ci: add a dispatchable sfw CI simulation - #21
Conversation
7dd5455 to
79af52b
Compare
79af52b to
79ef90f
Compare
7aa241b to
6aa81e0
Compare
Reproduces a customer CI shape, this action installing sfw followed by an explicit `sfw npm install`, against the checked-out action, so a change to the action or to the sfw binary it pins can be measured before it is announced. The candidate is always `./`. The fixture install is repeated N times per runner (windows-2025, windows-11-arm, ubuntu-26.04) for the candidate and a baseline action ref, each failure classified by symptom, and the report job aggregates a flake table into the run summary, splitting binary download failures out of the setup failures via the install jobs' annotations. A measurement, not a pass/fail test, so it is dispatched rather than run on every PR. Fleet form: inline bootstrap checkout, fleet artifact composites, no third-party actions, pinned runner images, named steps.
6aa81e0 to
d087b21
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix prepared a fix for the issue found in the latest run.
- ✅ Fixed: Fleet artifact actions never hydrated
- The install and report jobs now run the tracked fleet checkout composite after bootstrap so upload-artifact and download-artifact exist before those steps resolve.
Or push these changes by commenting:
@cursor push 08fd781737
Preview (08fd781737)
diff --git a/.github/workflows/test-sfw-ci-simulation.yml b/.github/workflows/test-sfw-ci-simulation.yml
--- a/.github/workflows/test-sfw-ci-simulation.yml
+++ b/.github/workflows/test-sfw-ci-simulation.yml
@@ -96,6 +96,14 @@
export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}"
git fetch --no-tags --prune --depth 1 origin "${TRIGGER_REF}"
git checkout -q --detach FETCH_HEAD
+ # Artifact composites are untracked fleet payload. Hydrate them here
+ # so upload-artifact resolves; checkout:false keeps this revision.
+ - name: 'Hydrate fleet Actions'
+ uses: ./.github/actions/fleet/checkout
+ with:
+ checkout: 'false'
+ payload-token-client-id: ${{ secrets.SOCKET_RELEASE_CLIENT_ID || vars.SOCKET_RELEASE_CLIENT_ID }}
+ payload-token-private-key: ${{ secrets.SOCKET_RELEASE_APP_PRIVATE_KEY }}
# The baseline is a second copy of the action at the requested ref, in
# its own directory so `./` stays the candidate.
- name: 'Fetch the baseline action'
@@ -211,6 +219,14 @@
export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}"
git fetch --no-tags --prune --depth 1 origin "${TRIGGER_REF}"
git checkout -q --detach FETCH_HEAD
+ # Artifact composites are untracked fleet payload. Hydrate them here
+ # so download-artifact resolves; checkout:false keeps this revision.
+ - name: 'Hydrate fleet Actions'
+ uses: ./.github/actions/fleet/checkout
+ with:
+ checkout: 'false'
+ payload-token-client-id: ${{ secrets.SOCKET_RELEASE_CLIENT_ID || vars.SOCKET_RELEASE_CLIENT_ID }}
+ payload-token-private-key: ${{ secrets.SOCKET_RELEASE_APP_PRIVATE_KEY }}
- name: 'Download the results'
uses: ./.github/actions/fleet/download-artifact
with:You can send follow-ups to the cloud agent here.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit d087b21. Configure here.
| uses: ./.github/actions/fleet/upload-artifact | ||
| with: | ||
| name: result-install-${{ matrix.os }}-${{ matrix.variant }}-${{ matrix.iteration }} | ||
| path: results/ |
There was a problem hiding this comment.
Fleet artifact actions never hydrated
High Severity
The install and report jobs call the fleet upload-artifact and download-artifact composites after an inline bootstrap only. Those action.yml files are gitignored payload and never land in a plain checkout, so every cell fails at upload and the report job cannot read results.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit d087b21. Configure here.



Why
Verify stability by simulating load in GitHub Actions context. The shape is common to any user running the action plus an explicit
sfw npm installin GitHub Actions.What
One dispatchable workflow,
test-sfw-ci-simulation.yml. A measurement rather than a pass/fail test. Inputs:baseline_action_ref(default: latest tagv1.3.2; empty skips the baseline)fixture_repo(defaultexpressjs/express)iterations(default10)Install — matrix of
windows-2025,windows-11-arm,ubuntu-26.04× candidate/baseline × N iterations. Each job installs sfw withuses: ./(candidate) or a second fetch of the action at the baseline ref, then runssfw npm install --ignore-scriptsin the fixture. Failures are classified by symptom text. Report aggregates a flake table into the run summary and splits binary download failures out ofaction-setup-failedfrom the install jobs' failure annotations.Fleet form throughout: inline bootstrap checkout (no
actions/checkout), fleetupload-artifact/download-artifactcomposites, no third-party actions, pinned runner images, every step named.pnpm run lint --allpasses; the remainingpnpm run checkfailures are machine-local (pricing data, telemetry env, Homebrew, roster).Running it
Simulation cost:
iterations=20with baseline is ~100 install jobs, most on Windows.🤖 Generated with Claude Code
Note
Low Risk
Adds optional CI measurement only; no changes to the action runtime, customer workflows, or release behavior.
Overview
Adds a manually dispatched workflow (
test-sfw-ci-simulation.yml) to measure how reliably the Socket Firewall action plus an explicitsfw npm installbehaves in GitHub Actions—before shipping action or binary changes.Each run repeats installs across windows-2025, windows-11-arm, and ubuntu-26.04, comparing the checked-out ref (candidate) to an optional baseline action ref (default
v1.3.2). Jobs install firewall mode from./or a fetched baseline copy, runsfw npm installin a configurable public fixture (defaultexpressjs/express), classify outcomes (setup failure, PATH, timeouts, libuv, telemetry, etc.), and upload JSON results. A Report job always runs, merges artifacts, writes a flake table to the step summary, and breaks out binary download failures from action-setup annotations via the GitHub API.Uses the repo’s fleet pattern: inline bootstrap checkout (no
actions/checkout), localupload-artifact/download-artifactcomposites, andcontinue-on-errorso the run is measurement—not a gate.Reviewed by Cursor Bugbot for commit d087b21. Configure here.