CI Issue
hivecommons/docs CI is currently green (0 failures in the last 50 runs), but the six workflows have three hygiene gaps that will bite later. All fixes live in .github/workflows/**, which this agent's token tier cannot push (GitHub rejects App pushes without the workflows permission), so this needs a human or an ISSUES_PRS_MERGE-tier agent to land — that is why there is no accompanying PR.
1. Node version drift across workflows (main risk)
| workflow |
node-version |
| build.yml |
"22" |
| vitest.yml |
"22" |
| typecheck.yml |
"20" |
| check-internal-links.yml |
"20" |
| meeting-recordings-refresh.yml |
'20.11.1' |
package-lock.json already contains packages that require Node ≥22: jsdom 30.0.1 declares engines: ^22.22.2 || ^24.15.0 || >=26.0.0 (vitest.yml even carries a comment that jsdom 30/undici 8 breaks Node 20). Today the Node-20 jobs only emit EBADENGINE warnings during npm ci, but any move to engine-strict, or a runtime dependency picking up undici 8, turns them into hard failures. package.json has no engines field and there is no .nvmrc.
Fix (exact replacements):
- typecheck.yml line 35:
node-version: "20" → node-version: "22"
- check-internal-links.yml line 41:
node-version: "20" → node-version: "22"
- meeting-recordings-refresh.yml line 23:
node-version: '20.11.1' → node-version: '22'
(Adding "engines": { "node": ">=22.22" } to package.json + a .nvmrc with 22 is pushable by agents and can follow separately once the workflows move.)
2. No concurrency cancellation in 5 of 6 workflows
Only build.yml has a concurrency block. vitest.yml, typecheck.yml, check-internal-links.yml, markdownlint-cli2.yml, and meeting-recordings-refresh.yml re-run redundantly on rapid successive pushes to the same PR.
Fix: add to each of vitest.yml / typecheck.yml / check-internal-links.yml / markdownlint-cli2.yml, directly below the permissions: line:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
(Skip meeting-recordings-refresh.yml — it is schedule/dispatch-only and commits back; cancelling mid-commit is worse than a duplicate run.)
3. typecheck.yml push paths drifted from pull_request paths
The pull_request trigger lists "*.tsx", "package.json", ".eslintrc*", and "next.config.*", but the push trigger omits all four. A direct push to main touching only e.g. package.json or next.config.mjs skips the TypeScript/ESLint gate.
Fix: make the push.paths list in typecheck.yml identical to the pull_request.paths list (add "*.tsx", "package.json", ".eslintrc*", "next.config.*").
Evidence
- Workflow files at current main (
git grep -n node-version .github/workflows/): build.yml:26, vitest.yml:36 = 22; typecheck.yml:35, check-internal-links.yml:41 = 20; meeting-recordings-refresh.yml:23 = 20.11.1
package-lock.json → node_modules/jsdom (30.0.1): "node": "^22.22.2 || ^24.15.0 || >=26.0.0"
- vitest.yml:34-35 comment: "jsdom 30 depends on undici 8, which requires Node >= 22.19"
concurrency grep: only build.yml:12
gh run list (last 50 runs): zero non-success conclusions — this is preventive hygiene, not a live failure
Recommendation
Apply the three exact replacements above in a single PR. No behavior change expected on green paths; verified locally that no workflow other than vitest.yml executes jsdom-dependent code, so the Node bumps are safe.
Filed by ci-maintainer agent (ACMM L4/L5 — hold-gated mode). Workflow-file changes require a human or ISSUES_PRS_MERGE agent; this agent's token cannot push .github/workflows/**.
🐝 Hive Agent: ci-maintainer | Instance: hosted-available-oke-11-placeholder-r05x | SHA: unknown
— hive: agent=ci-maintainer backend=copilot model=claude-fable-5 copilot=1.0.88
CI Issue
hivecommons/docs CI is currently green (0 failures in the last 50 runs), but the six workflows have three hygiene gaps that will bite later. All fixes live in
.github/workflows/**, which this agent's token tier cannot push (GitHub rejects App pushes without theworkflowspermission), so this needs a human or an ISSUES_PRS_MERGE-tier agent to land — that is why there is no accompanying PR.1. Node version drift across workflows (main risk)
package-lock.jsonalready contains packages that require Node ≥22: jsdom 30.0.1 declaresengines: ^22.22.2 || ^24.15.0 || >=26.0.0(vitest.yml even carries a comment that jsdom 30/undici 8 breaks Node 20). Today the Node-20 jobs only emit EBADENGINE warnings duringnpm ci, but any move toengine-strict, or a runtime dependency picking up undici 8, turns them into hard failures.package.jsonhas noenginesfield and there is no.nvmrc.Fix (exact replacements):
node-version: "20"→node-version: "22"node-version: "20"→node-version: "22"node-version: '20.11.1'→node-version: '22'(Adding
"engines": { "node": ">=22.22" }to package.json + a.nvmrcwith22is pushable by agents and can follow separately once the workflows move.)2. No concurrency cancellation in 5 of 6 workflows
Only build.yml has a
concurrencyblock. vitest.yml, typecheck.yml, check-internal-links.yml, markdownlint-cli2.yml, and meeting-recordings-refresh.yml re-run redundantly on rapid successive pushes to the same PR.Fix: add to each of vitest.yml / typecheck.yml / check-internal-links.yml / markdownlint-cli2.yml, directly below the
permissions:line:(Skip meeting-recordings-refresh.yml — it is schedule/dispatch-only and commits back; cancelling mid-commit is worse than a duplicate run.)
3. typecheck.yml push paths drifted from pull_request paths
The
pull_requesttrigger lists"*.tsx","package.json",".eslintrc*", and"next.config.*", but thepushtrigger omits all four. A direct push to main touching only e.g.package.jsonornext.config.mjsskips the TypeScript/ESLint gate.Fix: make the
push.pathslist in typecheck.yml identical to thepull_request.pathslist (add"*.tsx","package.json",".eslintrc*","next.config.*").Evidence
git grep -n node-version .github/workflows/): build.yml:26, vitest.yml:36 = 22; typecheck.yml:35, check-internal-links.yml:41 = 20; meeting-recordings-refresh.yml:23 = 20.11.1package-lock.json→node_modules/jsdom(30.0.1):"node": "^22.22.2 || ^24.15.0 || >=26.0.0"concurrencygrep: only build.yml:12gh run list(last 50 runs): zero non-success conclusions — this is preventive hygiene, not a live failureRecommendation
Apply the three exact replacements above in a single PR. No behavior change expected on green paths; verified locally that no workflow other than vitest.yml executes jsdom-dependent code, so the Node bumps are safe.
Filed by ci-maintainer agent (ACMM L4/L5 — hold-gated mode). Workflow-file changes require a human or ISSUES_PRS_MERGE agent; this agent's token cannot push
.github/workflows/**.🐝 Hive Agent:
ci-maintainer| Instance:hosted-available-oke-11-placeholder-r05x| SHA:unknown— hive: agent=ci-maintainer backend=copilot model=claude-fable-5 copilot=1.0.88