Skip to content

feat: make a generated project's released stack actually run #41

feat: make a generated project's released stack actually run

feat: make a generated project's released stack actually run #41

Workflow file for this run

name: CI
on:
pull_request:
push:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions: {}
jobs:
unit:
runs-on: ubuntu-latest
permissions:
contents: read
# ci-unit is lint plus test-unit, and test-unit is now genuinely
# offline (measured ~3s locally for 30 tests) — no adapter generator
# anywhere in its setup(), so no pnpm/php provisioning needed here.
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
- run: mise run ci-unit
integration:
runs-on: ubuntu-latest
permissions:
contents: read
# add-app.bats, compose.bats, docs.bats and workflows.bats each
# generate a real nestjs/laravel-api project as a fixture — same cost
# class as tier a in adapters.yml (bounded, not tier b's ~25 minutes),
# moved here because ADR-0012's tiers are about per-adapter smoke
# tests, not these cross-cutting mechanics suites.
timeout-minutes: 25
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# workflows.bats walks this repository's own history to find the
# commit that introduced an adapter, then diffs against its parent.
# A default checkout has one commit and no parent, so the test fails
# on `unknown revision` rather than on anything it is testing.
fetch-depth: 0
persist-credentials: false
- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
- run: corepack enable
- uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: "8.3"
- run: mise run test-integration
zizmor:
runs-on: ubuntu-latest
permissions:
contents: read
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
# Only this repository's own workflows. common/ holds templates whose
# `uses: you/.github/...` names no real repository, so ref-confusion
# cannot resolve it and the audit errors out rather than reporting a
# finding — a failure about the placeholder, not about the pipeline.
# What a generated project's call sites get instead is structural:
# tests/workflows.bats asserts sha-pinned actions, closed permission
# sets and shared-repository-only `uses:`. No audit runs on them.
- run: mise exec -- zizmor .github/workflows/
# The checklist is only worth having if something reads it. This parses the
# headings out of the template itself rather than holding a second copy of
# them, so editing the template changes what is enforced — the convention and
# its enforcement cannot drift apart. Borrowed from immich's auto-close.yml.
pull-request-body:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
permissions:
contents: read
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- env:
BODY: ${{ github.event.pull_request.body }}
run: |
missing=""
while IFS= read -r heading; do
printf '%s\n' "$BODY" | grep -qF "$heading" || missing="${missing}\n ${heading}"
done < <(grep '^## ' .github/pull_request_template.md)
if [ -n "$missing" ]; then
printf 'pull request body is missing:%b\n' "$missing" >&2
echo "Keep the template's sections; delete the comments, not the headings." >&2
exit 1
fi