Conversation
dfx.json becomes icp.yaml with the same nine canisters: the Rust and Motoko canisters use the icp-cli recipes, the two backends that embed their frontend build use a custom build script, and the two asset canisters stay on the legacy asset canister (pinned to the SDK 0.31.0 release) so the e2e tests keep testing the same canister. Declarations come from @icp-sdk/bindgen (pnpm run generate) instead of dfx generate. Its blob type is Uint8Array only, so the example tests type their requests with the canister's HttpRequest. The Motoko backend moves to mops with mo:core and a committed backend.did. The JS build and e2e jobs run in ghcr.io/dfinity/icp-dev-env-all:v2.2.1; the release workflows only swap dfx generate for pnpm run generate.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Pull-request-controlled jobs receive a job-wide token without explicit least-privilege permissions.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 2
Open (3)
What changed in this PR
Migrates canister builds, declaration generation, tests, and CI from dfx to icp-cli.
Changes:
- Adds
icp.yaml, Mops configuration, and bindgen-based declaration generation. - Updates test paths, generated declaration imports, and replica environment variables.
- Moves CI build and e2e jobs to the ICP development container.
| File | Description |
|---|---|
scripts/generate-declarations.sh |
Generates Candid bindings. |
scripts/e2e.sh |
Runs e2e tests with icp-cli. |
README.md |
Updates development prerequisites. |
pnpm-lock.yaml |
Locks bindgen dependencies. |
packages/ic-response-verification-tests/src/wasm-tests/src/main.ts |
Renames the replica environment variable. |
packages/ic-response-verification-tests/src/rust-tests/src/main.rs |
Renames the replica environment variable. |
package.json |
Adds declaration generation tooling. |
mops.toml |
Configures Motoko dependencies and canister. |
mops.lock |
Locks Motoko dependencies. |
icp.yaml |
Defines icp-cli canister builds. |
examples/http-certification/upgrade-to-update-call/src/tests/src/wasm.ts |
Updates declarations and WASM paths. |
examples/http-certification/upgrade-to-update-call/src/tests/src/http.spec.ts |
Updates declaration imports. |
examples/http-certification/upgrade-to-update-call/src/motoko-backend/main.mo |
Migrates to mo:core. |
examples/http-certification/upgrade-to-update-call/src/motoko-backend/backend.did |
Adds the Motoko Candid interface. |
examples/http-certification/skip-certification/src/tests/src/wasm.ts |
Updates declaration imports. |
examples/http-certification/skip-certification/src/tests/src/http.spec.ts |
Uses generated request types. |
examples/http-certification/json-api/src/tests/src/wasm.ts |
Updates declaration imports. |
examples/http-certification/json-api/src/tests/src/todos.spec.ts |
Uses generated request types. |
examples/http-certification/json-api/src/tests/src/response.ts |
Updates declaration imports. |
examples/http-certification/custom-assets/src/tests/src/wasm.ts |
Updates declaration imports. |
examples/http-certification/custom-assets/src/tests/src/http.spec.ts |
Uses generated request types. |
examples/http-certification/assets/src/tests/src/wasm.ts |
Updates declaration imports. |
examples/http-certification/assets/src/tests/src/http.spec.ts |
Uses generated request types. |
examples/certification/certified-counter/src/frontend/src/index.ts |
Updates declaration imports. |
dfx.json |
Removes the legacy dfx configuration. |
.prettierignore |
Ignores icp-cli and Mops output. |
.gitignore |
Ignores generated icp-cli and Mops files. |
.github/workflows/release.yml |
Uses bindgen during releases. |
.github/workflows/e2e-tests.yml |
Runs e2e tests in the ICP container. |
.github/workflows/create-release-pr.yml |
Uses bindgen for release PRs. |
.github/workflows/build-and-test.yml |
Builds canisters with icp-cli. |
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
The token only lets icp-cli fetch recipe releases without rate limits, so the two workflows declare contents: read and expose it to the steps that run icp. Also fixes the REPLICA_ADDRESS diagnostic.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The cross-cutting toolchain migration relies on external recipe and container behavior that static review cannot fully validate.
Review effort: Balanced
Findings: None
Resolved since last review (3)
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
marc0olo
marked this pull request as ready for review
September 25, 2026 15:36
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Replaces dfx with icp-cli for building, testing and CI, with no behavior change: every existing test runs unchanged and passes. The examples' runtime and docs follow in the stacked PR above.
dfx.json→icp.yaml, same nine canisters and names.@dfinity/rust@v3.4.0and the Motoko canister uses@dfinity/motoko@v5.1.0.optimize: cycleshas no recipe equivalent. It only affects wasm size, and nothing is deployed to mainnet.@dfinity/asset-canister@v2.3.0pinned to the SDK 0.31.0 wasm thatdfx.jsonused. Moving the tests to the certified-assets canister changes what they test (it is v2-only and has no SPA fallback), so that is a follow-up.@icp-sdk/bindgen(pnpm run generate) instead ofdfx generate.blobtype isUint8Array, notUint8Array | number[], so the example tests type their requests with the canister'sHttpRequest.^0.4.0(the lockfile resolves 0.4.0) because 0.4.1 is inside the workspace's 7-dayminimumReleaseAge.mops.toml,mops.lock,mo:coreinstead ofmo:base) with a committedbackend.did.ghcr.io/dfinity/icp-dev-env-all:v2.2.1and useicp buildand an icp-clie2e.sh(--use-latest-dfxis gone). The release workflows only swapdfx generateforpnpm run generate; their publishing setup is unchanged.DFX_REPLICA_ADDRESSis renamed toREPLICA_ADDRESS. Both container workflows declarepermissions: contents: readand passICP_CLI_GITHUB_TOKEN(used only to read recipe releases) to theicpsteps alone.Verified locally inside
icp-dev-env-all:v2.2.1:pnpm build,icp build, all example PocketIC suites, thecertificate-verification-jstests and the format check.e2e.sh, including the v1 and v2 Rust and JS e2e suites.wasm-bindgen-test-runnerneeds glibc 2.38, and the image has 2.36; x86_64 gets a static musl build.