forked from InsurNiffy/niff-Stellar-shurance
-
Notifications
You must be signed in to change notification settings - Fork 0
172 lines (147 loc) · 5.95 KB
/
Copy pathci.yml
File metadata and controls
172 lines (147 loc) · 5.95 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
name: CI
on:
push:
branches: [main, "feat/**", "fix/**"]
pull_request:
env:
CARGO_TERM_COLOR: always
jobs:
# ── Smart contract ────────────────────────────────────────────────────────
contract:
name: Contract (Rust / Soroban)
runs-on: ubuntu-latest
env:
RUSTFLAGS: "-D warnings"
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
with:
targets: wasm32-unknown-unknown
components: rustfmt, clippy
- uses: actions/cache@v4
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-${{ hashFiles('**/Cargo.lock') }}
- run: cargo fmt --all -- --check
- run: cargo clippy --target wasm32-unknown-unknown --release -- -D warnings
- run: cargo test
- run: cargo build --target wasm32-unknown-unknown --release
- name: Record wasm SHA-256
run: sha256sum target/wasm32-unknown-unknown/release/niffyinsure.wasm | tee niffyinsure.wasm.sha256
- name: Simulate wasm drift (staging acceptance test)
run: |
ACTUAL=$(cat niffyinsure.wasm.sha256 | awk '{print $1}')
EXPECTED=$(jq -r '.contracts[0].expectedWasmHash' contracts/deployment-registry.json)
# In CI the registry holds a placeholder; drift is detected when they differ.
# In staging, set NIFFYINSURE_EXPECTED_WASM_HASH to a known-wrong value to
# verify the alert path fires. Exit 0 here — alerting is runtime, not build-time.
if [ "$EXPECTED" = "\${NIFFYINSURE_EXPECTED_WASM_HASH}" ]; then
echo "Registry uses env placeholder — skipping drift comparison in CI"
elif [ "$ACTUAL" != "$EXPECTED" ]; then
echo "::warning::Wasm drift detected: expected=$EXPECTED actual=$ACTUAL"
else
echo "Wasm hash matches registry: $ACTUAL"
fi
- uses: actions/upload-artifact@v4
with:
name: niffyinsure-wasm-${{ github.sha }}
path: |
target/wasm32-unknown-unknown/release/niffyinsure.wasm
niffyinsure.wasm.sha256
retention-days: 30
# ── Backend ───────────────────────────────────────────────────────────────
backend:
name: Backend (Node / TypeScript)
runs-on: ubuntu-latest
defaults:
run:
working-directory: backend
services:
redis:
image: redis:7-alpine
ports:
- 6379:6379
options: >-
--health-cmd "redis-cli ping"
--health-interval 5s
--health-timeout 3s
--health-retries 5
--health-start-period 5s
env:
REDIS_HOST: 127.0.0.1
REDIS_PORT: 6379
NODE_ENV: test
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
- run: npm install
- run: npm run lint
- run: npm run build
- run: npm test
# ── Dependency audit / supply-chain ─────────────────────────────────────
# Policy: CRITICAL CVEs fail the build. HIGH CVEs produce a warning and
# must be triaged within 7 days. Accepted risks require a signed-off entry
# in docs/ops/audit-exceptions.md before the override label is applied.
# Override process:
# 1. Engineer opens a PR adding the CVE to audit-exceptions.md with
# justification, mitigations, and a review-by date.
# 2. A second engineer approves the PR.
# 3. Add the GitHub label `audit-exception-approved` to the failing PR.
# 4. Re-run this job — it will pass once the exception is documented.
dependency-audit:
name: Dependency Audit (npm / SBOM)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
- name: Audit backend dependencies
working-directory: backend
run: |
npm install --ignore-scripts
# Fail on critical; warn on high (exit 0 so we can capture output)
npm audit --audit-level=critical
npm audit --audit-level=high || echo "::warning::High-severity advisories found — triage within 7 days per audit policy"
- name: Audit frontend dependencies
working-directory: frontend
run: |
npm ci --ignore-scripts
npm audit --audit-level=critical
npm audit --audit-level=high || echo "::warning::High-severity advisories found — triage within 7 days per audit policy"
- name: Generate SBOM (backend)
working-directory: backend
run: npx --yes @cyclonedx/cyclonedx-npm --output-format JSON --output-file ../sbom-backend.json
- name: Generate SBOM (frontend)
working-directory: frontend
run: npx --yes @cyclonedx/cyclonedx-npm --output-format JSON --output-file ../sbom-frontend.json
- uses: actions/upload-artifact@v4
with:
name: sbom-${{ github.sha }}
path: |
sbom-backend.json
sbom-frontend.json
retention-days: 90
# ── Frontend ──────────────────────────────────────────────────────────────
frontend:
name: Frontend (Next.js / TypeScript)
runs-on: ubuntu-latest
defaults:
run:
working-directory: frontend
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
cache: npm
cache-dependency-path: frontend/package-lock.json
- run: npm ci
- run: npm run lint
- run: npm run build
- run: npm test