Skip to content

fix(deps): vitest 3→4.1.11 — patches CVE-2026-84373 MEDIUM #732

fix(deps): vitest 3→4.1.11 — patches CVE-2026-84373 MEDIUM

fix(deps): vitest 3→4.1.11 — patches CVE-2026-84373 MEDIUM #732

Workflow file for this run

# Docker build verification CI (v0.13.4)
#
# Builds API + Web Docker images on every push to main and every PR.
# Does NOT push to registry — this gate only verifies the Dockerfiles
# compile successfully. Pushing to ghcr.io is handled by docker-publish.yml.
#
# Runs in parallel with the main CI (ci.yml) since Docker builds are
# I/O-heavy and independent of the lint/test pipeline.
name: Docker build
on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
concurrency:
group: docker-build-${{ github.ref }}
cancel-in-progress: true
# Reusable build setup used by both API and Web jobs.
# Enables Docker BuildKit and sets up buildx with GHA cache.
env:
DOCKER_BUILDKIT: 1
jobs:
build-api:
name: Build API image
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Build API Docker image
uses: docker/build-push-action@v6
with:
context: .
file: apps/api/Dockerfile
tags: gw2analytics-api:ci
# Load into local Docker so the image is available for
# subsequent steps (no push needed for this CI gate).
load: true
# GHA cache shares layer blobs across CI runs on the
# same branch, significantly speeding up rebuilds when
# only source files change (layers before COPY stay cached).
cache-from: type=gha
cache-to: type=gha,mode=max
build-web:
name: Build Web image
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Build Web Docker image
uses: docker/build-push-action@v6
with:
context: ./web
file: web/Dockerfile
tags: gw2analytics-web:ci
load: true
cache-from: type=gha
cache-to: type=gha,mode=max