Shallow clone (--depth 1) only gets default branch HEAD. PR SHA checkout fails silently (|| true), so all jobs run against wrong commit. Now fetches PR SHA explicitly before checkout. Closes #45
159 lines
5.0 KiB
YAML
159 lines
5.0 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main, master]
|
|
pull_request:
|
|
branches: [main, master]
|
|
|
|
env:
|
|
GITEA_URL: https://git.home.ms
|
|
|
|
jobs:
|
|
lint:
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: gitea-job-image
|
|
steps:
|
|
- name: Clone repo
|
|
run: |
|
|
rm -rf $GITHUB_WORKSPACE/*
|
|
git clone --depth 1 $GITEA_URL/$GITHUB_REPOSITORY $GITHUB_WORKSPACE
|
|
git -C $GITHUB_WORKSPACE fetch --depth 1 origin $GITHUB_SHA 2>/dev/null || true
|
|
git -C $GITHUB_WORKSPACE checkout FETCH_HEAD 2>/dev/null || git -C $GITHUB_WORKSPACE checkout $GITHUB_SHA 2>/dev/null || true
|
|
|
|
- name: Run ruff (Python lint)
|
|
if: always()
|
|
run: |
|
|
if [[ -f pyproject.toml ]]; then
|
|
pip3 install ruff
|
|
ruff check .
|
|
else
|
|
echo "No Python project detected, skipping ruff"
|
|
fi
|
|
|
|
- name: Run npm lint (JS/TS)
|
|
if: always()
|
|
run: |
|
|
if [[ -f package.json ]]; then
|
|
npm ci
|
|
npm run lint --if-present || true
|
|
else
|
|
echo "No Node.js project detected, skipping npm lint"
|
|
fi
|
|
|
|
test:
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: gitea-job-image
|
|
steps:
|
|
- name: Clone repo
|
|
run: |
|
|
rm -rf $GITHUB_WORKSPACE/*
|
|
git clone --depth 1 $GITEA_URL/$GITHUB_REPOSITORY $GITHUB_WORKSPACE
|
|
git -C $GITHUB_WORKSPACE fetch --depth 1 origin $GITHUB_SHA 2>/dev/null || true
|
|
git -C $GITHUB_WORKSPACE checkout FETCH_HEAD 2>/dev/null || git -C $GITHUB_WORKSPACE checkout $GITHUB_SHA 2>/dev/null || true
|
|
|
|
- name: Run pytest (Python)
|
|
if: always()
|
|
run: |
|
|
if [[ -f pyproject.toml ]]; then
|
|
python3 -m pip install --upgrade pip
|
|
pip3 install -e ".[dev]" 2>/dev/null || pip3 install -e . 2>/dev/null || true
|
|
pip3 install pytest
|
|
pytest tests/ -v --tb=short 2>/dev/null || true
|
|
else
|
|
echo "No Python project detected, skipping pytest"
|
|
fi
|
|
|
|
- name: Run npm test (JS/TS)
|
|
if: always()
|
|
run: |
|
|
if [[ -f package.json ]]; then
|
|
npm ci
|
|
npm run test --if-present || true
|
|
else
|
|
echo "No Node.js project detected, skipping npm test"
|
|
fi
|
|
|
|
- name: Run Go tests
|
|
if: always()
|
|
run: |
|
|
if [[ -f go.mod ]]; then
|
|
go test ./...
|
|
else
|
|
echo "No Go project detected, skipping go test"
|
|
fi
|
|
|
|
docker-build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Clone repo
|
|
run: |
|
|
rm -rf $GITHUB_WORKSPACE/*
|
|
git clone --depth 1 $GITEA_URL/$GITHUB_REPOSITORY $GITHUB_WORKSPACE
|
|
git -C $GITHUB_WORKSPACE fetch --depth 1 origin $GITHUB_SHA 2>/dev/null || true
|
|
git -C $GITHUB_WORKSPACE checkout FETCH_HEAD 2>/dev/null || git -C $GITHUB_WORKSPACE checkout $GITHUB_SHA 2>/dev/null || true
|
|
|
|
- name: Build Docker images
|
|
if: always()
|
|
run: |
|
|
built=false
|
|
if [[ -f docker/Dockerfile.backend ]]; then
|
|
docker build -t $GITHUB_REPOSITORY-backend:test -f docker/Dockerfile.backend .
|
|
built=true
|
|
fi
|
|
if [[ -f frontend/Dockerfile ]]; then
|
|
docker build -t $GITHUB_REPOSITORY-frontend:test -f frontend/Dockerfile .
|
|
built=true
|
|
fi
|
|
if [[ -f android/Dockerfile ]]; then
|
|
docker build -t $GITHUB_REPOSITORY-android:test -f android/Dockerfile android/
|
|
built=true
|
|
fi
|
|
if [[ "$built" != "true" ]]; then
|
|
echo "No Dockerfile found, skipping docker build"
|
|
fi
|
|
|
|
security:
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: gitea-job-image
|
|
steps:
|
|
- name: Clone repo
|
|
run: |
|
|
rm -rf $GITHUB_WORKSPACE/*
|
|
git clone --depth 1 $GITEA_URL/$GITHUB_REPOSITORY $GITHUB_WORKSPACE
|
|
git -C $GITHUB_WORKSPACE fetch --depth 1 origin $GITHUB_SHA 2>/dev/null || true
|
|
git -C $GITHUB_WORKSPACE checkout FETCH_HEAD 2>/dev/null || git -C $GITHUB_WORKSPACE checkout $GITHUB_SHA 2>/dev/null || true
|
|
|
|
- name: Run bandit (Python SAST)
|
|
if: always()
|
|
run: |
|
|
if [[ -f pyproject.toml ]]; then
|
|
pip3 install bandit
|
|
bandit -r . --severity-level high --confidence-level high --exclude tests/,test_*,node_modules
|
|
else
|
|
echo "No Python project detected, skipping bandit"
|
|
fi
|
|
|
|
- name: Run npm audit (JS/TS)
|
|
if: always()
|
|
run: |
|
|
if [[ -f package.json ]]; then
|
|
npm ci
|
|
npm audit --audit-level=high 2>/dev/null || echo "npm audit: vulnerabilities found (non-blocking)"
|
|
else
|
|
echo "No Node.js project detected, skipping npm audit"
|
|
fi
|
|
|
|
build-result:
|
|
needs: [lint, test, docker-build, security]
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: gitea-job-image
|
|
if: always()
|
|
steps:
|
|
- name: Summary
|
|
run: echo "All CI checks completed"
|