Run the static checks (format, lint, typecheck, exception audit, npm
registry signatures) and the unit suite with its coverage gate on every
pull request and push to main. The workflow is also callable, so the
release workflow can require the same gates before building.
Every action is pinned to the full commit SHA of its latest release, as
the repository now requires. actionlint runs from a checksum-verified
release binary and zizmor audits the workflows. Dependabot keeps npm
packages and the action pins current, after a 7-day cooldown that
zizmor asks for to avoid picking up freshly published malicious
versions.
Set up the package, compiler and quality gates before any app code so
every later change lands under the same rules: Node 26 via .nvmrc and
engines, TypeScript 7 in strict mode with the extra strictness flags,
swc for transpiling, oxlint with type-aware, Unicorn and security rules
(eslint-plugin-security and no-unsanitized loaded as JS plugins),
oxfmt, Vitest with a 100% coverage gate, and husky hooks that run the
checks and commitlint.
Type escape hatches, lint suppressions and coverage exemptions are
banned unless registered in exceptions.json. scripts/audit-exceptions
enforces that, and its test runs it against this repository, so an
unregistered suppression fails both the pre-commit hook and CI.
npm 11 blocks dependency install scripts by default. None are needed:
Electron downloads its binary on first use, swc's native binding comes
from optionalDependencies, fsevents ships prebuilt, and
electron-winstaller only serves Squirrel installers, which aren't used.
They are recorded as denied in allowScripts.