Skip to content

fix(ci): Install the public repo without the private eslint plugin (#29) - #30

Merged
deanzaka merged 2 commits into
masterfrom
fix/1007-integrations-ci
Oct 8, 2026
Merged

deanzaka merged 2 commits into
masterfrom
fix/1007-integrations-ci

Conversation

@johnxie

@johnxie johnxie commented Oct 7, 2026

Copy link
Copy Markdown
Member

Summary

The CI install step failed with a 401 on master and on every PR, because package.json listed the private @taskade/eslint-plugin. This PR removes the private package and lints with public packages only. Anyone can now install, lint, build and test this public repo with no registry token. The README also gets a platform status table and a corrected list of Zapier operations.

Production signal

Root cause

GitHub Packages serves @taskade/eslint-plugin only to accounts with taskade organization access. The public runner gets a 401. The package was lint-only, but it sat in dependencies, and no script or CI step ran lint.

PR #20 had a fix. It was closed and folded into PR #19, which also moves the task_due trigger and rewrites the README. PR #19 is still open, so master stayed red.

Fix

File Change
package.json Remove @taskade/eslint-plugin. Add eslint ^8.57.1 and @typescript-eslint/* ^6.21.0 as devDependencies (the versions the lockfile already held). Add yarn lint.
yarn.lock Prunes 100 package entries (prettier, the react plugins, simple-import-sort and their trees). It adds no new package version.
.eslintrc.json Self-contained config: eslint:recommended, @typescript-eslint/recommended, and the core rules of the old plugin (curly, eqeqeq, no-implicit-coercion, no-param-reassign, @typescript-eslint/no-shadow). It drops prettier, react and import-sort. no-var-requires and ban-ts-comment are off for the 3 existing call sites, so no source file changes.
.github/workflows/ci.yml Add yarn lint after install.
README.md Add a Status table (Zapier live, n8n not yet on npm, Activepieces/Make/Pipedream planned). List all 6 instant triggers, 22 actions and 2 searches that src/index.ts registers. The old note said that the public webhook API was "in progress", but 5 triggers already use it.

Tests

All runs used an empty HOME (no .npmrc or .yarnrc auth), an empty yarn cache folder, and no NPM_TOKEN:

  • yarn install --frozen-lockfile: pass (master fails here with the 401).
  • yarn lint: 0 errors, 0 warnings. With the old private config, master had 3 errors and 10 prettier warnings.
  • yarn build: pass.
  • yarn test: 5 of 5 pass (Zapier schema validation included).
  • A probe file with ==, a brace-less if, any and !!x gets 4 errors, so the rules are active.

The CI run on this PR is the first green build-and-test run on a branch based on master.

Risk and rollback

Risk is low. No runtime source file changes. The Zapier bundle gets smaller, because the lint packages leave dependencies. Rollback: revert this commit.

Overlap: PR #19 carries the same CI fix together with the task_due move. After this merges, PR #19 needs a master merge and keeps only its trigger and README work.

Closes #29

Remove the private @taskade/eslint-plugin. CI got a 401 for it at install.
Add public eslint and @typescript-eslint devDependencies at the locked versions.
Replace .eslintrc.json with a self-contained config, and add a lint step to CI.
Add a platform status table to the README and correct its operation list.
Copilot AI balanced review requested due to automatic review settings October 7, 2026 23:52

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The updated README exposes a central contradiction about whether all integrations use only public APIs.

1 open finding
What changed in this PR

Removes the private ESLint dependency so public CI and contributor installs work without registry credentials.

Changes:

  • Replaces private lint tooling with public ESLint packages and configuration.
  • Adds linting to CI and prunes obsolete lockfile dependencies.
  • Updates README platform status and Zapier capabilities.
File Description
.eslintrc.json Adds self-contained TypeScript lint rules.
.github/​workflows/​ci.yml Runs lint in CI.
package.json Replaces private dependency and adds lint script.
README.md Updates platform and operation documentation.
yarn.lock Removes private and unused dependency trees.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread README.md
@johnxie
johnxie requested a balanced review from Copilot October 7, 2026 23:55
@johnxie

johnxie commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

@johnxie

johnxie commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

@deanzaka Impact of this PR: CI on taskade/integrations goes green again for every PR. The install step no longer pulls the private @taskade/eslint-plugin, so the public runner and external contributors install with no registry token. Lint now runs in CI with public eslint and @typescript-eslint. No runtime code changes, and the Zapier bundle gets smaller. The README gets a platform status table and the full Zapier operation list. Risk is low. Rollback: revert the PR.

Before / after flow

Before
+-------------------+     +------------------------------+     +-----------------------+
| PR or master push | --> | yarn install --frozen-lockfile| --> | GET npm.pkg.github.com|
+-------------------+     +------------------------------+     | @taskade/eslint-plugin|
                                                               +-----------+-----------+
                                                                           |
                                                                           v
                                                               +-----------------------+
                                                               | 401 Unauthorized      |
                                                               | job fails, no build,  |
                                                               | no tests              |
                                                               +-----------------------+
After
+-------------------+     +------------------------------+     +-----------------------+
| PR or master push | --> | yarn install --frozen-lockfile| --> | registry.yarnpkg.com  |
+-------------------+     +------------------------------+     | public packages only  |
                                                               +-----------+-----------+
                                                                           |
                                                                           v
                          +-----------+     +------------+     +-----------------------+
                          | yarn test | <-- | yarn build | <-- | yarn lint (public     |
                          | 5 pass    |     | tsc        |     | eslint config)        |
                          +-----------+     +------------+     +-----------------------+

How to QA

Step Where / setup Action Expected result
1 PR #30 checks tab Open the build-and-test job Install, lint, build and test steps all pass
2 Local clone of this branch, empty home dir: mkdir /tmp/h && export HOME=/tmp/h, unset NPM_TOKEN yarn install --frozen-lockfile --cache-folder /tmp/yc Install completes. No request to npm.pkg.github.com
3 Same shell yarn lint && yarn build && yarn test Lint has 0 problems. Tests: 5 passed
4 Edge case: same shell Add if (a == b) x(); to a file in src/, then yarn lint Lint fails with eqeqeq and curly errors. Remove the line after
5 README.md on this branch Read the Status and capabilities tables, then compare with src/index.ts Every registered key is listed. n8n shows "not yet published to npm"
6 Rollback check git revert the PR commits on a scratch branch, then repeat step 2 Install fails again with the 401, which confirms the cause

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The dependency, lint configuration, workflow, lockfile, and documentation changes are consistent and address the reported CI failure.

0 open findings

1 resolved since last review

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

@deanzaka
deanzaka merged commit ff1ad6c into master Oct 8, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI install fails with 401 on the private @taskade/eslint-plugin

3 participants