Skip to content

build(deps): bump astro in /docs in the astro-docs group (#541) #1153

build(deps): bump astro in /docs in the astro-docs group (#541)

build(deps): bump astro in /docs in the astro-docs group (#541) #1153

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
frontend-lint:
name: Frontend / Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '22'
cache: 'npm'
cache-dependency-path: frontend/package-lock.json
- name: Install dependencies
run: npm ci
working-directory: frontend
- name: Lint
run: npm run ci
working-directory: frontend
frontend-test:
name: Frontend / Test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '22'
cache: 'npm'
cache-dependency-path: frontend/package-lock.json
- name: Install dependencies
run: npm ci
working-directory: frontend
- name: Run unit tests
run: npm run test
working-directory: frontend
- name: Cache Playwright browsers
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ~/.cache/ms-playwright
key: ${{ runner.os }}-playwright-${{ hashFiles('frontend/package-lock.json') }}
restore-keys: |
${{ runner.os }}-playwright-
- name: Install Playwright browsers
run: npx playwright install --with-deps
working-directory: frontend
- name: Run e2e and accessibility tests
run: npm run test:e2e
working-directory: frontend
- name: Upload Playwright report
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: playwright-report
path: frontend/playwright-report
retention-days: 7
frontend-build:
name: Frontend / Build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '22'
cache: 'npm'
cache-dependency-path: frontend/package-lock.json
- name: Build
run: make build-frontend
- name: Upload dist artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: frontend-dist
path: internal/web/dist
retention-days: 1
backend-lint:
name: Backend / Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Set up Go
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: 'go.mod'
- name: Create stub frontend/dist for embed
run: mkdir -p frontend/dist internal/web/dist && touch frontend/dist/.gitkeep internal/web/dist/.gitkeep
# The Release workflow regenerates these docs and GoReleaser refuses a
# dirty tree, so stale committed docs break releases. Catch the drift on
# the PR that causes it instead. Uses swag@latest to match release.yml.
- name: Check Swagger docs are up to date
run: |
make swagger
if ! git diff --exit-code internal/swagger/; then
echo "::error::internal/swagger is stale. Run: make swagger"
exit 1
fi
- name: golangci-lint
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0
with:
version: v2.12.2
backend-test:
name: Backend / Test
runs-on: ubuntu-latest
needs: frontend-build
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Set up Go
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: 'go.mod'
- name: Download dist artifact
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: frontend-dist
path: internal/web/dist
- name: Install swag
run: |
go mod download
go install github.com/swaggo/swag/cmd/swag
- name: Run tests (unit + e2e)
run: go test -tags=e2e -v -race -coverprofile=coverage.out ./cmd/... ./internal/...
- name: Upload coverage
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
files: ./coverage.out
flags: unittests
fail_ci_if_error: false
backend-security:
name: Backend / Security
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
# Rejects toolchains on Go release lines that no longer receive
# security fixes (#451). Warns (release gate fails) when a newer
# patch of the pinned line exists.
- name: Check Go toolchain is a supported release line
run: ./scripts/check-go-toolchain.sh
- name: Set up Go
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: 'go.mod'
# Reachability-aware scan: fails only on vulnerabilities whose
# affected symbols the code actually calls.
- name: govulncheck (source)
run: |
go install golang.org/x/vuln/cmd/govulncheck@v1.6.0
govulncheck ./cmd/... ./internal/...
build-binaries:
name: Build CLI Binaries
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0
- name: Set up Go
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: 'go.mod'
- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '20'
cache: 'npm'
cache-dependency-path: frontend/package-lock.json
- name: Install build tools
run: |
go mod download
go install github.com/swaggo/swag/cmd/swag@latest
- name: Generate Swagger docs
run: make swagger
- name: Build snapshot binaries
uses: goreleaser/goreleaser-action@5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89 # v7.2.2
with:
distribution: goreleaser
version: latest
args: build --snapshot --clean
# Binary-mode scan of a compiled artifact: checks the symbols actually
# linked into the binary (including the exact stdlib the toolchain
# shipped) against the vulndb. The release binaries are stripped
# (-s -w), which loses the symbol table and degrades govulncheck to
# module-level reporting (false positives like GO-2026-5932), so scan
# an unstripped build of the same package, toolchain, and deps.
- name: govulncheck (compiled binary)
run: |
go install golang.org/x/vuln/cmd/govulncheck@v1.6.0
go build -trimpath -o /tmp/nebi-scan ./cmd/nebi
govulncheck -mode=binary /tmp/nebi-scan
- name: Upload Linux amd64
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: nebi-cli-linux-amd64
path: dist/nebi_linux_amd64_v1/nebi
- name: Upload Linux arm64
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: nebi-cli-linux-arm64
path: dist/nebi_linux_arm64_v8.0/nebi
- name: Upload macOS Intel
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: nebi-cli-darwin-amd64
path: dist/nebi_darwin_amd64_v1/nebi
- name: Upload macOS ARM
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: nebi-cli-darwin-arm64
path: dist/nebi_darwin_arm64_v8.0/nebi
- name: Upload Windows amd64
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: nebi-cli-windows-amd64
path: dist/nebi_windows_amd64_v1/nebi.exe