Skip to main content
The pull-request job should prove the file is clean, inspect the authority and spend shape, then rehearse the graph with the mock provider.

Admission script

Authority ladder

CI ADMISSION · SECRETS ARRIVE LAST
The shown mock workflow needs no provider key. Rehearsal fixtures must also have safe tool boundaries: a mock model does not disable external effects. Protected execution receives only the authority its environment and workflow declare.

Pin and print both versions

Keep the engine and SDK release train visible in logs. Do not debug skew from an implicit global binary — and do not npm exec -- nika an uninstalled name: with no locked local package, npm would download whatever that name resolves to. The direct node_modules/.bin path only ever runs the lockfile’s payload.
Commit the package lockfile and keep optional platform dependencies enabled. The local npm executable above resolves the project’s installed package; it does not require a global CLI. Pin the SDK and native payload together. A newer standalone engine release does not update an existing npm install.

Continue

GitHub Actions

Use the Nika action for PR comments and receipts.

Check and plan

Read every admission field.

Security

Keep authority explicit.

Testing

Design deterministic mock goldens.