-
Notifications
You must be signed in to change notification settings - Fork 61
174 lines (150 loc) · 5.18 KB
/
Copy pathci.yml
File metadata and controls
174 lines (150 loc) · 5.18 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
name: CI
on:
pull_request:
branches: [main]
# Skip the matrix when a PR touches only docs / templates so we don't
# burn CI minutes on changes that can't possibly break a build.
paths-ignore:
- '**/*.md'
- 'docs/**'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE.md'
- CHANGELOG.md
- LICENSE
- CODE_OF_CONDUCT.md
- CONTRIBUTING.md
push:
branches: [main]
paths-ignore:
- '**/*.md'
- 'docs/**'
- '.github/ISSUE_TEMPLATE/**'
- '.github/PULL_REQUEST_TEMPLATE.md'
- CHANGELOG.md
- LICENSE
- CODE_OF_CONDUCT.md
- CONTRIBUTING.md
schedule:
# Nightly full CI run keeps the app checks fresh even without pushes.
- cron: "30 2 * * *"
# Cancel any previous in-progress run for the same ref so we don't burn
# runner minutes on superseded pushes while a PR is iterating.
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
# All jobs only need to read the repo.
permissions:
contents: read
jobs:
contracts:
name: Contracts (Rust / Soroban)
runs-on: ubuntu-latest
defaults:
run:
working-directory: contracts
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
toolchain: stable
targets: wasm32-unknown-unknown
components: rustfmt, clippy
- name: Cache cargo artifacts
uses: Swatinem/rust-cache@v2
with:
workspaces: contracts
- name: cargo fmt
run: cargo fmt --all -- --check
- name: cargo clippy (deny warnings)
run: cargo clippy --locked --workspace --all-targets -- -D warnings
- name: cargo check
run: cargo check --locked --workspace --all-targets
- name: cargo test
run: cargo test --locked --workspace
# Sanity check only: catches compile failures on the deploy target.
# Does NOT run `wasm-opt` — production Soroban artifacts come from
# `soroban contract build`, which adds the optimizer pass. Wire that
# in if CI artifacts ever become the release source.
# The workspace lockfile is enforced because Soroban 22's broad
# transitive version ranges can otherwise select incompatible majors.
- name: cargo build (wasm32 release)
run: cargo build --locked --workspace --target wasm32-unknown-unknown --release
contracts-audit:
name: Contracts Audit (cargo-deny / cargo-audit)
runs-on: ubuntu-latest
defaults:
run:
working-directory: contracts
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
toolchain: stable
- name: Cache cargo artifacts
uses: Swatinem/rust-cache@v2
with:
workspaces: contracts
- name: Install cargo-deny
uses: taiki-e/install-action@v2
with:
tool: cargo-deny
- name: Install cargo-audit
uses: taiki-e/install-action@v2
with:
tool: cargo-audit
# Scan for license conflicts, duplicate crate versions, and
# unmaintained/vulnerable dependencies. The deny.toml config
# controls thresholds and allow-lists.
- name: cargo deny check
run: cargo deny check --show-stats
# Fetch the latest RustSec advisory database and compare against
# every crate in the workspace. Exits non-zero (fails the build)
# when any advisory is found.
#
# Ignored advisories:
# RUSTSEC-2026-0009 — time v0.3.36 (DoS via stack exhaustion)
# Cannot update: time-core >=0.1.8 requires edition2024 (Rust >=1.85),
# but the contract-builder Docker image pins rust:1.84-slim.
# RUSTSEC-2024-0388 — derivative v2.2.0 (unmaintained)
# RUSTSEC-2024-0436 — paste v1.0.15 (unmaintained)
# Cannot upgrade: transitive dependencies of the Soroban SDK.
- name: cargo audit
run: cargo audit --deny=warnings --ignore RUSTSEC-2026-0009 --ignore RUSTSEC-2024-0388 --ignore RUSTSEC-2024-0436
backend:
uses: ./.github/workflows/node-matrix.yml
with:
app-name: Backend (NestJS)
working-directory: Backend
verification-command: npm test -- --runInBand
frontend:
uses: ./.github/workflows/node-matrix.yml
with:
app-name: Frontend (Next.js)
working-directory: Frontend
verification-command: npm run test
analytics:
uses: ./.github/workflows/node-matrix.yml
with:
app-name: Analytics (Next.js)
working-directory: analytics
verification-command: npm run typecheck
terraform-fmt:
name: Terraform fmt
runs-on: ubuntu-latest
defaults:
run:
working-directory: infrastructure/terraform
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Terraform
uses: hashicorp/setup-terraform@v3
with:
terraform_version: 1.9.8
# No `terraform init` needed: `fmt -check` only inspects source files.
- name: terraform fmt -check
run: terraform fmt -check -recursive