Files
c0py/.gitea/workflows/ci.yml
T
Claude CodeandClaude Sonnet 5 d362852384
CI (SIAX Cloud) / security (push) Successful in 18s
CI (SIAX Cloud) / security (pull_request) Successful in 21s
CI (SIAX Cloud) / contracts (pull_request) Successful in 26s
CI (SIAX Cloud) / quality (push) Successful in 1m10s
CI (SIAX Cloud) / quality (pull_request) Successful in 1m11s
CI (SIAX Cloud) / contracts (push) Successful in 1m24s
ci(workflows): add job timeout-minutes and concurrency guard
Part of a fleet-wide CI-speed pass. ci.yml's three jobs (quality,
security, contracts) had no timeout-minutes, so a hung step could run
indefinitely and tie up a scarce runner. Added 30min for the
build/test jobs (quality, contracts) and 15min for the single-check
security scan (Trivy).

ci.yml also triggers on both push and pull_request with no branch
filter, which fires the full CI suite twice per PR commit. Added the
same concurrency group pattern already used elsewhere in the fleet
(admin/serv0, admin/s0cial, admin/ppl0, admin/pers0n) to cancel the
superseded run instead of changing the triggers themselves.

masterplan-lock.yml is schedule-only and not on the hot path, so left
untouched.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-27 04:29:10 +02:00

54 lines
1.6 KiB
YAML

name: CI (SIAX Cloud)
on: [push, pull_request, workflow_dispatch]
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.ref }}
cancel-in-progress: true
jobs:
quality:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- uses: pnpm/action-setup@v4
with:
version: 9.15.9
- name: Install
run: pnpm install --frozen-lockfile
- name: Canonical architecture policy
run: pnpm run validate:architecture
- name: Typecheck
run: pnpm run typecheck
- name: Test
run: pnpm run test
- name: Build
run: pnpm run build
security:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
- name: Install Trivy
run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
- name: Scan
run: trivy fs --scanners vuln,secret --severity HIGH,CRITICAL --exit-code 0 .
contracts:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- uses: pnpm/action-setup@v4
with:
version: 9.15.9
- name: Install
run: pnpm install --frozen-lockfile
- name: Canonical architecture policy
run: pnpm run validate:architecture
- name: Check schema/contracts and provenance policy
run: pnpm --filter @siax/c0py-core test