ci: run the checks on push and pull request
release.yml was the only workflow and it fires on v* tags, so `go vet` and `go test` first met a change once that change was already on the release path, where the only remedy is another tag. The panel suite ran nowhere at all: a release goes through the Dockerfile and the Dockerfile runs `npm run build`, never `npm test`. 111 assertions across 8 files existed and nothing outside a developer's checkout ever executed them. Both jobs are green as of this commit, checked before writing it rather than after: go vet and go test ./... (24 packages, 0 failures, on Linux), npm test (8 files, 111 tests) and npm run typecheck. A gate that lands red is a gate everyone learns to ignore. The panel's Node version is read out of the Dockerfile instead of repeated here. `FROM node:<major>` is the only place the tree declares it -- no .nvmrc, no engines field -- so a copy in this file would keep testing 22 the first time the image moved. That is the class of drift this workflow exists to catch, not to introduce. The step fails loudly if the FROM line stops matching. Tags are excluded from the push trigger. A v* push already runs release.yml, which repeats the Go job, and this is a private repository billed for both.
This commit is contained in:
1 file changed
+68
@@ -0,0 +1,68 @@
|
||||
# Runs the checks on every push and pull request.
|
||||
#
|
||||
# release.yml already runs `go vet` and `go test`, but only once a vX.Y.Z tag exists — by then
|
||||
# a red change is on the release path and the only remedy is a new tag. This is the same gate
|
||||
# moved to where it can still stop something, plus the panel suite, which nothing ran at all:
|
||||
# the release goes through the Dockerfile, and the Dockerfile runs `npm run build`, never
|
||||
# `npm test`.
|
||||
#
|
||||
# Tags are excluded from the push trigger. A vX.Y.Z push fires release.yml, which repeats the
|
||||
# Go job itself; running both would spend a private repository's Actions minutes twice for one
|
||||
# answer.
|
||||
name: ci
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: ['**']
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: ci-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
go:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: actions/setup-go@v5
|
||||
with:
|
||||
go-version-file: go.mod
|
||||
|
||||
- run: go vet ./...
|
||||
- run: go test ./...
|
||||
|
||||
panel:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
# The Dockerfile's `FROM node:<major>` is the only place the panel's Node version is
|
||||
# declared — there is no .nvmrc and no engines field. Reading it here rather than
|
||||
# repeating the number keeps CI testing the version a release is actually built on;
|
||||
# a second copy would drift silently the first time the image is bumped.
|
||||
- name: Read the panel's Node version from the Dockerfile
|
||||
id: node
|
||||
run: |
|
||||
version="$(sed -n 's/^FROM.*node:\([0-9][0-9]*\)-.*/\1/p' Dockerfile | head -1)"
|
||||
[ -n "$version" ] || { echo "Dockerfile has no 'FROM ... node:<major>' line"; exit 1; }
|
||||
echo "version=${version}" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: ${{ steps.node.outputs.version }}
|
||||
cache: npm
|
||||
cache-dependency-path: panel/package-lock.json
|
||||
|
||||
- run: npm ci
|
||||
working-directory: panel
|
||||
|
||||
- run: npm test
|
||||
working-directory: panel
|
||||
|
||||
- run: npm run typecheck
|
||||
working-directory: panel
|
||||
Reference in new issue
Block a user