-
-
Notifications
You must be signed in to change notification settings - Fork 4
78 lines (73 loc) · 2.65 KB
/
Copy pathci.yml
File metadata and controls
78 lines (73 loc) · 2.65 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
name: ci
on:
push:
branches: [main]
pull_request:
jobs:
cli-os:
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: 22
- run: npm install
working-directory: packages/cli
- run: npm run check
working-directory: packages/cli
- run: npm test
working-directory: packages/cli
- run: node dist/index.js --version
working-directory: packages/cli
- name: Benchmark is deterministic and its committed output is fresh
# Linux-only: CRLF working trees would skew the measured token counts.
if: runner.os == 'Linux'
run: npm run bench --prefix packages/cli && git diff --exit-code docs/benchmarks/README.md
# Aggregator keeping the required status-check name "cli" stable across the OS matrix.
cli:
needs: cli-os
runs-on: ubuntu-latest
steps:
- run: echo "cli passed on all platforms"
# Dogfood the SARIF path on our own flagship skill. Uses the locally built CLI
# rather than the published action: at PR time npm has not seen this version yet.
skills:
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: 22
- run: npm install
working-directory: packages/cli
- run: npm run build
working-directory: packages/cli
- name: Lint the example skill, emitting SARIF
run: node packages/cli/dist/index.js lint examples/skills/prereview --strict --sarif kitbash.sarif
- name: Upload findings to code scanning
# Runs even when the lint fails — a failing run is exactly the one whose
# findings need to reach the Security tab.
if: always() && hashFiles('kitbash.sarif') != ''
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: kitbash.sarif
schema:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: 22
- name: Validate JSON schema is well-formed
run: node -e "JSON.parse(require('fs').readFileSync('spec/schema/skill.schema.json','utf8')); console.log('schema ok')"
- name: Committed site output is current
# build.mjs stamps the CLI version and renders CHANGELOG.md into the site,
# and its output is committed — a stale commit ships a wrong version badge.
run: node site/build.mjs --check