Skip to content

chore: migrate build, tests and CI from dfx to icp-cli - #500

Open
marc0olo wants to merge 3 commits into
mainfrom
chore/migrate-dfx-to-icp-cli
Open

marc0olo wants to merge 3 commits into
mainfrom
chore/migrate-dfx-to-icp-cli

Conversation

@marc0olo

@marc0olo marc0olo commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Replaces dfx with icp-cli for building, testing and CI, with no behavior change: every existing test runs unchanged and passes. The examples' runtime and docs follow in the stacked PR above.

  • dfx.json → icp.yaml, same nine canisters and names.
    • Rust canisters use @dfinity/rust@v3.4.0 and the Motoko canister uses @dfinity/motoko@v5.1.0.
    • The two backends that embed their frontend build use a custom build script: frontend first, then cargo, Candid metadata, shrink and gzip.
    • dfx's optimize: cycles has no recipe equivalent. It only affects wasm size, and nothing is deployed to mainnet.
  • The e2e test target stays the legacy asset canister, via @dfinity/asset-canister@v2.3.0 pinned to the SDK 0.31.0 wasm that dfx.json used. Moving the tests to the certified-assets canister changes what they test (it is v2-only and has no SPA fallback), so that is a follow-up.
  • Declarations come from @icp-sdk/bindgen (pnpm run generate) instead of dfx generate.
    • Its blob type is Uint8Array, not Uint8Array | number[], so the example tests type their requests with the canister's HttpRequest.
    • It is ^0.4.0 (the lockfile resolves 0.4.0) because 0.4.1 is inside the workspace's 7-day minimumReleaseAge.
  • Motoko: the backend moves to mops (mops.toml, mops.lock, mo:core instead of mo:base) with a committed backend.did.
  • CI: the JS build and e2e jobs run in ghcr.io/dfinity/icp-dev-env-all:v2.2.1 and use icp build and an icp-cli e2e.sh (--use-latest-dfx is gone). The release workflows only swap dfx generate for pnpm run generate; their publishing setup is unchanged. DFX_REPLICA_ADDRESS is renamed to REPLICA_ADDRESS. Both container workflows declare permissions: contents: read and pass ICP_CLI_GITHUB_TOKEN (used only to read recipe releases) to the icp steps alone.

Verified locally inside icp-dev-env-all:v2.2.1:

  • JS job: pnpm build, icp build, all example PocketIC suites, the certificate-verification-js tests and the format check.
  • e2e: e2e.sh, including the v1 and v2 Rust and JS e2e suites.
  • The wasm-pack tests: run on amd64, CI's architecture. On arm64 the downloaded wasm-bindgen-test-runner needs glibc 2.38, and the image has 2.36; x86_64 gets a static musl build.

dfx.json becomes icp.yaml with the same nine canisters: the Rust and Motoko
canisters use the icp-cli recipes, the two backends that embed their frontend
build use a custom build script, and the two asset canisters stay on the legacy
asset canister (pinned to the SDK 0.31.0 release) so the e2e tests keep testing
the same canister.

Declarations come from @icp-sdk/bindgen (pnpm run generate) instead of
dfx generate. Its blob type is Uint8Array only, so the example tests type their
requests with the canister's HttpRequest. The Motoko backend moves to mops with
mo:core and a committed backend.did.

The JS build and e2e jobs run in ghcr.io/dfinity/icp-dev-env-all:v2.2.1; the
release workflows only swap dfx generate for pnpm run generate.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Pull-request-controlled jobs receive a job-wide token without explicit least-privilege permissions.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 2 High severity · 1 Low severity

Open (3)
What changed in this PR

Migrates canister builds, declaration generation, tests, and CI from dfx to icp-cli.

Changes:

  • Adds icp.yaml, Mops configuration, and bindgen-based declaration generation.
  • Updates test paths, generated declaration imports, and replica environment variables.
  • Moves CI build and e2e jobs to the ICP development container.
File Description
scripts/​generate-declarations.sh Generates Candid bindings.
scripts/​e2e.sh Runs e2e tests with icp-cli.
README.md Updates development prerequisites.
pnpm-lock.yaml Locks bindgen dependencies.
packages/​ic-response-verification-tests/​src/​wasm-tests/​src/​main.ts Renames the replica environment variable.
packages/​ic-response-verification-tests/​src/​rust-tests/​src/​main.rs Renames the replica environment variable.
package.json Adds declaration generation tooling.
mops.toml Configures Motoko dependencies and canister.
mops.lock Locks Motoko dependencies.
icp.yaml Defines icp-cli canister builds.
examples/​http-certification/​upgrade-to-update-call/​src/​tests/​src/​wasm.ts Updates declarations and WASM paths.
examples/​http-certification/​upgrade-to-update-call/​src/​tests/​src/​http.spec.ts Updates declaration imports.
examples/​http-certification/​upgrade-to-update-call/​src/​motoko-backend/​main.mo Migrates to mo:core.
examples/​http-certification/​upgrade-to-update-call/​src/​motoko-backend/​backend.did Adds the Motoko Candid interface.
examples/​http-certification/​skip-certification/​src/​tests/​src/​wasm.ts Updates declaration imports.
examples/​http-certification/​skip-certification/​src/​tests/​src/​http.spec.ts Uses generated request types.
examples/​http-certification/​json-api/​src/​tests/​src/​wasm.ts Updates declaration imports.
examples/​http-certification/​json-api/​src/​tests/​src/​todos.spec.ts Uses generated request types.
examples/​http-certification/​json-api/​src/​tests/​src/​response.ts Updates declaration imports.
examples/​http-certification/​custom-assets/​src/​tests/​src/​wasm.ts Updates declaration imports.
examples/​http-certification/​custom-assets/​src/​tests/​src/​http.spec.ts Uses generated request types.
examples/​http-certification/​assets/​src/​tests/​src/​wasm.ts Updates declaration imports.
examples/​http-certification/​assets/​src/​tests/​src/​http.spec.ts Uses generated request types.
examples/​certification/​certified-counter/​src/​frontend/​src/​index.ts Updates declaration imports.
dfx.json Removes the legacy dfx configuration.
.prettierignore Ignores icp-cli and Mops output.
.gitignore Ignores generated icp-cli and Mops files.
.github/​workflows/​release.yml Uses bindgen during releases.
.github/​workflows/​e2e-tests.yml Runs e2e tests in the ICP container.
.github/​workflows/​create-release-pr.yml Uses bindgen for release PRs.
.github/​workflows/​build-and-test.yml Builds canisters with icp-cli.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/build-and-test.yml Outdated
Comment thread .github/workflows/e2e-tests.yml Outdated
Comment thread packages/ic-response-verification-tests/src/rust-tests/src/main.rs Outdated
The token only lets icp-cli fetch recipe releases without rate limits, so the
two workflows declare contents: read and expose it to the steps that run icp.
Also fixes the REPLICA_ADDRESS diagnostic.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The cross-cutting toolchain migration relies on external recipe and container behavior that static review cannot fully validate.

Review effort: Balanced
Findings: None

Resolved since last review (3)
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

@marc0olo
marc0olo marked this pull request as ready for review September 25, 2026 15:36
@marc0olo
marc0olo requested a review from a team as a code owner September 25, 2026 15:36

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants