name: build-verify # Catches the exact class of failure that broke two consecutive PeerCortex # deploys on 2026-07-16: server.js requiring a local file that was never # actually committed/uploaded (MODULE_NOT_FOUND crash-loop on Erik), and a # runtime dependency (pg) missing from package.json/node_modules. Runs on # every push and PR; does NOT deploy anything -- see deploy.sh / the manual # Erik deploy process for that. # # No untrusted event data (PR titles/bodies/commit messages) is interpolated # into any run: step below -- nothing here is exposed to injection. on: push: pull_request: permissions: contents: read jobs: build-verify: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" - name: npm ci run: npm ci - name: server.js / local-db-client.js / bio-rd-client.js syntax run: | for f in server.js local-db-client.js bio-rd-client.js bgp-hijack-monitor.js magatama-s2ten-bgp-enrichment.js; do [ -f "$f" ] && node --check "$f" done - name: every local require() target actually exists run: | MISSING=0 for f in server.js local-db-client.js bio-rd-client.js; do [ -f "$f" ] || continue for req in $(grep -oE "require\(['\"]\./[^'\"]+['\"]\)" "$f" | sed -E "s/require\(['\"]\.\/([^'\"]+)['\"]\)/\1/"); do target="$req" if [ ! -f "$target" ] && [ ! -f "$target.js" ] && [ ! -d "$target" ]; then echo "::error file=$f::require('./$req') has no matching file (checked $target, $target.js)" MISSING=1 fi done done exit $MISSING - name: TypeScript typecheck run: npx tsc --noEmit --pretty false || true # Non-blocking for now: src/mcp-server/* and src/sources/* have pre-existing # errors unrelated to the deployed server.js path (see project memory, # 2026-07-16 audit). Flip to a hard failure once those are cleaned up -- # until then this step is informational only, visible in the job log. - name: build (dist/) run: npm run build - name: vitest run: npm test