| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283 |
- name: CI
- on:
- push:
- branches: [main, master]
- pull_request:
- concurrency:
- group: ${{ github.workflow }}-${{ github.ref }}
- cancel-in-progress: true
- permissions:
- contents: read
- env:
- PRIMARY_NODE_VERSION: '24'
- jobs:
- node-24:
- runs-on: ubuntu-latest
- name: node 24 / ${{ matrix.lane }}
- env:
- DSH_GATE_CONCURRENCY: ${{ matrix.gate_concurrency }}
- DSH_PUBLINT_CONCURRENCY: ${{ matrix.publint_concurrency }}
- DSH_COVERAGE_MAX_WORKERS: ${{ matrix.coverage_max_workers }}
- DSH_ESLINT_CACHE: ${{ matrix.eslint_cache }}
- strategy:
- fail-fast: false
- matrix:
- include:
- - lane: static
- command: pnpm run check:ci:static
- gate_concurrency: '4'
- publint_concurrency: '8'
- coverage_max_workers: ''
- eslint_cache: ''
- - lane: lint
- command: pnpm run check:ci:lint
- gate_concurrency: '1'
- publint_concurrency: '8'
- coverage_max_workers: ''
- eslint_cache: '1'
- - lane: coverage
- command: pnpm run check:ci:coverage
- gate_concurrency: '1'
- publint_concurrency: '8'
- coverage_max_workers: '4'
- eslint_cache: ''
- - lane: snapshot
- command: pnpm run check:ci:snapshot
- gate_concurrency: '1'
- publint_concurrency: '8'
- coverage_max_workers: ''
- eslint_cache: ''
- - lane: artifacts
- command: pnpm run check:ci:artifacts
- gate_concurrency: '3'
- publint_concurrency: '8'
- coverage_max_workers: ''
- eslint_cache: ''
- steps:
- - uses: actions/checkout@v6
- - uses: actions/setup-node@v6
- with:
- node-version: ${{ env.PRIMARY_NODE_VERSION }}
- - name: Enable corepack (pnpm)
- run: corepack enable
- - name: Resolve pnpm store path
- id: pnpm-store
- run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
- - uses: actions/cache@v4
- with:
- path: ${{ steps.pnpm-store.outputs.path }}
- key: ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-${{ hashFiles('pnpm-lock.yaml') }}
- restore-keys: |
- ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-
- - name: Install (immutable)
- run: pnpm install --frozen-lockfile
- # The snapshot lane REPLAYS the sandbox example's recorded scenarios,
- # re-executing their bash calls under a real runner. ubuntu-latest has
- # no bubblewrap preinstalled and no built Landlock launcher, so without
- # this the confined executions fail closed (SANDBOX_UNAVAILABLE). Same
- # install as sandbox.yml's bwrap leg (incl. the Ubuntu 24.04 AppArmor
- # userns knob).
- - name: Install bubblewrap (unrestrict userns)
- if: matrix.lane == 'snapshot'
- run: |
- sudo apt-get update -q
- sudo apt-get install -yq bubblewrap
- sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 \
- || echo "apparmor userns knob absent — the functional probe decides"
- - uses: actions/cache@v4
- if: matrix.lane == 'lint'
- with:
- path: .cache/eslint
- key: ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-eslint-${{ hashFiles('pnpm-lock.yaml', 'eslint.config.mjs', 'tsconfig.json', 'packages/*/*/tsconfig.json', 'examples/*/tsconfig.json') }}
- restore-keys: |
- ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-eslint-
- - name: Run gates
- run: ${{ matrix.command }}
- node-compat:
- runs-on: ubuntu-latest
- name: node ${{ matrix.node }}
- env:
- DSH_GATE_CONCURRENCY: '2'
- strategy:
- fail-fast: false
- matrix:
- node: ['22.19', 24, 26]
- steps:
- - uses: actions/checkout@v6
- - uses: actions/setup-node@v6
- with:
- node-version: ${{ matrix.node }}
- - name: Enable corepack (pnpm)
- run: corepack enable
- - name: Resolve pnpm store path
- id: pnpm-store
- run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
- - uses: actions/cache@v4
- with:
- path: ${{ steps.pnpm-store.outputs.path }}
- key: ${{ runner.os }}-node-${{ matrix.node }}-pnpm-${{ hashFiles('pnpm-lock.yaml') }}
- restore-keys: |
- ${{ runner.os }}-node-${{ matrix.node }}-pnpm-
- - name: Install (immutable)
- run: pnpm install --frozen-lockfile
- - name: Run compatibility gates
- run: pnpm run check:node-compat
- python-sdk:
- runs-on: ubuntu-latest
- name: python 3.10 / keyless SDK
- steps:
- - uses: actions/checkout@v6
- - uses: actions/setup-python@v6
- with:
- python-version: '3.10'
- cache: pip
- - name: Install uv
- run: python -m pip install uv==0.11.23
- - name: Run complete keyless Python suite
- run: uv run --python 3.10 --group test --project python/sdk pytest
- # Blocking Windows build lane: keep the already-green native build protected
- # while the broader observational gate matrix below exposes the remaining
- # portability work without blocking mainline merges.
