action-dogfood/self-dogfood run the new bundle against the real corpus.

Checklist

  • Commits are DCO signed off.
  • No recorded decision changes. ADR-0010 chooses Bun but pins no version.
  • Schema: n/a
  • packages/ci/dist regenerated under linux/amd64 bun 1.4.2.
  • Tests: none added; this is a toolchain move with no behavior change. The full suite passes on 1.4.2 (3,168 tests, 0 failures).
  • bun run typecheck && bun run build && bun test && bun run lint pass locally on 1.4.2. bun install --frozen-lockfile accepts the existing bun.lock unchanged.

Notes for reviewers

  • Bundle behavior, checked locally. I ran both bundles under Node beside the 1.3.14 bundles from main. They produce identical output: index.js exits early outside a pull_request event, and queue-action.js loads the corpus, builds the report, and fails at the same GitHub API 401. CI runs the governing-decisions bundle end to end (uses: ./packages/ci) and builds every Containerfile target. Nothing in CI runs the queue-action bundle, so the local run above is the only evidence for it until the next release.
  • npm stays the publish transport. bun publish --help in 1.4.2 still shows no OIDC or provenance option, so RELEASING.md's reason stands, re-worded for the new version.
  • Left alone on purpose: 1.3.14 in ADRs, specs, CHANGELOG, and code comments that record where something was observed (e.g. the Windows path.relative reproduction). Those are history.
  • No CHANGELOG entry: this is a toolchain change, and the next release's published artifacts are simply built with 1.4.2. Happy to add a line under Unreleased if you'd like it recorded.
  • Merge order: docs(adr): accept ADR-0040 #248 (ADR-0040) and this PR are independent. The adr accept PR goes last.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 23:30
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Decisions governing this change

  • 0006 — License Apache-2.0 with a DCO and develop in a single monorepo
    • via path: CONTRIBUTING.md
  • 0007 — Isolate integrations as optional adapters and build only against public surfaces
    • via path: .github/workflows/**
  • 0010 — Use Bun as the package manager and test runner while publishing Node-targeted artifacts
    • via path: .github/workflows/**
    • via path: package.json
  • 0011 — Host the canonical JSON Schema at its $id on adrkit.dev
    • via path: .github/workflows/site.yml
  • 0017 — Keep dependency audit scope explicit and release-scoped
    • via path: .github/workflows/ci.yml
  • 0025 — Ship badges as recipes over existing output, not a new CLI surface
    • via path: .github/workflows/ci.yml
    • via path: .github/workflows/site.yml
    • via path: package.json
  • 0030 — Keep extension surfaces that carry a dependency tree outside this repository
    • via path: package.json
    • via path: packages/ci/**
  • 0031 — Publish a narrow consumer SDK as the contract, and document the CLI JSON as its sibling
    • via path: docs/RELEASING.md
  • 0032 — Publish one lockstep OCI image after the coordinated release succeeds
    • via path: .github/workflows/ci.yml
    • via path: .github/workflows/container-release.yml
    • via path: Containerfile
    • via path: docs/RELEASING.md
  • 0035 — Execute the gates that certify a pull request from the default branch
    • via path: .github/workflows/**
    • via path: packages/ci/**
  • 0036 — Expose the governing-decisions Action through one root Marketplace entry point
    • via path: .github/workflows/action-tag-recovery.yml
    • via path: .github/workflows/container-release.yml
    • via path: .github/workflows/release.yml
    • via path: docs/RELEASING.md
    • via path: packages/ci/dist/index.js
  • 0040 — Keep derived surfaces in lockstep with three mechanisms matched to three classes of drift
    • via path: .github/workflows/ci.yml
    • via path: CONTRIBUTING.md
  • 0041 — Regenerate committed artifacts on Dependabot pull requests with default-branch scripts behind a maintainer label
    • via path: .github/dependabot.yml
    • via path: .github/workflows/regenerate-artifacts.yml
    • via path: packages/ci/dist/**
  • 0042 — Count a gate-change acknowledgment only when an admin or maintainer applied it
    • via path: .github/workflows/trusted-gates.yml

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The large generated bundle changes and currently failing audit and gate-integrity checks require final human review.

Review effort: Balanced
Findings: None

What changed in this PR

Updates the repository’s pinned Bun toolchain to 1.4.2 and regenerates Bun-produced Action bundles.

Changes:

  • Aligns active Bun pins across CI, containers, package metadata, and documentation.
  • Amends the constitution to reference the root packageManager pin.
  • Regenerates committed CI bundles with Bun 1.4.2.
File Description
.github/​PULL_REQUEST_TEMPLATE.md Updates bundle regeneration guidance.
.github/​dependabot.yml Updates regeneration instructions.
.github/​workflows/​action-tag-recovery.yml Uses Bun 1.4.2.
.github/​workflows/​ci.yml Updates seven Bun setup steps.
.github/​workflows/​container-release.yml Uses Bun 1.4.2.
.github/​workflows/​regenerate-artifacts.yml Updates both Bun setup steps.
.github/​workflows/​release.yml Uses Bun 1.4.2.
.github/​workflows/​site.yml Uses Bun 1.4.2.
.github/​workflows/​trusted-gates.yml Updates both Bun setup steps.
.specify/​memory/​constitution.md References the canonical package-manager pin.
CONTRIBUTING.md Updates installation and rebuild guidance.
Containerfile Pins Bun 1.4.2 and its image digest.
docs/​RELEASING.md Updates release toolchain documentation.
package.json Sets packageManager to Bun 1.4.2.
packages/​ci/​dist/​index.js Regenerates the governing-decisions Action bundle.
packages/​ci/​dist/​queue-action.js Regenerates the queue Action bundle.

Every pin moves together: packageManager, all 17 setup-bun steps across
nine workflows, the Containerfile build stage (BUN_VERSION plus the
oven/bun:1.4.2-alpine multi-arch index digest), and the rebuild
instructions in CONTRIBUTING.md, the PR template, and dependabot.yml.

packages/ci/dist is regenerated under linux/amd64 oven/bun:1.4.2, as
CONTRIBUTING.md requires. The bundles are about 25% smaller; the diff is
bundler runtime helpers, not source. Both bundles behave the same as the
1.3.14 ones under Node: index.js exits early outside a pull_request event,
and queue-action.js loads the corpus and reaches the GitHub API.

The Spec Kit constitution named Bun 1.3.14 literally in Principle II. It
now names the packageManager pin instead (PATCH, 1.0.2 -> 1.0.3), so the
next bump will not leave it stale.

docs/RELEASING.md keeps npm CLI as the publish transport: `bun publish`
in 1.4.2 still has no OIDC or provenance option.

bun.lock is unchanged: 1.4.2 accepts it under --frozen-lockfile. Mentions
of 1.3.14 in ADRs, specs, the changelog, and comments recording where
something was observed are history and are left as they are.

Signed-off-by: Mark Beacom <m@beacom.dev>
@mbeacom mbeacom added the gate-change-acknowledged A maintainer has seen and accepted this PR's change to the CI gate surface (ADR-0035) label Oct 1, 2026
@mbeacom
mbeacom merged commit ef2545d into main Oct 1, 2026
24 of 25 checks passed
@mbeacom
mbeacom deleted the chore/bun-1-4-2 branch October 1, 2026 01:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gate-change-acknowledged A maintainer has seen and accepted this PR's change to the CI gate surface (ADR-0035)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants