* ci: migrate ESLint to Biome, optimize workflows, fix tar vulnerability - Replace ESLint with Biome (15-25x faster linting) - Pin Biome to 2.3.11 for consistent behavior across local/CI - Disable useArrowFunction rule (breaks vitest constructor mocks) - Add composite actions for DRY workflow setup - Fix tar vulnerability (CVE-2026-23745) by upgrading to v7.5.3 - Add @electron/rebuild override to ensure consistent tar version - Update electron-builder to 26.4.0 Co-Authored-By: Claude Opus 4.5 <[email protected]> * fix(workflows): address all 15 PR review findings HIGH priority fixes: - Add [email protected] override to frontend package.json (CVE-2026-23745) - Use setup-node-frontend composite action in release.yml (4 build jobs) - Use setup-node-frontend composite action in beta-release.yml (4 build jobs) MEDIUM priority fixes: - Add notarization status verification ('Accepted') before stapling - Add blockmap files to beta-release asset copying (delta updates) - Add DMG validation with fallback in release.yml - Extract yq checksum to env block, single definition per step - Fix snake_case to kebab-case in notarization action outputs LOW priority fixes: - Add config files (pyproject.toml, tsconfig*.json, biome.jsonc) to CI paths - Document yq checksum requirement in merge-macos-manifests - Always use jq for notarization ID parsing (no regex fallback) - Add blockmap files to dry-run-summary job - Change noControlCharactersInRegex from off to warn - Rename biome.json to biome.jsonc, add comments explaining disabled rules noSecrets rule kept off due to 2700+ false positives on normal strings. Co-Authored-By: Claude Opus 4.5 <[email protected]> * fix(lint): correct biome.jsonc path in workflow triggers The lint workflow path filter referenced 'biome.json' but the actual config file is 'biome.jsonc' (renamed to support comments). This fix ensures the lint workflow triggers when the Biome config is modified. Co-Authored-By: Claude Opus 4.5 <[email protected]> * fix(workflows): address 6 PR review findings - QUAL-001/002: Add DMG file existence checks before stapling - QUAL-003: Quote all path variables in merge-macos-manifests - QUAL-004: Add semver validation in update-readme.py - QUAL-005: Document noDangerouslySetInnerHtml security rule decision - LOGIC-001: Add warning when both notarization IDs are empty Co-Authored-By: Claude Opus 4.5 <[email protected]> * feat(workflows): add gate jobs for branch protection Add summary/gate jobs to match existing branch protection rules: - CI Complete: aggregates test-python and test-frontend results - Lint Complete: aggregates python and typescript lint results - Security Summary: aggregates codeql and python-security results These jobs provide a single status check for branch protection instead of requiring individual job names which can change with matrix configs. Co-Authored-By: Claude Opus 4.5 <[email protected]> --------- Co-authored-by: Claude Opus 4.5 <[email protected]>
