CI (SIAX Cloud) / security (push) Successful in 18s
CI (SIAX Cloud) / security (pull_request) Successful in 21s
CI (SIAX Cloud) / contracts (pull_request) Successful in 26s
CI (SIAX Cloud) / quality (push) Successful in 1m10s
CI (SIAX Cloud) / quality (pull_request) Successful in 1m11s
CI (SIAX Cloud) / contracts (push) Successful in 1m24s
Part of a fleet-wide CI-speed pass. ci.yml's three jobs (quality, security, contracts) had no timeout-minutes, so a hung step could run indefinitely and tie up a scarce runner. Added 30min for the build/test jobs (quality, contracts) and 15min for the single-check security scan (Trivy). ci.yml also triggers on both push and pull_request with no branch filter, which fires the full CI suite twice per PR commit. Added the same concurrency group pattern already used elsewhere in the fleet (admin/serv0, admin/s0cial, admin/ppl0, admin/pers0n) to cancel the superseded run instead of changing the triggers themselves. masterplan-lock.yml is schedule-only and not on the hot path, so left untouched. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
54 lines
1.6 KiB
YAML
54 lines
1.6 KiB
YAML
name: CI (SIAX Cloud)
|
|
on: [push, pull_request, workflow_dispatch]
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.head_ref || github.ref }}
|
|
cancel-in-progress: true
|
|
jobs:
|
|
quality:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
- uses: pnpm/action-setup@v4
|
|
with:
|
|
version: 9.15.9
|
|
- name: Install
|
|
run: pnpm install --frozen-lockfile
|
|
- name: Canonical architecture policy
|
|
run: pnpm run validate:architecture
|
|
- name: Typecheck
|
|
run: pnpm run typecheck
|
|
- name: Test
|
|
run: pnpm run test
|
|
- name: Build
|
|
run: pnpm run build
|
|
security:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Install Trivy
|
|
run: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin
|
|
- name: Scan
|
|
run: trivy fs --scanners vuln,secret --severity HIGH,CRITICAL --exit-code 0 .
|
|
contracts:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
- uses: pnpm/action-setup@v4
|
|
with:
|
|
version: 9.15.9
|
|
- name: Install
|
|
run: pnpm install --frozen-lockfile
|
|
- name: Canonical architecture policy
|
|
run: pnpm run validate:architecture
|
|
- name: Check schema/contracts and provenance policy
|
|
run: pnpm --filter @siax/c0py-core test
|