-
Notifications
You must be signed in to change notification settings - Fork 32
141 lines (121 loc) · 4.56 KB
/
Copy pathci.yml
File metadata and controls
141 lines (121 loc) · 4.56 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
name: CI
on:
pull_request:
types: [opened, synchronize, reopened]
push:
branches: [main]
# Manual trigger. Lets a maintainer run the full gate on any ref from the
# Actions tab without pushing a throwaway commit — useful for confirming the
# pipeline itself works, and for re-running against a branch after an
# infrastructure problem rather than a code change.
workflow_dispatch:
# Cancel superseded runs on the same ref to save CI minutes.
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
jobs:
quality:
name: Quality (Node ${{ matrix.node }} / ${{ matrix.os }})
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
# Node 18 is absent on purpose: vitest 4 declares
# `engines: ^20.0.0 || ^22.0.0 || >=24.0.0`, and on Node 18 the suite
# fails 226 tests across 21 files with `Hook timed out` in ordinary
# afterEach blocks. The package itself still supports Node 18, so that
# claim is tested by the consumer-smoke job below rather than dropped.
node: ['20', '22', '24']
os: [ubuntu-latest]
include:
- node: '20'
os: windows-latest
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false
- name: Setup Node ${{ matrix.node }}
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: ${{ matrix.node }}
cache: npm
- name: Install dependencies
run: npm ci
- name: Typecheck
run: npm run typecheck
- name: Lint
run: npm run lint
# Build must precede Test: dist/ is gitignored, and the standalone CLI
# tests load the compiled warm/limits runtime out of dist/.
- name: Build
run: npm run build
- name: Test
run: npm test
# package.json declares `engines: >=18.0.0`, but the quality job cannot test
# Node 18 because the dev toolchain requires >=20. This job defends the claim
# from the consumer's side instead: pack the real tarball, install it, and run
# the CLI on Node 18. It never loads vitest or eslint.
consumer-smoke:
name: Consumer smoke (Node ${{ matrix.node }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
node: ['18']
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false
- name: Setup Node ${{ matrix.node }}
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: ${{ matrix.node }}
cache: npm
- name: Install dependencies
run: npm ci
# `npm pack` runs prepack, not prepublishOnly, so dist/ must be built here
# or the tarball ships without its compiled runtime.
- name: Build
run: npm run build
- name: Pack the publishable tarball
run: npm pack --pack-destination "$RUNNER_TEMP"
- name: Install the tarball and run the CLI
run: |
set -euo pipefail
mkdir -p "$RUNNER_TEMP/consumer"
cd "$RUNNER_TEMP/consumer"
npm init -y > /dev/null
npm install "$RUNNER_TEMP"/oc-codex-multi-auth-*.tgz
node node_modules/oc-codex-multi-auth/scripts/install-oc-codex-multi-auth.js status --json > status.json
cat status.json
node -e '
const { readFileSync } = require("node:fs");
const status = JSON.parse(readFileSync("status.json", "utf8"));
if (status.command !== "status") {
throw new Error("expected command status, got " + JSON.stringify(status.command));
}
if (typeof status.totalAccounts !== "number") {
throw new Error("status output is missing totalAccounts");
}
'
audit-ci:
name: Dependency audit
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false
- name: Setup Node 20
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: '20'
cache: npm
- name: Install dependencies
run: npm ci
- name: Audit dependencies and dev allowlist
run: npm run audit:ci