name: Dev CI on: push: branches: [dev] pull_request: branches: [dev] jobs: security: name: Security gate runs-on: ubuntu-latest steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - name: Install Trivy shell: bash run: | trivy_bin=$(bash scripts/ci/install-tool.sh trivy) "$trivy_bin" --version - name: Validate workflows and deployment checks shell: bash run: | actionlint_bin=$(bash scripts/ci/install-tool.sh actionlint) ACTIONLINT_BIN="$actionlint_bin" bash scripts/ci/validate-workflows.sh - name: Audit dependencies, secrets and infrastructure shell: bash run: bash scripts/ci/security-audit.sh - name: Show security results if: always() shell: bash run: python3 scripts/ci/summarize-security.py - name: Save security reports on Gitea if: always() uses: https://github.com/actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3, Gitea artifact protocol with: name: security-reports path: ${{ runner.temp }}/security-reports/*.json retention-days: 7 if-no-files-found: error backend-quality: name: Backend — Lint runs-on: ubuntu-latest defaults: run: working-directory: apps/backend steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - run: npm ci --legacy-peer-deps - run: npm run lint -- --no-fix frontend-quality: name: Frontend — Lint & Type-check runs-on: ubuntu-latest defaults: run: working-directory: apps/frontend steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - run: npm ci --legacy-peer-deps - run: npm run lint - run: npm run type-check backend-tests: name: Backend — Unit Tests runs-on: ubuntu-latest needs: backend-quality defaults: run: working-directory: apps/backend steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - run: npm ci --legacy-peer-deps - run: npm test -- --ci --runInBand frontend-tests: name: Frontend — Unit Tests runs-on: ubuntu-latest needs: frontend-quality defaults: run: working-directory: apps/frontend steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - run: npm ci --legacy-peer-deps - run: npm test -- --ci --runInBand notify-failure: name: Notify Failure runs-on: ubuntu-latest needs: [security, backend-quality, frontend-quality, backend-tests, frontend-tests] if: failure() steps: - name: Discord run: | curl -s -H "Content-Type: application/json" -d '{ "embeds": [{ "title": "❌ Dev CI Failed", "color": 15158332, "fields": [ {"name": "Branch", "value": "`${{ github.ref_name }}`", "inline": true}, {"name": "Author", "value": "${{ github.actor }}", "inline": true}, {"name": "Workflow", "value": "[${{ github.run_id }}](${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }})", "inline": false} ], "footer": {"text": "Xpeditis CI • Dev"} }] }' ${{ secrets.DISCORD_WEBHOOK_URL }}