feat: make a generated project's released stack actually run #41
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: {} | |
| jobs: | |
| unit: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| # ci-unit is lint plus test-unit, and test-unit is now genuinely | |
| # offline (measured ~3s locally for 30 tests) — no adapter generator | |
| # anywhere in its setup(), so no pnpm/php provisioning needed here. | |
| timeout-minutes: 5 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | |
| - run: mise run ci-unit | |
| integration: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| # add-app.bats, compose.bats, docs.bats and workflows.bats each | |
| # generate a real nestjs/laravel-api project as a fixture — same cost | |
| # class as tier a in adapters.yml (bounded, not tier b's ~25 minutes), | |
| # moved here because ADR-0012's tiers are about per-adapter smoke | |
| # tests, not these cross-cutting mechanics suites. | |
| timeout-minutes: 25 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| # workflows.bats walks this repository's own history to find the | |
| # commit that introduced an adapter, then diffs against its parent. | |
| # A default checkout has one commit and no parent, so the test fails | |
| # on `unknown revision` rather than on anything it is testing. | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | |
| - run: corepack enable | |
| - uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2 | |
| with: | |
| php-version: "8.3" | |
| - run: mise run test-integration | |
| zizmor: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| timeout-minutes: 5 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | |
| # Only this repository's own workflows. common/ holds templates whose | |
| # `uses: you/.github/...` names no real repository, so ref-confusion | |
| # cannot resolve it and the audit errors out rather than reporting a | |
| # finding — a failure about the placeholder, not about the pipeline. | |
| # What a generated project's call sites get instead is structural: | |
| # tests/workflows.bats asserts sha-pinned actions, closed permission | |
| # sets and shared-repository-only `uses:`. No audit runs on them. | |
| - run: mise exec -- zizmor .github/workflows/ | |
| # The checklist is only worth having if something reads it. This parses the | |
| # headings out of the template itself rather than holding a second copy of | |
| # them, so editing the template changes what is enforced — the convention and | |
| # its enforcement cannot drift apart. Borrowed from immich's auto-close.yml. | |
| pull-request-body: | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| timeout-minutes: 5 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - env: | |
| BODY: ${{ github.event.pull_request.body }} | |
| run: | | |
| missing="" | |
| while IFS= read -r heading; do | |
| printf '%s\n' "$BODY" | grep -qF "$heading" || missing="${missing}\n ${heading}" | |
| done < <(grep '^## ' .github/pull_request_template.md) | |
| if [ -n "$missing" ]; then | |
| printf 'pull request body is missing:%b\n' "$missing" >&2 | |
| echo "Keep the template's sections; delete the comments, not the headings." >&2 | |
| exit 1 | |
| fi |