CI Issue
TypeScript & Lint Check (.github/workflows/typecheck.yml) is path-filtered, and its filter does not include scripts/**. But tsconfig.json has include: ["**/*.ts", ...], so npm run type-check (tsc --noEmit) does type-check the 19 scripts/*.ts files. The result: a PR that only touches scripts/ never runs the type check that would fail on it.
The other gates that do run on scripts/** do not catch type errors:
Vitest transpiles with esbuild (no type checking).
Build runs the scripts through tsx in prebuild (no type checking), and eslint src/ does not look at scripts/.
So a type error in scripts/ lands on main green, and only surfaces as a red TypeScript & Lint Check on the next unrelated PR that touches src/** — a baseline failure that gets blamed on the wrong diff.
Script-only PRs are common here: #154, #114, #105 all changed scripts/*.ts and none of them ran TypeScript & Lint Check.
Evidence
Reproduced locally on main @ 2c1e7c4:
$ npx tsc --noEmit --listFilesOnly | grep -c '/scripts/'
19
$ echo 'export const x: number = "oops";' > scripts/zz_probe.ts
$ npx tsc --noEmit
scripts/zz_probe.ts(1,14): error TS2322: Type 'string' is not assignable to type 'number'.
$ # same file, imported from a vitest test:
$ npx vitest run scripts/zz_probe.test.ts
Test Files 1 passed (1)
Tests 1 passed (1)
Recent scripts/-only PR heads with no TypeScript & Lint Check run: scanner/fix-hive-9941 is the counter-example (touched src/, ran it); PR #154 (7d13e99, scripts/sync-sibling-docs*.ts only) did not.
Recommendation
Add scripts/** to both path lists in .github/workflows/typecheck.yml. Exact replacement — apply the same 1-line insertion under pull_request.paths and push.paths:
on:
pull_request:
branches: [main]
paths:
- "src/**"
- "scripts/**"
- "netlify/**"
- "*.ts"
- "*.tsx"
- "tsconfig.json"
- "package.json"
- ".eslintrc*"
- "eslint.config.*"
- "next.config.*"
push:
branches: [main]
paths:
- "src/**"
- "scripts/**"
- "netlify/**"
- "*.ts"
- "*.tsx"
- "tsconfig.json"
- "package.json"
- ".eslintrc*"
- "eslint.config.*"
- "next.config.*"
This matches the scripts/** entry already present in vitest.yml. Cost: one extra ~1-minute job on script-only PRs.
Why this is an issue and not a PR
The entire fix lives in .github/workflows/typecheck.yml. This agent's GitHub App token is minted at the contributor tier, which lacks the workflows permission, so GitHub rejects any push whose diff touches .github/workflows/**. Landing this needs a human or an ISSUES_PRS_MERGE-tier agent — the change above is mechanical and self-contained.
Filed by ci-maintainer agent (ACMM L6 — full mode)
🐝 Hive Agent: ci-maintainer | Instance: hosted-available-oke-11-placeholder-r05x | SHA: 2c1e7c4
— hive: agent=ci-maintainer backend=copilot model=claude-fable-5.1 copilot=1.0.88
CI Issue
TypeScript & Lint Check(.github/workflows/typecheck.yml) is path-filtered, and its filter does not includescripts/**. Buttsconfig.jsonhasinclude: ["**/*.ts", ...], sonpm run type-check(tsc --noEmit) does type-check the 19scripts/*.tsfiles. The result: a PR that only touchesscripts/never runs the type check that would fail on it.The other gates that do run on
scripts/**do not catch type errors:Vitesttranspiles with esbuild (no type checking).Buildruns the scripts throughtsxinprebuild(no type checking), andeslint src/does not look atscripts/.So a type error in
scripts/lands onmaingreen, and only surfaces as a redTypeScript & Lint Checkon the next unrelated PR that touchessrc/**— a baseline failure that gets blamed on the wrong diff.Script-only PRs are common here: #154, #114, #105 all changed
scripts/*.tsand none of them ranTypeScript & Lint Check.Evidence
Reproduced locally on
main@ 2c1e7c4:Recent
scripts/-only PR heads with noTypeScript & Lint Checkrun:scanner/fix-hive-9941is the counter-example (touchedsrc/, ran it); PR #154 (7d13e99,scripts/sync-sibling-docs*.tsonly) did not.Recommendation
Add
scripts/**to both path lists in.github/workflows/typecheck.yml. Exact replacement — apply the same 1-line insertion underpull_request.pathsandpush.paths:This matches the
scripts/**entry already present invitest.yml. Cost: one extra ~1-minute job on script-only PRs.Why this is an issue and not a PR
The entire fix lives in
.github/workflows/typecheck.yml. This agent's GitHub App token is minted at thecontributortier, which lacks theworkflowspermission, so GitHub rejects any push whose diff touches.github/workflows/**. Landing this needs a human or an ISSUES_PRS_MERGE-tier agent — the change above is mechanical and self-contained.scripts/**added topull_request.pathsandpush.pathsintypecheck.ymlFiled by ci-maintainer agent (ACMM L6 — full mode)
🐝 Hive Agent:
ci-maintainer| Instance:hosted-available-oke-11-placeholder-r05x| SHA:2c1e7c4— hive: agent=ci-maintainer backend=copilot model=claude-fable-5.1 copilot=1.0.88