mirror of
https://github.com/giancarloerra/socraticode.git
synced 2026-07-03 14:05:21 +02:00
562a946053
A pass over the extension surface to address review feedback: Safety / hardening: - `graphPanel.ts`: validate `m.path` from the webview before opening files. Reject absolute paths and any path that escapes the workspace root (`..`, `/foo`, `C:/...`). Validate the line number is a positive integer before constructing a `Range`. Surface failures via the output channel rather than letting the rejection bubble up. - `mcpProvider.ts`: defensively check that `vscode.lm.registerMcpServerDefinitionProvider` exists before calling it. The `engines.vscode: ^1.99.0` field already enforces this on install, but some VS Code-derived editors mis-report their engine version. The extension now degrades gracefully (sidebar, commands, status bar still work) instead of failing activation. - `commands.ts` and `graphPanel.ts`: wrap `workbench.action.chat.open` in try/catch. Not every VS Code-compatible editor exposes that command; falling back to the output channel avoids unhandled rejections after the user clicked "Open chat". - `extension.ts`: persist the first-run walkthrough flag only after the walkthrough command resolves successfully, so a transient failure doesn't silently skip the onboarding forever. CI gates: - `extension-ci.yml` and `extension-release.yml`: run `npm test` between typecheck and build, so manifest-level smoke regressions can't slip through to either the PR artefact or the marketplace publishes. Settings copy: - `socraticode.env` description: explicitly call out that the setting is for non-secret config only. Recommend OS environment variables / local `.env` files for API keys, since workspace settings can sync via Settings Sync and end up in committed `.vscode/settings.json`. Quality of life: - `sidebar.ts` `formatRelative`: clamp the computed seconds to zero so a file mtime slightly ahead of the local clock doesn't render "-5s ago". - `walkthroughs/first-index.md`: corrected the embedding model name (`nomic-embed-text`, not `mxbai-embed-large`) to match the engine default in `src/constants.ts`. Lint / docs: - `extension/README.md`: hyphenate "Eclipse Theia-based editors". - `DEVELOPER.md`: add `text` language hint to the directory-tree code fence (markdownlint MD040). Updated the inline comment for `settings.ts` to reflect its current shape. - `README.md`: reflow the "extension vs plugin" callout into a single blockquote (markdownlint MD028). Lint, typecheck, manifest tests and build all clean. Engine unit tests unaffected (706/706 still pass).
64 lines
1.3 KiB
YAML
64 lines
1.3 KiB
YAML
name: Extension Release
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v*"
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
publish:
|
|
name: Publish .vsix to VS Code Marketplace and Open VSX
|
|
runs-on: ubuntu-latest
|
|
defaults:
|
|
run:
|
|
working-directory: extension
|
|
permissions:
|
|
contents: write
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 22
|
|
cache: npm
|
|
cache-dependency-path: extension/package-lock.json
|
|
|
|
- name: Install dependencies
|
|
run: npm ci
|
|
|
|
- name: Lint
|
|
run: npm run lint
|
|
|
|
- name: Typecheck
|
|
run: npm run typecheck
|
|
|
|
- name: Test
|
|
run: npm test
|
|
|
|
- name: Build
|
|
run: npm run compile
|
|
|
|
- name: Package .vsix
|
|
run: npm run package
|
|
|
|
- name: Publish to VS Code Marketplace
|
|
env:
|
|
VSCE_PAT: ${{ secrets.VSCE_PAT }}
|
|
run: npm run publish:vsce
|
|
|
|
- name: Publish to Open VSX
|
|
env:
|
|
OVSX_PAT: ${{ secrets.OVSX_PAT }}
|
|
run: npm run publish:ovsx
|
|
|
|
- name: Upload .vsix to GitHub release
|
|
if: startsWith(github.ref, 'refs/tags/v')
|
|
uses: softprops/action-gh-release@v2
|
|
with:
|
|
files: extension/*.vsix
|
|
fail_on_unmatched_files: false
|