From 9b94d3382405ec5af879fdc96b7e1e9332277305 Mon Sep 17 00:00:00 2001 From: Jason Ross Date: Mon, 28 Sep 2026 15:52:59 -0500 Subject: [PATCH] ci: add CI workflow and Dependabot config Run the static checks (format, lint, typecheck, exception audit, npm registry signatures) and the unit suite with its coverage gate on every pull request and push to main. The workflow is also callable, so the release workflow can require the same gates before building. Every action is pinned to the full commit SHA of its latest release, as the repository now requires. actionlint runs from a checksum-verified release binary and zizmor audits the workflows. Dependabot keeps npm packages and the action pins current, after a 7-day cooldown that zizmor asks for to avoid picking up freshly published malicious versions. --- .github/dependabot.yml | 22 ++++++++++ .github/workflows/ci.yml | 89 ++++++++++++++++++++++++++++++++++++++++ 2 files changed, 111 insertions(+) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/ci.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..848db22 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,22 @@ +version: 2 +updates: + - package-ecosystem: npm + directory: / + schedule: + interval: weekly + cooldown: + default-days: 7 + groups: + production: + dependency-type: production + development: + dependency-type: development + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + cooldown: + default-days: 7 + groups: + actions: + patterns: ['*'] diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..b647430 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,89 @@ +name: CI + +on: + pull_request: + push: + branches: [main] + workflow_call: + +permissions: {} + +concurrency: + group: ci-${{ github.ref }}-${{ github.event_name }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + +jobs: + static: + name: Static checks + runs-on: ubuntu-24.04 + permissions: + contents: read + steps: + - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 + with: + egress-policy: audit + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version-file: .nvmrc + cache: npm + - run: npm ci + - run: npm audit signatures + - run: npm run check + + unit: + name: Unit tests + runs-on: ubuntu-24.04 + permissions: + contents: read + steps: + - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 + with: + egress-policy: audit + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version-file: .nvmrc + cache: npm + - run: npm ci + - run: npx playwright install --with-deps chromium + - run: npm run test:unit + - if: ${{ !cancelled() }} + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: unit-coverage + path: coverage/ + retention-days: 14 + + workflows: + name: Workflow lint + runs-on: ubuntu-24.04 + permissions: + contents: read + env: + ACTIONLINT_VERSION: 1.7.12 + ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 + steps: + - uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 + with: + egress-policy: audit + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - name: Install actionlint + run: | + archive="actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" + curl --fail --silent --show-error --location --output "${RUNNER_TEMP}/${archive}" \ + "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/${archive}" + echo "${ACTIONLINT_SHA256} ${RUNNER_TEMP}/${archive}" | sha256sum --check --strict + tar --extract --gzip --file "${RUNNER_TEMP}/${archive}" --directory "${RUNNER_TEMP}" actionlint + - run: '"${RUNNER_TEMP}/actionlint" -color' + - uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4 + with: + version: 1.30.1 + advanced-security: false + persona: pedantic