Files
mdts-desktop/.github/workflows/ci.yml
T
JMR-dev 9b94d33824 ci: add CI workflow and Dependabot config
Run the static checks (format, lint, typecheck, exception audit, npm
registry signatures) and the unit suite with its coverage gate on every
pull request and push to main. The workflow is also callable, so the
release workflow can require the same gates before building.

Every action is pinned to the full commit SHA of its latest release, as
the repository now requires. actionlint runs from a checksum-verified
release binary and zizmor audits the workflows. Dependabot keeps npm
packages and the action pins current, after a 7-day cooldown that
zizmor asks for to avoid picking up freshly published malicious
versions.
2026-09-28 15:52:59 -05:00

90 lines
2.9 KiB
YAML

name: CI
on:
pull_request:
push:
branches: [main]
workflow_call:
permissions: {}
concurrency:
group: ci-${{ github.ref }}-${{ github.event_name }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
static:
name: Static checks
runs-on: ubuntu-24.04
permissions:
contents: read
steps:
- uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: .nvmrc
cache: npm
- run: npm ci
- run: npm audit signatures
- run: npm run check
unit:
name: Unit tests
runs-on: ubuntu-24.04
permissions:
contents: read
steps:
- uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: .nvmrc
cache: npm
- run: npm ci
- run: npx playwright install --with-deps chromium
- run: npm run test:unit
- if: ${{ !cancelled() }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: unit-coverage
path: coverage/
retention-days: 14
workflows:
name: Workflow lint
runs-on: ubuntu-24.04
permissions:
contents: read
env:
ACTIONLINT_VERSION: 1.7.12
ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
steps:
- uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install actionlint
run: |
archive="actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
curl --fail --silent --show-error --location --output "${RUNNER_TEMP}/${archive}" \
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/${archive}"
echo "${ACTIONLINT_SHA256} ${RUNNER_TEMP}/${archive}" | sha256sum --check --strict
tar --extract --gzip --file "${RUNNER_TEMP}/${archive}" --directory "${RUNNER_TEMP}" actionlint
- run: '"${RUNNER_TEMP}/actionlint" -color'
- uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
with:
version: 1.30.1
advanced-security: false
persona: pedantic