-
Notifications
You must be signed in to change notification settings - Fork 63
181 lines (150 loc) · 4.54 KB
/
Copy pathci.yml
File metadata and controls
181 lines (150 loc) · 4.54 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
name: CI
on:
pull_request:
branches: [main]
# Skip the matrix when a PR touches only docs / templates so we don't
# burn CI minutes on changes that can't possibly break a build.
paths-ignore:
- '**/*.md'
- 'docs/**'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE.md'
- CHANGELOG.md
- LICENSE
- CODE_OF_CONDUCT.md
- CONTRIBUTING.md
push:
branches: [main]
paths-ignore:
- '**/*.md'
- 'docs/**'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE.md'
- CHANGELOG.md
- LICENSE
- CODE_OF_CONDUCT.md
- CONTRIBUTING.md
# Cancel any previous in-progress run for the same ref so we don't burn
# runner minutes on superseded pushes while a PR is iterating.
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
# All jobs only need to read the repo.
permissions:
contents: read
jobs:
contracts:
name: Contracts (Rust / Soroban)
runs-on: ubuntu-latest
defaults:
working-directory: contracts
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
targets: wasm32-unknown-unknown
components: rustfmt, clippy
- name: Cache cargo artifacts
uses: Swatinem/rust-cache@v2
with:
workspaces: contracts
- name: cargo fmt
run: cargo fmt --all -- --check
- name: cargo clippy (deny warnings)
run: cargo clippy --workspace --all-targets -- -D warnings
- name: cargo check
run: cargo check --workspace --all-targets
- name: cargo test
run: cargo test --workspace
# Sanity check only: catches compile failures on the deploy target.
# Does NOT run `wasm-opt` — production Soroban artifacts come from
# `soroban contract build`, which adds the optimizer pass. Wire that
# in if CI artifacts ever become the release source.
# (`--locked` is intentionally omitted: Soroban contract crates
# conventionally don't commit Cargo.lock.)
- name: cargo build (wasm32 release)
run: cargo build --workspace --target wasm32-unknown-unknown --release
backend:
name: Backend (NestJS)
runs-on: ubuntu-latest
defaults:
working-directory: Backend
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version-file: .nvmrc
cache: npm
cache-dependency-path: package-lock.json
- name: Install dependencies
run: npm ci
- name: Lint
run: npm run lint
- name: Unit tests
run: npm test -- --runInBand
# `nest build` invokes tsc, so this doubles as the typecheck step.
- name: Build
run: npm run build
frontend:
name: Frontend (Next.js)
runs-on: ubuntu-latest
defaults:
working-directory: Frontend
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version-file: .nvmrc
cache: npm
cache-dependency-path: package-lock.json
- name: Install dependencies
run: npm ci
- name: Lint
run: npm run lint
# Next.js's `build` runs the TypeScript compiler end-to-end, so this
# doubles as the typecheck step.
- name: Build
run: npm run build
analytics:
name: Analytics (Next.js)
runs-on: ubuntu-latest
defaults:
working-directory: analytics
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version-file: .nvmrc
cache: npm
cache-dependency-path: package-lock.json
- name: Install dependencies
run: npm ci
- name: Lint
run: npm run lint
- name: Typecheck
run: npm run typecheck
- name: Build
run: npm run build
terraform-fmt:
name: Terraform fmt
runs-on: ubuntu-latest
defaults:
working-directory: infrastructure/terraform
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Terraform
uses: hashicorp/setup-terraform@v3
with:
terraform_version: 1.9.8
# No `terraform init` needed: `fmt -check` only inspects source files.
- name: terraform fmt -check
run: terraform fmt -check -recursive