name: PR Checks # Required status checks — configure these in branch protection rules. # PRs to preprod : lint + type-check + unit tests + integration tests # PRs to main : same checks, including integration and security on: pull_request: branches: [preprod, main] jobs: security: name: Security gate runs-on: ubuntu-latest steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - name: Install Trivy shell: bash run: | trivy_bin=$(bash scripts/ci/install-tool.sh trivy) "$trivy_bin" --version - name: Validate workflows and deployment checks shell: bash run: | actionlint_bin=$(bash scripts/ci/install-tool.sh actionlint) ACTIONLINT_BIN="$actionlint_bin" bash scripts/ci/validate-workflows.sh - name: Audit dependencies, secrets and infrastructure shell: bash run: bash scripts/ci/security-audit.sh - name: Show security results if: always() shell: bash run: python3 scripts/ci/summarize-security.py - name: Save security reports on Gitea if: always() uses: https://github.com/actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3, Gitea artifact protocol with: name: security-reports path: ${{ runner.temp }}/security-reports/*.json retention-days: 7 if-no-files-found: error backend-quality: name: Backend — Lint runs-on: ubuntu-latest defaults: run: working-directory: apps/backend steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - run: npm ci --legacy-peer-deps - run: npm run lint -- --no-fix frontend-quality: name: Frontend — Lint & Type-check runs-on: ubuntu-latest defaults: run: working-directory: apps/frontend steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - run: npm ci --legacy-peer-deps - run: npm run lint - run: npm run type-check backend-tests: name: Backend — Unit Tests runs-on: ubuntu-latest needs: backend-quality defaults: run: working-directory: apps/backend steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - run: npm ci --legacy-peer-deps - run: npm test -- --ci --runInBand frontend-tests: name: Frontend — Unit Tests runs-on: ubuntu-latest needs: frontend-quality defaults: run: working-directory: apps/frontend steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - run: npm ci --legacy-peer-deps - run: npm test -- --ci --runInBand # Integration tests validate the actual merge candidate for both branches. integration-tests: name: Backend — Integration Tests runs-on: ubuntu-latest needs: backend-tests defaults: run: working-directory: apps/backend services: postgres: image: postgres:15-alpine env: POSTGRES_USER: xpeditis_test POSTGRES_PASSWORD: xpeditis_test_password POSTGRES_DB: xpeditis_test options: >- --health-cmd pg_isready --health-interval 5s --health-timeout 5s --health-retries 10 redis: image: redis:7-alpine options: >- --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 5s --health-retries 10 steps: - uses: https://github.com/actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: persist-credentials: false - uses: ./.gitea/actions/setup-node - run: npm ci --legacy-peer-deps - name: Run integration tests env: NODE_ENV: test TEST_DB_HOST: postgres TEST_DB_PORT: 5432 TEST_DB_USER: xpeditis_test TEST_DB_PASSWORD: xpeditis_test_password TEST_DB_NAME: xpeditis_test DATABASE_HOST: postgres DATABASE_PORT: 5432 DATABASE_USER: xpeditis_test DATABASE_PASSWORD: xpeditis_test_password DATABASE_NAME: xpeditis_test DATABASE_SYNCHRONIZE: 'false' REDIS_HOST: redis REDIS_PORT: 6379 REDIS_PASSWORD: '' JWT_SECRET: test-secret-key-ci SMTP_HOST: localhost SMTP_PORT: 1025 SMTP_FROM: test@xpeditis.com run: npm run test:integration -- --ci --runInBand