-
Notifications
You must be signed in to change notification settings - Fork 0
79 lines (75 loc) · 2.77 KB
/
Copy pathci.yml
File metadata and controls
79 lines (75 loc) · 2.77 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
# Reusable from release.yml so a tag can't ship without the same
# validation a PR runs (audit A50).
workflow_call:
# The frontend is committed at cmd/teploy-dash/frontend/ and embedded into
# the binary at build time via //go:embed. CI only needs the Go toolchain —
# no Node, no pnpm, no asset pipeline.
jobs:
go:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version: '1.27.1'
- name: Build
run: go build ./...
- name: Vet
run: go vet ./...
- name: Formatting
run: test -z "$(gofmt -l $(git ls-files '*.go'))"
- name: Test
run: go test ./...
- name: Race tests
run: go test -race -count=1 ./...
- name: Module consistency
run: |
go mod tidy
git diff --exit-code -- go.mod go.sum
# X01 5.2 job 3 (X02 ADR 4): dash CI decodes the PINNED contracts corpus.
# One job proves the shipped pair, not just the pin: the pinned teploy-cli
# revision's corpus is schema-validated (ajv, pinned in ci/package.json)
# and driven through dash's real decode paths (TEPLOY_CONTRACTS_DIR makes
# the corpus tests fail-closed rather than skip). A corpus this dash
# cannot decode fails the job -- never skip-as-success. The pin lives in
# ci/contracts.pin; the MANIFEST's revision table is the authority.
contracts:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Read corpus pin
id: pin
run: |
cli_rev="$(awk -F= '/^cli_rev=/{print $2}' ci/contracts.pin)"
corpus_rev="$(awk -F= '/^corpus_rev=/{print $2}' ci/contracts.pin)"
[ -n "$cli_rev" ] && [ -n "$corpus_rev" ] || { echo "ci/contracts.pin is incomplete"; exit 1; }
echo "cli_rev=$cli_rev" >> "$GITHUB_OUTPUT"
echo "corpus_rev=$corpus_rev" >> "$GITHUB_OUTPUT"
- name: Checkout pinned teploy-cli contracts corpus
uses: actions/checkout@v4
with:
repository: useteploy/teploy-cli
ref: ${{ steps.pin.outputs.cli_rev }}
path: teploy-cli
sparse-checkout: contracts
- uses: actions/setup-node@v4
with:
node-version: '22'
- name: Schema-validate the pinned corpus
run: |
cd ci
npm ci
node validate-contracts.mjs "../teploy-cli/contracts" "${{ steps.pin.outputs.corpus_rev }}"
- uses: actions/setup-go@v5
with:
go-version: '1.27.1'
- name: Decode the pinned corpus through dash's importers
run: go test ./internal/... -run 'TestContracts' -count=1
env:
TEPLOY_CONTRACTS_DIR: ${{ github.workspace }}/teploy-cli/contracts