Validation
Use Node 24 and Rust 1.98.1. Each segment retains its reproducible lockfiles. Run checks relevant to the change; do not open live stores for tests.
Source checks#
From the repository root:
node scripts/check-boundaries.mjs
node infra/scripts/check-workflows.mjs .
node scripts/check-publication.mjs --public --checkout
node scripts/check-secrets.mjs
node docs/scripts/check-links.mjs .
The credential scanner requires Gitleaks 8.30.1 on PATH or the GITLEAKS environment variable pointing to that executable. It scans tracked files, so stage additions before running it. Exact synthetic/provenance findings are documented in security; new findings must be reviewed.
Segment checks#
| Segment | Checks |
|---|---|
| Root Rust | cargo test --locked -j 1 --workspace --exclude scopenet-launcher --no-fail-fast |
| Panel web | npm run check; npm run check:runes; npm run build |
| Launcher | npm run check; npm run check:runes; npm run build |
| Infra | npm test; npx --no-install tsc -p control-plane/tsconfig.json; cargo test --locked --workspace -j 1 |
| Docs | npm test; npm run check; npm run build |
| Java | Loader/toolchain checks in each integration/package README |
Run npm commands inside the matching segment after npm ci --no-audit --no-fund.
For memory-constrained Rust tests set CARGO_PROFILE_TEST_DEBUG=0; on PowerShell
use $env:CARGO_PROFILE_TEST_DEBUG='0'.
GitHub Actions#
The root .github/workflows/ci.yml runs automatically on public pull requests and main pushes. It uses read-only permissions, pinned actions, one bounded Ubuntu runner, no deployment secrets and no artifact upload. Packaging, native application acceptance and release workflows remain manual to keep compute/storage costs low.
The root deployment-baseline, release-probe and panel-release workflows are manual. Their registration jobs require successful artifact validation, main, a repository opt-in variable and an exact immutable workflow policy in the control plane. Workflow templates inside Infra remain historical references. No local test substitutes for exact-image Docker acceptance, native desktop/game upgrade testing or production rollout/restore validation.