Finding
The Node major the action runs under is declared in five independent places, and nothing asserts they agree:
action.yml:31 — runs.using: node24 (the runtime GitHub actually starts dist/index.js under)
package.json — engines.node: ">=24" (what actions/setup-node with node-version-file: package.json installs in test.yml, release.yml and pre-release.yml)
package.json — @types/node: "^24" (the API surface tsc checks src/ against)
README.md:75 — "The action requires the node24 runtime"
.github/workflows/{test,release,pre-release}.yml — every setup-node step must keep reading node-version-file: package.json rather than pin a node-version by hand, or CI silently stops following engines
__tests__/workflows.test.ts and __tests__/version.test.ts already guard this class of manifest drift for action inputs, action pins and the release version, but the runtime major has no such guard. When GitHub ships the next nodeNN runtime, bumping runs.using alone leaves the bundle built, typed and e2e-tested (__tests__/bundle) under the old major with no red check.
Evidence: unit coverage on main @ c48bd6d is 99.83% lines / 98.35% branches (npx vitest run --coverage, local, 2026-09-29); every remaining uncovered line is claimed by an open hold-gated PR (#217–#229). The remaining test debt in this repository is drift between manifests, not untested src/ branches.
Recommendation
Add __tests__/runtime.test.ts that parses action.yml, package.json, README.md and every workflow under .github/workflows/ and asserts:
Priority
- Impact: medium — a runtime-major drift ships a bundle tested under the wrong Node with no failing check
- Effort: low
Filed by quality agent (hold-gated mode)
🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: c48bd6d
— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
Finding
The Node major the action runs under is declared in five independent places, and nothing asserts they agree:
action.yml:31—runs.using: node24(the runtime GitHub actually startsdist/index.jsunder)package.json—engines.node: ">=24"(whatactions/setup-nodewithnode-version-file: package.jsoninstalls intest.yml,release.ymlandpre-release.yml)package.json—@types/node: "^24"(the API surfacetsccheckssrc/against)README.md:75— "The action requires thenode24runtime".github/workflows/{test,release,pre-release}.yml— everysetup-nodestep must keep readingnode-version-file: package.jsonrather than pin anode-versionby hand, or CI silently stops followingengines__tests__/workflows.test.tsand__tests__/version.test.tsalready guard this class of manifest drift for action inputs, action pins and the release version, but the runtime major has no such guard. When GitHub ships the nextnodeNNruntime, bumpingruns.usingalone leaves the bundle built, typed and e2e-tested (__tests__/bundle) under the old major with no red check.Evidence: unit coverage on
main@ c48bd6d is 99.83% lines / 98.35% branches (npx vitest run --coverage, local, 2026-09-29); every remaining uncovered line is claimed by an open hold-gated PR (#217–#229). The remaining test debt in this repository is drift between manifests, not untestedsrc/branches.Recommendation
Add
__tests__/runtime.test.tsthat parsesaction.yml,package.json,README.mdand every workflow under.github/workflows/and asserts:runs.usingmatches^node\d+$andruns.mainisdist/index.jsengines.nodeis exactly>=<major>and@types/nodeis exactly^<major>README.mdnames the same`nodeNN` runtimeactions/setup-nodestep usesnode-version-file: package.jsonand nonode-versionPriority
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:c48bd6d— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88