166 lines
4.9 KiB
YAML
166 lines
4.9 KiB
YAML
# Cross-Platform CI Pipeline
|
|
#
|
|
# Tests on all target platforms (Linux, Windows, macOS) to catch
|
|
# platform-specific bugs before they merge. ALL platforms must pass.
|
|
#
|
|
# Optimized: Reduced matrix (4 jobs vs 6), merged integration tests,
|
|
# coverage on Linux only, path filters to skip on docs-only changes.
|
|
|
|
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main, develop]
|
|
paths:
|
|
- 'apps/**'
|
|
- 'tests/**'
|
|
- 'package*.json'
|
|
- 'requirements*.txt'
|
|
- 'pyproject.toml'
|
|
- 'tsconfig*.json'
|
|
- 'biome.jsonc'
|
|
- '.github/workflows/ci.yml'
|
|
- '.github/actions/**'
|
|
pull_request:
|
|
branches: [main, develop]
|
|
paths:
|
|
- 'apps/**'
|
|
- 'tests/**'
|
|
- 'package*.json'
|
|
- 'requirements*.txt'
|
|
- 'pyproject.toml'
|
|
- 'tsconfig*.json'
|
|
- 'biome.jsonc'
|
|
- '.github/workflows/ci.yml'
|
|
- '.github/actions/**'
|
|
|
|
concurrency:
|
|
group: ci-${{ github.event.pull_request.number || github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
actions: read
|
|
|
|
jobs:
|
|
# --------------------------------------------------------------------------
|
|
# Python Backend Tests - Optimized Matrix (4 jobs instead of 6)
|
|
# --------------------------------------------------------------------------
|
|
test-python:
|
|
name: test-python (${{ matrix.python-version }}, ${{ matrix.os }})
|
|
runs-on: ${{ matrix.os }}
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
# 3.12 on all OS for cross-platform coverage
|
|
# 3.13 on Linux only for compatibility check (saves 2 jobs)
|
|
include:
|
|
- os: ubuntu-latest
|
|
python-version: '3.12'
|
|
- os: ubuntu-latest
|
|
python-version: '3.13'
|
|
- os: windows-latest
|
|
python-version: '3.12'
|
|
- os: macos-latest
|
|
python-version: '3.12'
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup Python backend
|
|
uses: ./.github/actions/setup-python-backend
|
|
with:
|
|
python-version: ${{ matrix.python-version }}
|
|
install-test-deps: 'true'
|
|
|
|
- name: Run all tests (including platform-specific)
|
|
working-directory: apps/backend
|
|
shell: bash
|
|
env:
|
|
PYTHONPATH: ${{ github.workspace }}/apps/backend
|
|
run: |
|
|
if [ "$RUNNER_OS" == "Windows" ]; then
|
|
source .venv/Scripts/activate
|
|
else
|
|
source .venv/bin/activate
|
|
fi
|
|
pytest ../../tests/ -v --tb=short -x
|
|
|
|
- name: Run coverage (Linux + Python 3.12 only)
|
|
if: matrix.os == 'ubuntu-latest' && matrix.python-version == '3.12'
|
|
working-directory: apps/backend
|
|
shell: bash
|
|
env:
|
|
PYTHONPATH: ${{ github.workspace }}/apps/backend
|
|
run: |
|
|
source .venv/bin/activate
|
|
pytest ../../tests/ -v --cov=. --cov-report=xml --cov-report=term-missing --cov-fail-under=10
|
|
|
|
- name: Upload coverage to Codecov
|
|
if: matrix.os == 'ubuntu-latest' && matrix.python-version == '3.12'
|
|
uses: codecov/codecov-action@v4
|
|
with:
|
|
file: ./apps/backend/coverage.xml
|
|
fail_ci_if_error: false
|
|
env:
|
|
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
|
|
|
|
# --------------------------------------------------------------------------
|
|
# Frontend Tests - All Platforms
|
|
# --------------------------------------------------------------------------
|
|
test-frontend:
|
|
name: test-frontend (${{ matrix.os }})
|
|
runs-on: ${{ matrix.os }}
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
os: [ubuntu-latest, windows-latest, macos-latest]
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup Node.js frontend
|
|
uses: ./.github/actions/setup-node-frontend
|
|
with:
|
|
ignore-scripts: 'true'
|
|
|
|
- name: Run TypeScript type check
|
|
working-directory: apps/frontend
|
|
run: npm run typecheck
|
|
|
|
- name: Run unit tests
|
|
working-directory: apps/frontend
|
|
run: npm run test
|
|
|
|
- name: Build application
|
|
working-directory: apps/frontend
|
|
run: npm run build
|
|
|
|
# --------------------------------------------------------------------------
|
|
# Gate Job - Single check for branch protection
|
|
# --------------------------------------------------------------------------
|
|
ci-complete:
|
|
name: CI Complete
|
|
runs-on: ubuntu-latest
|
|
needs: [test-python, test-frontend]
|
|
if: always()
|
|
steps:
|
|
- name: Check all CI jobs passed
|
|
run: |
|
|
echo "CI Job Results:"
|
|
echo " test-python: ${{ needs.test-python.result }}"
|
|
echo " test-frontend: ${{ needs.test-frontend.result }}"
|
|
echo ""
|
|
|
|
if [[ "${{ needs.test-python.result }}" != "success" ]] || \
|
|
[[ "${{ needs.test-frontend.result }}" != "success" ]]; then
|
|
echo "❌ One or more CI jobs failed"
|
|
exit 1
|
|
fi
|
|
|
|
echo "✅ All CI checks passed"
|