-
Notifications
You must be signed in to change notification settings - Fork 0
138 lines (123 loc) · 3.58 KB
/
Copy pathci.yml
File metadata and controls
138 lines (123 loc) · 3.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
name: CI
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm lint
typecheck:
name: Type check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm typecheck
test:
name: Unit tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm test --run
build:
name: Build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm build
e2e:
name: E2E
runs-on: ubuntu-latest
needs: [lint, typecheck, test, build]
# Playwright's official image ships chromium/webkit and all their OS
# deps preinstalled — avoids `playwright install --with-deps` re-running
# a full apt-get against the Ubuntu package mirror on every single run
# (measured 10+ minutes on a slow mirror day, vs. a fast image pull).
# Version must match the resolved `@playwright/test` version exactly
# (pnpm-lock.yaml) or Playwright refuses to run — bump both together.
container:
image: mcr.microsoft.com/playwright:v1.62.1-noble
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm build
- run: pnpm e2e
env:
CI: true
e2e-infralens:
name: E2E — InfraLens
runs-on: ubuntu-latest
needs: [lint, typecheck, test, build]
# Same rationale as the `e2e` job above — this one felt it most, since
# webkit's own dependency tree (media/audio/video libs) is far larger
# than chromium's.
container:
image: mcr.microsoft.com/playwright:v1.62.1-noble
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
with:
version: 10.7.0
- uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm build
# Serialized (--workers=1, see playwright.config.ts) — not because CI
# itself is rate-limited (it never has Upstash credentials, so
# src/lib/rate-limit runs allow-all here), but because this same
# script also runs locally, where a developer may have added real
# credentials and would hit the genuine InfraLens policy. Staying
# serialized keeps that case safe without needing to know which one
# is active.
- run: pnpm e2e:infralens
env:
CI: true