-
-
Notifications
You must be signed in to change notification settings - Fork 654
203 lines (173 loc) · 6.6 KB
/
Copy pathci.yml
File metadata and controls
203 lines (173 loc) · 6.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
name: CI
on:
pull_request:
branches: [main]
push:
branches: [main]
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
audit:
name: Dependency audit
runs-on: ubuntu-22.04
steps:
- name: Checkout repository
uses: actions/checkout@v6
with:
persist-credentials: false
- name: Set up Node.js
uses: actions/setup-node@v6
with:
node-version: "22"
# Reads package-lock.json and queries the registry — no install needed, so
# this stays fast. Blocking at `high` catches high/critical advisories
# without reddening CI for the moderate/low noise Dependabot handles via PR.
- name: Audit npm dependencies (high and critical)
run: npm audit --audit-level=high
e2e:
name: E2E smoke (Playwright)
runs-on: ubuntu-22.04
steps:
- name: Checkout repository
uses: actions/checkout@v6
with:
persist-credentials: false
- name: Set up Node.js
uses: actions/setup-node@v6
with:
node-version: "22"
cache: npm
cache-dependency-path: package-lock.json
- name: Install dependencies
run: npm ci
- name: Resolve Playwright version
id: pw
run: echo "version=$(node -p "require('@playwright/test/package.json').version")" >> "$GITHUB_OUTPUT"
- name: Cache Playwright browsers
id: pw-cache
uses: actions/cache@v6
with:
path: ~/.cache/ms-playwright
key: playwright-${{ runner.os }}-${{ steps.pw.outputs.version }}
- name: Install Playwright Chromium (cache miss)
if: steps.pw-cache.outputs.cache-hit != 'true'
run: npx playwright install --with-deps chromium
- name: Install Playwright system deps (cache hit)
if: steps.pw-cache.outputs.cache-hit == 'true'
run: npx playwright install-deps chromium
- name: Run E2E smoke tests
run: npm run test:e2e
env:
VITE_GEE_OAUTH_CLIENT_ID: ${{ secrets.VITE_GEE_OAUTH_CLIENT_ID }}
- name: Upload Playwright report
if: ${{ failure() }}
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: |
playwright-report/
test-results/
retention-days: 7
citation:
name: Validate CITATION.cff
runs-on: ubuntu-22.04
steps:
- name: Checkout repository
uses: actions/checkout@v6
with:
persist-credentials: false
- name: Set up Python
uses: actions/setup-python@v6
with:
python-version: "3.12"
- name: Install cffconvert
run: python -m pip install cffconvert
- name: Validate CITATION.cff against the CFF schema
run: cffconvert --validate -i CITATION.cff
- name: Ensure version matches package.json
run: |
cff_version="$(sed -n 's/^version: *//p' CITATION.cff | tr -d '"' | head -n1)"
pkg_version="$(python -c "import json; print(json.load(open('package.json'))['version'])")"
echo "CITATION.cff version: $cff_version"
echo "package.json version: $pkg_version"
if [ "$cff_version" != "$pkg_version" ]; then
echo "::error file=CITATION.cff::version ($cff_version) does not match package.json ($pkg_version). Update CITATION.cff version and date-released when bumping the release version."
exit 1
fi
checks:
name: Build and test
runs-on: ubuntu-22.04
steps:
- name: Checkout repository
uses: actions/checkout@v6
with:
persist-credentials: false
- name: Set up Node.js
uses: actions/setup-node@v6
with:
node-version: "22"
cache: npm
cache-dependency-path: package-lock.json
- name: Set up Python
uses: actions/setup-python@v6
with:
python-version: "3.12"
cache: pip
cache-dependency-path: backend/geolibre_server/pyproject.toml
- name: Install Rust stable
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
toolchain: stable
- name: Cache Rust dependencies
uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
with:
workspaces: apps/geolibre-desktop/src-tauri -> target
- name: Install Linux desktop dependencies
run: |
sudo apt-get update
sudo apt-get install -y \
build-essential \
curl \
file \
libayatana-appindicator3-dev \
libssl-dev \
libwebkit2gtk-4.1-dev \
libxdo-dev \
patchelf \
wget
- name: Install frontend dependencies
run: npm ci
- name: Install backend test dependencies
# The full test suite needs the optional engines; without them the
# vector/raster/SQL/ML tests skip themselves and CI is green but hollow.
run: python -m pip install -e "backend/geolibre_server[test]"
# Audit the resolved backend environment for known advisories. Non-blocking
# (continue-on-error): the sidecar pulls a heavy geospatial/ML dependency
# tree whose transitive advisories are often upstream and not immediately
# fixable, so this surfaces them without halting the release cadence.
# Dependabot opens the fix PRs; this step keeps the signal visible in CI.
#
# pip-audit runs in a throwaway venv against a frozen snapshot of the test
# environment (--exclude-editable drops the local geolibre_server checkout,
# which isn't on PyPI). This keeps its own dependency resolution from
# mutating the environment the "Run CI gate" step below tests against.
- name: Audit Python dependencies (advisory, non-blocking)
continue-on-error: true
run: |
python -m pip freeze --exclude-editable > /tmp/backend-freeze.txt
python -m venv /tmp/pip-audit-venv
/tmp/pip-audit-venv/bin/pip install --quiet pip-audit
/tmp/pip-audit-venv/bin/pip-audit \
--progress-spinner off \
--requirement /tmp/backend-freeze.txt
# Drive the documented `npm run ci` gate directly (lint -> build ->
# frontend+worker+backend coverage -> rust) so this workflow cannot drift
# from the script in package.json.
- name: Run CI gate (lint, build, frontend/worker/backend tests, rust)
run: npm run ci
env:
VITE_GEE_OAUTH_CLIENT_ID: ${{ secrets.VITE_GEE_OAUTH_CLIENT_ID }}