Skip to content

[quality] no test guards the Node runtime major across action.yml, package.json engines, @types/node, README and setup-node #233

Description

@hivecommons-hive

Finding

The Node major the action runs under is declared in five independent places, and nothing asserts they agree:

  • action.yml:31 — runs.using: node24 (the runtime GitHub actually starts dist/index.js under)
  • package.json — engines.node: ">=24" (what actions/setup-node with node-version-file: package.json installs in test.yml, release.yml and pre-release.yml)
  • package.json — @types/node: "^24" (the API surface tsc checks src/ against)
  • README.md:75 — "The action requires the node24 runtime"
  • .github/workflows/{test,release,pre-release}.yml — every setup-node step must keep reading node-version-file: package.json rather than pin a node-version by hand, or CI silently stops following engines

__tests__/workflows.test.ts and __tests__/version.test.ts already guard this class of manifest drift for action inputs, action pins and the release version, but the runtime major has no such guard. When GitHub ships the next nodeNN runtime, bumping runs.using alone leaves the bundle built, typed and e2e-tested (__tests__/bundle) under the old major with no red check.

Evidence: unit coverage on main @ c48bd6d is 99.83% lines / 98.35% branches (npx vitest run --coverage, local, 2026-09-29); every remaining uncovered line is claimed by an open hold-gated PR (#217–#229). The remaining test debt in this repository is drift between manifests, not untested src/ branches.

Recommendation

Add __tests__/runtime.test.ts that parses action.yml, package.json, README.md and every workflow under .github/workflows/ and asserts:

  • runs.using matches ^node\d+$ and runs.main is dist/index.js
  • engines.node is exactly >=<major> and @types/node is exactly ^<major>
  • README.md names the same `nodeNN` runtime
  • every actions/setup-node step uses node-version-file: package.json and no node-version

Priority

  • Impact: medium — a runtime-major drift ships a bundle tested under the wrong Node with no failing check
  • Effort: low

Filed by quality agent (hold-gated mode)


🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: c48bd6d

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/qualityCreated by Hive for agent-filed issue provenancehive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedhive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceneeds-kindqualityCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenance

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions