* fix(ci): set up Node 22 for every job that runs bun install
isolated-vm's install script now runs on install (#5935), and upstream only
publishes prebuilds for Node 22 (ABI 127) and Node 24 (ABI 137). Jobs without
an explicit setup-node inherit the runner default, Node 20, where
prebuild-install finds nothing and falls back to node-gyp — which crashes on
Node 20 with "webidl.util.markAsUncloneable is not a function", failing
bun install --frozen-lockfile outright.
This broke Create GitHub Release on main.
- add setup-node 22 to ci.yml create-release and deploy-trigger-dev
- add setup-node 22 to migrations.yml migrate
- bump publish-cli.yml from the EOL Node 18 to 22, matching publish-ts-sdk.yml
All eight jobs that run bun install now pin Node 22, matching the repo's
declared engines.node >= 22.19.0.
* fix(ci): skip lifecycle scripts on CI installs
No CI job needs a compiled native module. isolated-vm landed in December 2025
and .npmrc blocked all lifecycle scripts until #5935, so CI ran green for
~7 months with it never built: next.config.ts and trigger.config.ts both
external it, every test mocks it, and the only real require lives in
isolated-vm-worker.cjs, which no CI job spawns. All three Dockerfiles already
install with --ignore-scripts and rebuild it by hand.
Building it in CI therefore buys nothing and couples every job to prebuild
availability for the pinned Node. Upstream ships prebuilds for two ABIs only
(Node 22/24), so the next setup-node bump would resurface the same opaque
node-gyp failure that broke Create GitHub Release on main.
- pass --ignore-scripts to all 8 CI bun install invocations
- retarget the Setup Node comments at engines.node >= 22.19.0, which is the
standalone reason for the pin now that scripts no longer run
* fix(ci): drop redundant setup-node from bun-only jobs
Once lifecycle scripts are skipped, nothing in create-release, migrate, or
deploy-trigger-dev invokes node: they run bun run scripts/create-single-release.ts,
bun run db:push plus bun run scripts/migrate.ts, and bunx trigger.dev deploy.
All three were green without setup-node for months — the isolated-vm install
script was the only thing that ever needed it, and --ignore-scripts covers that.
setup-node stays where it is load-bearing: publish-cli and publish-ts-sdk need
it for npm publish and its registry-url auth, and test-build/docs-embeddings
already had it.
publish-cli keeps the Node 18 -> 22 bump: that setup-node is required, and 18
has been EOL since April 2025, so it now matches publish-ts-sdk.
* chore(ci): add CI_PROVIDER toggle between Blacksmith and GitHub-hosted runners
* chore(ci): fail unrecognized CI_PROVIDER values over to GitHub-hosted runners
* improvement(ci): job timeouts everywhere, docs-only PR skip, event-scoped sticky disks, Node pin; drop dead i18n workflow
- timeout-minutes on every runnable job (defaults ran hung jobs to the
6-hour cap — the i18n workflow burned three full 6-hour runs in Feb
before its schedule was pulled)
- paths-ignore on the pull_request trigger: docs content and markdown
don't affect the app build or images; push runs stay unfiltered
- sticky-disk keys scoped by event name so fork PR runs never share a
disk with the push runs that feed production image builds
- node-version pinned to 22 (was 'latest', non-deterministic)
- delete i18n.yml: schedule already removed after repeated 6-hour hangs,
workflow_dispatch-only since, comments stale
* improvement(ci): 45m migrate timeout (covers 30m lock wait), fork-namespaced PR sticky disks
- migrate.ts waits up to 30 minutes for the migration advisory lock
(LOCK_ACQUIRE_DEADLINE_MS); the 15m job timeout would preempt that
designed wait, so the bound is 45m
- fork PRs now get their own sticky-disk namespace so an untrusted fork
run can't poison the disks that trusted internal-PR runs restore
* chore(deps): remove unused dependencies and harden CI supply chain
Dependency cleanup:
- Remove unused deps: papaparse, unified, and 6 unused Radix primitives
(alert-dialog, radio-group, scroll-area, separator, toggle, visually-hidden)
plus @tanstack/react-query-devtools (all verified zero imports repo-wide)
- Consolidate jwt-decode into the existing jose dependency (decodeJwt)
- Migrate react-window to @tanstack/react-virtual to drop a redundant
virtualization library (terminal, structured-output, code viewer)
- Remove the better-auth-harmony plugin and its gating env flag
Supply-chain hardening:
- SHA-pin every GitHub Action to a full commit SHA with a version comment
- Pin CI bun-version to 1.3.13 (was "latest" in the release job)
- Raise bun minimumReleaseAge cooldown from 3 to 7 days
- Add a non-blocking `bun audit` step in CI
- Add a CODEOWNERS gate routing dependency-manifest changes to @simstudioai/deps
* chore(deps): remove unused apps/docs dependencies (@tabler/icons-react, dotenv-cli)
* style(search-modal): use Send icon for Invite teammates action
* feat(search-modal): surface New chat as the top action above Create workflow
* feat(search-modal): add Secrets to the pages list
* fix(docker): use full bun.lock and copy it into builder
The staging build for app.Dockerfile (commit dc2022995, PR #4322) is
failing in two ways after switching to turbo prune:
1. turbo 2.9.6's pruned bun.lock is malformed for bun 1.3.x:
error: Failed to resolve prod dependency 'wrap-ansi' for package
'log-update' at bun.lock:2688:5
Bun ignores it and falls back to a fresh resolve (~7m install).
2. Next.js 16.1.6's Turbopack production build can't infer the workspace
root because /app/bun.lock doesn't exist in the builder stage:
Error: We couldn't find the Next.js package (next/package.json)
from the project directory: /app/apps/sim
This blocks the build entirely.
Fix:
- deps stage: use the full bun.lock from /app/bun.lock (the original
lockfile after `COPY . .` in pruner) instead of the broken
/app/out/bun.lock that turbo prune emits.
- builder stage: also copy the full bun.lock to /app/bun.lock so
Turbopack and turborepo can detect the workspace root.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* chore(ci): bump deprecated Node.js 20 actions to Node.js 24 versions
GitHub Actions runners emit deprecation warnings for actions still on the
Node.js 20 runtime. Node.js 20 will be force-upgraded by GitHub on
2026-06-02 and removed on 2026-09-16.
Bumps to the latest stable major versions, all of which use Node.js 24:
- actions/cache: v4 -> v5
- actions/setup-node: v4 -> v6
- aws-actions/configure-aws-credentials: v4 -> v6
- docker/login-action: v3 -> v4
All require GHA runner v2.327.1+ which Blacksmith already runs.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
* chore(ci): bump actions/checkout to v6 and dorny/paths-filter to v4
* fix(ci): mock secureFetchWithPinnedIP in tools tests to prevent timeouts
* lint
* added blacksmith optimizations to workflows and dockerfiles to enhance performance. please review before pushing to production
* remove cache from and cache to directives from docker based actions, per blacksmith docs
---------
Co-authored-by: Connor Mulholland <connormul@Connors-MacBook-Pro.local>