CI (SIAX Cloud) / sonar (push) Skipped
CI (SIAX Cloud) / security (push) Successful in 17s
CI (SIAX Cloud) / contracts (push) Successful in 18s
CI (SIAX Cloud) / quality (push) Successful in 55s
CI (SIAX Cloud) / sonar (pull_request) Skipped
CI (SIAX Cloud) / contracts (pull_request) Successful in 16s
CI (SIAX Cloud) / security (pull_request) Successful in 40s
CI (SIAX Cloud) / quality (pull_request) Successful in 1m29s
Repo: c0py. Lägger till sonar-project.properties (projectKey=c0py) och en ny sonar-job i .gitea/workflows/ci.yml som kör sonar-scanner mot sonar.siax.io vid push till main (Community Build saknar PR-analysläge). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
81 lines
2.9 KiB
YAML
81 lines
2.9 KiB
YAML
name: CI (SIAX Cloud)
|
|
on: [push, pull_request, workflow_dispatch]
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.head_ref || github.ref }}
|
|
cancel-in-progress: true
|
|
jobs:
|
|
quality:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
- uses: pnpm/action-setup@v4
|
|
with:
|
|
version: 9.15.9
|
|
- name: Install
|
|
run: pnpm install --frozen-lockfile
|
|
- name: Canonical architecture policy
|
|
run: pnpm run validate:architecture
|
|
- name: Typecheck
|
|
run: pnpm run typecheck
|
|
- name: Test
|
|
run: pnpm run test
|
|
- name: Build
|
|
run: pnpm run build
|
|
security:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Install Trivy
|
|
run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
|
|
- name: Scan
|
|
run: trivy fs --scanners vuln,secret --severity HIGH,CRITICAL --exit-code 0 .
|
|
contracts:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
- uses: pnpm/action-setup@v4
|
|
with:
|
|
version: 9.15.9
|
|
- name: Install
|
|
run: pnpm install --frozen-lockfile
|
|
- name: Canonical architecture policy
|
|
run: pnpm run validate:architecture
|
|
- name: Check schema/contracts and provenance policy
|
|
run: pnpm --filter @siax/c0py-core test
|
|
sonar:
|
|
# SonarQube Community Build har inget separat PR-analysläge (en enda "main"-gren
|
|
# per projekt) — en analys från en PR-branch eller en tagg-push som inte pekar på
|
|
# main skulle skriva över kvalitetshistoriken. Kör därför bara
|
|
# vid push till main.
|
|
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 20
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
- name: SonarQube analysis (self-hosted sonar.siax.io)
|
|
env:
|
|
SONAR_HOST_URL: https://sonar.siax.io
|
|
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
test -n "$SONAR_TOKEN" || { echo "::error::SONAR_TOKEN repo secret missing"; exit 1; }
|
|
# Jobbet kör i en container på act_runner; "docker run -v \"$PWD:...\""
|
|
# skulle montera VÄRDENS (tomma) sökväg. Kopiera in källträdet istället.
|
|
cid=$(docker create -e SONAR_HOST_URL -e SONAR_TOKEN -w /usr/src \
|
|
sonarsource/sonar-scanner-cli:latest \
|
|
sonar-scanner -Dsonar.projectKey=c0py -Dsonar.host.url="$SONAR_HOST_URL")
|
|
trap 'docker rm -f "$cid" >/dev/null 2>&1 || true' EXIT
|
|
docker cp . "$cid":/usr/src
|
|
docker start -a "$cid"
|