A TypeScript config can evaluate differently on another machine. vx lock evaluates every config now and writes the resolved objects to vx-lock.json.
vx run --frozen loads configs from the lock and evaluates nothing. vx lock --check re-evaluates every config and fails on drift, so a pipeline can check the lock first.
More in CI

Run only what a change reaches
--affected follows task edges from the change, and nothing else runs.

Flaky task detection
Local and free: the same key failing after it passed is called flaky.

Results on GitHub
Every run on GitHub Actions writes a job summary and a check.

Results on the pull request
A check run on the commit carries the run summary, failures first.

Cache scope from the branch
On Actions, main writes trusted cache entries and a pull request writes only its own.
