Run the static checks (format, lint, typecheck, exception audit, npm registry signatures) and the unit suite with its coverage gate on every pull request and push to main. The workflow is also callable, so the release workflow can require the same gates before building. Every action is pinned to the full commit SHA of its latest release, as the repository now requires. actionlint runs from a checksum-verified release binary and zizmor audits the workflows. Dependabot keeps npm packages and the action pins current, after a 7-day cooldown that zizmor asks for to avoid picking up freshly published malicious versions.
90 lines
2.9 KiB
YAML
90 lines
2.9 KiB
YAML
name: CI
|
|
|
|
on:
|
|
pull_request:
|
|
push:
|
|
branches: [main]
|
|
workflow_call:
|
|
|
|
permissions: {}
|
|
|
|
concurrency:
|
|
group: ci-${{ github.ref }}-${{ github.event_name }}
|
|
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
|
|
|
jobs:
|
|
static:
|
|
name: Static checks
|
|
runs-on: ubuntu-24.04
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
|
|
with:
|
|
egress-policy: audit
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version-file: .nvmrc
|
|
cache: npm
|
|
- run: npm ci
|
|
- run: npm audit signatures
|
|
- run: npm run check
|
|
|
|
unit:
|
|
name: Unit tests
|
|
runs-on: ubuntu-24.04
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
|
|
with:
|
|
egress-policy: audit
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version-file: .nvmrc
|
|
cache: npm
|
|
- run: npm ci
|
|
- run: npx playwright install --with-deps chromium
|
|
- run: npm run test:unit
|
|
- if: ${{ !cancelled() }}
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: unit-coverage
|
|
path: coverage/
|
|
retention-days: 14
|
|
|
|
workflows:
|
|
name: Workflow lint
|
|
runs-on: ubuntu-24.04
|
|
permissions:
|
|
contents: read
|
|
env:
|
|
ACTIONLINT_VERSION: 1.7.12
|
|
ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
|
|
steps:
|
|
- uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
|
|
with:
|
|
egress-policy: audit
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
- name: Install actionlint
|
|
run: |
|
|
archive="actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
|
|
curl --fail --silent --show-error --location --output "${RUNNER_TEMP}/${archive}" \
|
|
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/${archive}"
|
|
echo "${ACTIONLINT_SHA256} ${RUNNER_TEMP}/${archive}" | sha256sum --check --strict
|
|
tar --extract --gzip --file "${RUNNER_TEMP}/${archive}" --directory "${RUNNER_TEMP}" actionlint
|
|
- run: '"${RUNNER_TEMP}/actionlint" -color'
|
|
- uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
|
|
with:
|
|
version: 1.30.1
|
|
advanced-security: false
|
|
persona: pedantic
|