| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166 |
- name: CI
- on:
- push:
- branches: [main, master]
- pull_request:
- concurrency:
- group: ${{ github.workflow }}-${{ github.ref }}
- cancel-in-progress: true
- permissions:
- contents: read
- env:
- PRIMARY_NODE_VERSION: '24'
- jobs:
- node-24:
- runs-on: ubuntu-latest
- name: node 24 / ${{ matrix.lane }}
- env:
- DSH_GATE_CONCURRENCY: ${{ matrix.gate_concurrency }}
- DSH_PUBLINT_CONCURRENCY: ${{ matrix.publint_concurrency }}
- DSH_COVERAGE_MAX_WORKERS: ${{ matrix.coverage_max_workers }}
- DSH_ESLINT_CACHE: ${{ matrix.eslint_cache }}
- strategy:
- fail-fast: false
- matrix:
- include:
- - lane: static
- command: pnpm run check:ci:static
- gate_concurrency: '4'
- publint_concurrency: '8'
- coverage_max_workers: ''
- eslint_cache: ''
- - lane: lint
- command: pnpm run check:ci:lint
- gate_concurrency: '1'
- publint_concurrency: '8'
- coverage_max_workers: ''
- eslint_cache: '1'
- - lane: coverage
- command: pnpm run check:ci:coverage
- gate_concurrency: '1'
- publint_concurrency: '8'
- coverage_max_workers: '4'
- eslint_cache: ''
- - lane: snapshot
- command: pnpm run check:ci:snapshot
- gate_concurrency: '1'
- publint_concurrency: '8'
- coverage_max_workers: ''
- eslint_cache: ''
- - lane: artifacts
- command: pnpm run check:ci:artifacts
- gate_concurrency: '3'
- publint_concurrency: '8'
- coverage_max_workers: ''
- eslint_cache: ''
- steps:
- - uses: actions/checkout@v6
- - uses: actions/setup-node@v6
- with:
- node-version: ${{ env.PRIMARY_NODE_VERSION }}
- - name: Enable corepack (pnpm)
- run: corepack enable
- - name: Resolve pnpm store path
- id: pnpm-store
- run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
- - uses: actions/cache@v4
- with:
- path: ${{ steps.pnpm-store.outputs.path }}
- key: ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-${{ hashFiles('pnpm-lock.yaml') }}
- restore-keys: |
- ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-
- - name: Install (immutable)
- run: pnpm install --frozen-lockfile
- # The snapshot lane REPLAYS the sandbox example's recorded scenarios,
- # re-executing their bash calls under a real runner. ubuntu-latest has
- # no bubblewrap preinstalled and no built Landlock launcher, so without
- # this the confined executions fail closed (SANDBOX_UNAVAILABLE). Same
- # install as sandbox.yml's bwrap leg (incl. the Ubuntu 24.04 AppArmor
- # userns knob).
- - name: Install bubblewrap (unrestrict userns)
- if: matrix.lane == 'snapshot'
- run: |
- sudo apt-get update -q
- sudo apt-get install -yq bubblewrap
- sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 \
- || echo "apparmor userns knob absent — the functional probe decides"
- - uses: actions/cache@v4
- if: matrix.lane == 'lint'
- with:
- path: .cache/eslint
- key: ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-eslint-${{ hashFiles('pnpm-lock.yaml', 'eslint.config.mjs', 'tsconfig.json', 'packages/*/*/tsconfig.json', 'examples/*/tsconfig.json') }}
- restore-keys: |
- ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-eslint-
- - name: Run gates
- run: ${{ matrix.command }}
- node-compat:
- runs-on: ubuntu-latest
- name: node ${{ matrix.node }}
- env:
- DSH_GATE_CONCURRENCY: '2'
- strategy:
- fail-fast: false
- matrix:
- node: ['22.19', 24, 26]
- steps:
- - uses: actions/checkout@v6
- - uses: actions/setup-node@v6
- with:
- node-version: ${{ matrix.node }}
- - name: Enable corepack (pnpm)
- run: corepack enable
- - name: Resolve pnpm store path
- id: pnpm-store
- run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
- - uses: actions/cache@v4
- with:
- path: ${{ steps.pnpm-store.outputs.path }}
- key: ${{ runner.os }}-node-${{ matrix.node }}-pnpm-${{ hashFiles('pnpm-lock.yaml') }}
- restore-keys: |
- ${{ runner.os }}-node-${{ matrix.node }}-pnpm-
- - name: Install (immutable)
- run: pnpm install --frozen-lockfile
- - name: Run compatibility gates
- run: pnpm run check:node-compat
- # Single stable required check for branch protection: require "all checks
- # passed" instead of enumerating matrix legs whose names change as lanes and
- # node versions evolve. Every other job in THIS workflow must be listed in
- # `needs` (`needs` cannot reach across workflow files; e2e.yml stays its own
- # check). `if: always()` is load-bearing: without it a failed dependency
- # would SKIP this job, and GitHub counts a skipped required check as passing
- # — so this job always runs and fails on any non-success result, including
- # 'cancelled' and 'skipped'.
- all-checks-passed:
- name: all checks passed
- runs-on: ubuntu-latest
- needs: [node-24, node-compat]
- if: always()
- steps:
- - name: Fail if any needed job did not succeed
- if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') || contains(needs.*.result, 'skipped')
- run: |
- echo "::error::Needed job results: ${{ join(needs.*.result, ', ') }}"
- exit 1
- - name: All checks passed
- run: echo "All needed jobs succeeded (${{ join(needs.*.result, ', ') }})"
|