chore: bump actions/download-artifact from 4 to 8 #227
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| paths-ignore: | |
| - "**/*.md" | |
| - "CLAUDE.md" | |
| - "LICENSE" | |
| - ".beads/**" | |
| pull_request: | |
| branches: [main] | |
| paths-ignore: | |
| - "**/*.md" | |
| - "CLAUDE.md" | |
| - "LICENSE" | |
| - ".beads/**" | |
| env: | |
| CARGO_TERM_COLOR: always | |
| jobs: | |
| check: | |
| name: Check | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: Swatinem/rust-cache@v2 | |
| - run: cargo check --workspace | |
| fmt: | |
| name: Format | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: dtolnay/rust-toolchain@stable | |
| with: | |
| components: rustfmt | |
| - run: cargo fmt --check | |
| clippy: | |
| name: Clippy | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: dtolnay/rust-toolchain@stable | |
| with: | |
| components: clippy | |
| - uses: Swatinem/rust-cache@v2 | |
| - run: cargo clippy --workspace -- -D warnings | |
| # Fails on any RUSTSEC advisory affecting Cargo.lock (vulnerabilities only; | |
| # informational warnings such as unmaintained/unsound do not fail the job). | |
| audit: | |
| name: Security Audit | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - name: Install cargo-audit | |
| uses: taiki-e/install-action@v2 | |
| with: | |
| tool: cargo-audit | |
| - run: cargo audit | |
| test: | |
| name: Test | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: Swatinem/rust-cache@v2 | |
| - run: cargo test --workspace | |
| sonar: | |
| name: SonarCloud | |
| runs-on: ubuntu-latest | |
| needs: [test] | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: SonarCloud Scan | |
| uses: SonarSource/sonarqube-scan-action@v6 | |
| env: | |
| SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} | |
| # Cross-platform build smoke test | |
| build: | |
| name: Build (${{ matrix.os }}) | |
| runs-on: ${{ matrix.os }} | |
| permissions: | |
| contents: read | |
| strategy: | |
| matrix: | |
| os: [ubuntu-latest, macos-latest, windows-latest] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: Swatinem/rust-cache@v2 | |
| - run: cargo build --release | |
| e2e: | |
| name: E2E Tests | |
| runs-on: ubuntu-latest | |
| needs: [check] | |
| permissions: | |
| contents: read | |
| services: | |
| postgres: | |
| image: postgres:16 | |
| env: | |
| POSTGRES_DB: artifact_registry_test | |
| POSTGRES_USER: registry | |
| POSTGRES_PASSWORD: registry | |
| ports: | |
| - 30433:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U registry -d artifact_registry_test" | |
| --health-interval 2s | |
| --health-timeout 5s | |
| --health-retries 15 | |
| meilisearch: | |
| image: getmeili/meilisearch:v1.12 | |
| env: | |
| MEILI_ENV: development | |
| ports: | |
| - 7701:7700 | |
| options: >- | |
| --health-cmd "curl -f http://localhost:7700/health" | |
| --health-interval 2s | |
| --health-timeout 5s | |
| --health-retries 15 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: dtolnay/rust-toolchain@stable | |
| - uses: Swatinem/rust-cache@v2 | |
| - name: Start backend | |
| run: | | |
| # The backend hard-fails at startup ("JWT_SECRET is unsuitable: | |
| # ... known placeholder value") on weak/placeholder signing | |
| # secrets in EVERY environment. The old literal | |
| # "e2e-test-secret-key-not-for-production" trips that check (it | |
| # embeds the weak substrings "test-secret" / "secret-key"), so | |
| # the backend never booted and "Wait for backend" timed out. | |
| # Generate a strong, random secret per run instead. Use base64 | |
| # (not hex): the backend also rejects "low entropy" secrets with | |
| # fewer than 16 DISTINCT characters, and a hex string draws from | |
| # only 16 symbols so a random one occasionally lands at 14-15 | |
| # distinct and is rejected (flaky). base64 draws from 64 symbols, | |
| # so `openssl rand -base64 48` reliably clears the check — and it | |
| # is exactly what the backend's error message recommends. | |
| JWT_SECRET="$(openssl rand -base64 48)" | |
| docker run -d --name e2e-backend \ | |
| --network ${{ job.services.postgres.network }} \ | |
| -e DATABASE_URL="postgresql://registry:registry@postgres:5432/artifact_registry_test" \ | |
| -e MEILI_URL="http://meilisearch:7700" \ | |
| -e ADMIN_PASSWORD="TestRunner!2026secure" \ | |
| -e JWT_SECRET="${JWT_SECRET}" \ | |
| -e RATE_LIMIT_ENABLED="false" \ | |
| -p 8081:8080 \ | |
| ghcr.io/artifact-keeper/artifact-keeper-backend:1.4.0 | |
| - name: Wait for backend | |
| run: | | |
| for i in $(seq 1 60); do | |
| if curl -sf http://localhost:8081/health > /dev/null 2>&1; then | |
| echo "Backend healthy after $i attempts" | |
| exit 0 | |
| fi | |
| sleep 2 | |
| done | |
| docker logs e2e-backend | |
| exit 1 | |
| - name: Run E2E tests | |
| env: | |
| E2E_BACKEND_URL: http://localhost:8081 | |
| run: cargo test --test 'e2e_*' -- --include-ignored --test-threads=1 | |
| - name: Backend logs (on failure) | |
| if: failure() | |
| run: docker logs e2e-backend |