- windows-build:
- runs-on: windows-2025
- name: windows / build
- steps:
- - uses: actions/checkout@v6
- - uses: actions/setup-node@v6
- with:
- node-version: ${{ env.PRIMARY_NODE_VERSION }}
- - name: Enable corepack (pnpm)
- run: corepack enable
- - name: Install (immutable)
- run: pnpm install --frozen-lockfile
- - name: Build (tsc -b + tsdown)
- run: pnpm run build
- # Observational, non-blocking Windows static, lint, and artifact lanes. Coverage
- # and snapshot stay Linux-only until their platform-specific runtime failures
- # have dedicated support. Run the gates from native PowerShell: an MSYS parent
- # would change the environment being measured. This job intentionally stays
- # out of all-checks-passed.needs.
- windows-gates:
- continue-on-error: true
- runs-on: windows-2025
- name: windows node 24 / ${{ matrix.lane }}
- env:
- DSH_GATE_CONCURRENCY: ${{ matrix.gate_concurrency }}
- DSH_PUBLINT_CONCURRENCY: ${{ matrix.publint_concurrency }}
- DSH_ESLINT_CACHE: ${{ matrix.eslint_cache }}
- strategy:
- fail-fast: false
- matrix:
- include:
- - lane: static
- command: pnpm run check:ci:static
- gate_concurrency: '4'
- publint_concurrency: '8'
- eslint_cache: ''
- - lane: lint
- command: pnpm run check:ci:lint
- gate_concurrency: '1'
- publint_concurrency: '8'
- eslint_cache: '1'
- - lane: artifacts
- command: pnpm run check:ci:artifacts
- gate_concurrency: '3'
- publint_concurrency: '8'
- eslint_cache: ''
- steps:
- - uses: actions/checkout@v6
- - name: Enable Developer Mode (symlink support)
- shell: pwsh
- run: >-
- reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock"
- /t REG_DWORD /f /v "AllowDevelopmentWithoutDevLicense" /d "1"
- - uses: actions/setup-node@v6
- with:
- node-version: ${{ env.PRIMARY_NODE_VERSION }}
- - name: Enable corepack (pnpm)
- shell: pwsh
- run: corepack enable
- - name: Resolve pnpm store path
- id: pnpm-store
- shell: pwsh
- run: '"path=$(pnpm store path --silent)" >> $env:GITHUB_OUTPUT'
- - uses: actions/cache@v4
- with:
- path: ${{ steps.pnpm-store.outputs.path }}
- key: ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-${{ hashFiles('pnpm-lock.yaml') }}
- restore-keys: |
- ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-
- - name: Install (immutable)
- shell: pwsh
- run: pnpm install --frozen-lockfile
- - uses: actions/cache@v4
- if: matrix.lane == 'lint'
- with:
- path: .cache/eslint
- key: ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-eslint-${{ hashFiles('pnpm-lock.yaml', 'eslint.config.mjs', 'tsconfig.json', 'packages/*/*/tsconfig.json', 'examples/*/tsconfig.json') }}
- restore-keys: |
- ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-eslint-
- - name: Run gates
- shell: pwsh
- run: ${{ matrix.command }}
- # Single stable required check for branch protection: require "all checks
- # passed" instead of enumerating matrix legs whose names change as lanes and
- # node versions evolve. Every blocking job in THIS workflow must be listed in
- # `needs`; explicitly observational jobs such as windows-gates stay out
- # (`needs` cannot reach across workflow files; e2e.yml stays its own check).
- # `if: always()` is load-bearing: without it a failed dependency
- # would SKIP this job, and GitHub counts a skipped required check as passing
- # — so this job always runs and fails on any non-success result, including
- # 'cancelled' and 'skipped'.
- all-checks-passed:
- name: all checks passed
- runs-on: ubuntu-latest
- needs: [node-24, node-compat, python-sdk, windows-build]
- if: always()
- steps:
- - name: Fail if any needed job did not succeed
- if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') || contains(needs.*.result, 'skipped')
- run: |
- echo "::error::Needed job results: ${{ join(needs.*.result, ', ') }}"
- exit 1
- - name: All checks passed
- run: echo "All needed jobs succeeded (${{ join(needs.*.result, ', ') }})"
|