Skip to content

feat: v1.7.0 — add Vercel Web Analytics and a privacy page #46

feat: v1.7.0 — add Vercel Web Analytics and a privacy page

feat: v1.7.0 — add Vercel Web Analytics and a privacy page #46

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm lint
typecheck:
name: Type check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm typecheck
test:
name: Unit tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm test --run
build:
name: Build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm build
e2e:
name: E2E
runs-on: ubuntu-latest
needs: [lint, typecheck, test, build]
# Playwright's official image ships chromium/webkit and all their OS
# deps preinstalled — avoids `playwright install --with-deps` re-running
# a full apt-get against the Ubuntu package mirror on every single run
# (measured 10+ minutes on a slow mirror day, vs. a fast image pull).
# Version must match the resolved `@playwright/test` version exactly
# (pnpm-lock.yaml) or Playwright refuses to run — bump both together.
container:
image: mcr.microsoft.com/playwright:v1.62.1-noble
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm build
- run: pnpm e2e
env:
CI: true
e2e-infralens:
name: E2E — InfraLens
runs-on: ubuntu-latest
needs: [lint, typecheck, test, build]
# Same rationale as the `e2e` job above — this one felt it most, since
# webkit's own dependency tree (media/audio/video libs) is far larger
# than chromium's.
container:
image: mcr.microsoft.com/playwright:v1.62.1-noble
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm build
# Serialized (--workers=1, see playwright.config.ts) — not because CI
# itself is rate-limited (it never has Upstash credentials, so
# src/lib/rate-limit runs allow-all here), but because this same
# script also runs locally, where a developer may have added real
# credentials and would hit the genuine InfraLens policy. Staying
# serialized keeps that case safe without needing to know which one
# is active.
- run: pnpm e2e:infralens
env:
CI: true