build(deps): bump astro in /docs in the astro-docs group (#541) #1153
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| jobs: | |
| frontend-lint: | |
| name: Frontend / Lint | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - name: Set up Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| cache-dependency-path: frontend/package-lock.json | |
| - name: Install dependencies | |
| run: npm ci | |
| working-directory: frontend | |
| - name: Lint | |
| run: npm run ci | |
| working-directory: frontend | |
| frontend-test: | |
| name: Frontend / Test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - name: Set up Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| cache-dependency-path: frontend/package-lock.json | |
| - name: Install dependencies | |
| run: npm ci | |
| working-directory: frontend | |
| - name: Run unit tests | |
| run: npm run test | |
| working-directory: frontend | |
| - name: Cache Playwright browsers | |
| uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| with: | |
| path: ~/.cache/ms-playwright | |
| key: ${{ runner.os }}-playwright-${{ hashFiles('frontend/package-lock.json') }} | |
| restore-keys: | | |
| ${{ runner.os }}-playwright- | |
| - name: Install Playwright browsers | |
| run: npx playwright install --with-deps | |
| working-directory: frontend | |
| - name: Run e2e and accessibility tests | |
| run: npm run test:e2e | |
| working-directory: frontend | |
| - name: Upload Playwright report | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: playwright-report | |
| path: frontend/playwright-report | |
| retention-days: 7 | |
| frontend-build: | |
| name: Frontend / Build | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - name: Set up Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| cache-dependency-path: frontend/package-lock.json | |
| - name: Build | |
| run: make build-frontend | |
| - name: Upload dist artifact | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: frontend-dist | |
| path: internal/web/dist | |
| retention-days: 1 | |
| backend-lint: | |
| name: Backend / Lint | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - name: Set up Go | |
| uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0 | |
| with: | |
| go-version-file: 'go.mod' | |
| - name: Create stub frontend/dist for embed | |
| run: mkdir -p frontend/dist internal/web/dist && touch frontend/dist/.gitkeep internal/web/dist/.gitkeep | |
| # The Release workflow regenerates these docs and GoReleaser refuses a | |
| # dirty tree, so stale committed docs break releases. Catch the drift on | |
| # the PR that causes it instead. Uses swag@latest to match release.yml. | |
| - name: Check Swagger docs are up to date | |
| run: | | |
| make swagger | |
| if ! git diff --exit-code internal/swagger/; then | |
| echo "::error::internal/swagger is stale. Run: make swagger" | |
| exit 1 | |
| fi | |
| - name: golangci-lint | |
| uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 | |
| with: | |
| version: v2.12.2 | |
| backend-test: | |
| name: Backend / Test | |
| runs-on: ubuntu-latest | |
| needs: frontend-build | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - name: Set up Go | |
| uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0 | |
| with: | |
| go-version-file: 'go.mod' | |
| - name: Download dist artifact | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: frontend-dist | |
| path: internal/web/dist | |
| - name: Install swag | |
| run: | | |
| go mod download | |
| go install github.com/swaggo/swag/cmd/swag | |
| - name: Run tests (unit + e2e) | |
| run: go test -tags=e2e -v -race -coverprofile=coverage.out ./cmd/... ./internal/... | |
| - name: Upload coverage | |
| uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 | |
| with: | |
| files: ./coverage.out | |
| flags: unittests | |
| fail_ci_if_error: false | |
| backend-security: | |
| name: Backend / Security | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| # Rejects toolchains on Go release lines that no longer receive | |
| # security fixes (#451). Warns (release gate fails) when a newer | |
| # patch of the pinned line exists. | |
| - name: Check Go toolchain is a supported release line | |
| run: ./scripts/check-go-toolchain.sh | |
| - name: Set up Go | |
| uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0 | |
| with: | |
| go-version-file: 'go.mod' | |
| # Reachability-aware scan: fails only on vulnerabilities whose | |
| # affected symbols the code actually calls. | |
| - name: govulncheck (source) | |
| run: | | |
| go install golang.org/x/vuln/cmd/govulncheck@v1.6.0 | |
| govulncheck ./cmd/... ./internal/... | |
| build-binaries: | |
| name: Build CLI Binaries | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| with: | |
| fetch-depth: 0 | |
| - name: Set up Go | |
| uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0 | |
| with: | |
| go-version-file: 'go.mod' | |
| - name: Set up Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| with: | |
| node-version: '20' | |
| cache: 'npm' | |
| cache-dependency-path: frontend/package-lock.json | |
| - name: Install build tools | |
| run: | | |
| go mod download | |
| go install github.com/swaggo/swag/cmd/swag@latest | |
| - name: Generate Swagger docs | |
| run: make swagger | |
| - name: Build snapshot binaries | |
| uses: goreleaser/goreleaser-action@5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89 # v7.2.2 | |
| with: | |
| distribution: goreleaser | |
| version: latest | |
| args: build --snapshot --clean | |
| # Binary-mode scan of a compiled artifact: checks the symbols actually | |
| # linked into the binary (including the exact stdlib the toolchain | |
| # shipped) against the vulndb. The release binaries are stripped | |
| # (-s -w), which loses the symbol table and degrades govulncheck to | |
| # module-level reporting (false positives like GO-2026-5932), so scan | |
| # an unstripped build of the same package, toolchain, and deps. | |
| - name: govulncheck (compiled binary) | |
| run: | | |
| go install golang.org/x/vuln/cmd/govulncheck@v1.6.0 | |
| go build -trimpath -o /tmp/nebi-scan ./cmd/nebi | |
| govulncheck -mode=binary /tmp/nebi-scan | |
| - name: Upload Linux amd64 | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: nebi-cli-linux-amd64 | |
| path: dist/nebi_linux_amd64_v1/nebi | |
| - name: Upload Linux arm64 | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: nebi-cli-linux-arm64 | |
| path: dist/nebi_linux_arm64_v8.0/nebi | |
| - name: Upload macOS Intel | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: nebi-cli-darwin-amd64 | |
| path: dist/nebi_darwin_amd64_v1/nebi | |
| - name: Upload macOS ARM | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: nebi-cli-darwin-arm64 | |
| path: dist/nebi_darwin_arm64_v8.0/nebi | |
| - name: Upload Windows amd64 | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: nebi-cli-windows-amd64 | |
| path: dist/nebi_windows_amd64_v1/nebi.exe |