name: CI on: push: branches: [main] pull_request: branches: [main] concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true permissions: contents: read jobs: lint: name: Lint runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 22 cache: npm - run: npm ci - run: npm run lint - run: npm run check:cycles - run: npm run check:route-validation:t06 - run: npm run check:any-budget:t11 - run: npm run check:docs-sync - run: npm run typecheck:core - run: npm run typecheck:noimplicit:core i18n-matrix: name: Build language matrix runs-on: ubuntu-latest outputs: langs: ${{ steps.langs.outputs.langs }} steps: - uses: actions/checkout@v4 - id: langs run: | LANG_DIR="src/i18n/messages" LANGS=$(ls "$LANG_DIR"/*.json | xargs -n1 basename | sed 's/.json$//' | grep -v '^en$' | jq -R . | jq -s . | jq -c .) echo "langs=${LANGS}" >> $GITHUB_OUTPUT i18n: name: i18n Validation runs-on: ubuntu-latest continue-on-error: true strategy: fail-fast: false matrix: lang: ${{ fromJson(needs.i18n-matrix.outputs.langs) }} needs: i18n-matrix steps: - uses: actions/checkout@v4 - uses: actions/setup-python@v6.2.0 with: python-version: "3.12" - name: Validate ${{ matrix.lang }} run: | python3 scripts/validate_translation.py quick -l '${{ matrix.lang }}' > result.txt - name: Upload result if: always() uses: actions/upload-artifact@v4 with: name: i18n-${{ matrix.lang }} path: result.txt security: name: Security Audit runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 22 cache: npm - run: npm ci - name: Dependency audit run: npm audit --audit-level=high --omit=dev || true - name: Check for known vulnerabilities run: npx is-my-node-vulnerable || true build: name: Build runs-on: ubuntu-latest strategy: matrix: node-version: [20, 22] steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: ${{ matrix.node-version }} cache: npm - run: npm ci - run: npm run build test-unit: name: Unit Tests runs-on: ubuntu-latest needs: build strategy: matrix: node-version: [20, 22] env: JWT_SECRET: ci-test-secret-with-sufficient-length-for-validation API_KEY_SECRET: ci-test-api-key-secret-long steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: ${{ matrix.node-version }} cache: npm - run: npm ci - run: npm run test:unit test-coverage: name: Coverage runs-on: ubuntu-latest needs: build env: JWT_SECRET: ci-test-secret-with-sufficient-length-for-validation API_KEY_SECRET: ci-test-api-key-secret-long steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 22 cache: npm - run: npm ci - run: npm run test:coverage test-e2e: name: E2E Tests runs-on: ubuntu-latest needs: build env: JWT_SECRET: ci-test-secret-with-sufficient-length-for-validation API_KEY_SECRET: ci-test-api-key-secret-long steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 22 cache: npm - run: npm ci - run: npx playwright install --with-deps chromium - run: npm run build - run: npm run test:e2e test-integration: name: Integration Tests runs-on: ubuntu-latest needs: build env: JWT_SECRET: ci-test-secret-with-sufficient-length-for-validation API_KEY_SECRET: ci-test-api-key-secret-long INITIAL_PASSWORD: ci-test-password-for-integration DATA_DIR: /tmp/omniroute-ci steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 22 cache: npm - run: npm ci - run: npm run test:integration test-security: name: Security Tests runs-on: ubuntu-latest needs: build env: JWT_SECRET: ci-test-secret-with-sufficient-length-for-validation API_KEY_SECRET: ci-test-api-key-secret-long steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 22 cache: npm - run: npm ci - run: npm run test:security # ๐Ÿ”ฅ DASHBOARD ci-summary: name: CI Dashboard runs-on: ubuntu-latest if: always() needs: - lint - security - build - test-unit - test-coverage - test-e2e - test-integration - test-security - i18n steps: - name: Download i18n results uses: actions/download-artifact@v4 with: path: results - name: Generate dashboard run: | status() { case "$1" in success) echo "๐ŸŸข PASS" ;; failure) echo "๐Ÿ”ด FAIL" ;; cancelled) echo "โšซ CANCELLED" ;; *) echo "๐ŸŸก UNKNOWN" ;; esac } echo "# ๐Ÿš€ CI Dashboard" >> $GITHUB_STEP_SUMMARY echo "" >> $GITHUB_STEP_SUMMARY # ๐Ÿ”น CORE echo "## ๐Ÿงฑ Core Checks" >> $GITHUB_STEP_SUMMARY echo "| Job | Status |" >> $GITHUB_STEP_SUMMARY echo "|-----|--------|" >> $GITHUB_STEP_SUMMARY echo "| Lint | $(status '${{ needs.lint.result }}') |" >> $GITHUB_STEP_SUMMARY echo "| Security Audit | $(status '${{ needs.security.result }}') |" >> $GITHUB_STEP_SUMMARY # ๐Ÿ”น BUILD echo "" >> $GITHUB_STEP_SUMMARY echo "## ๐Ÿ—๏ธ Build" >> $GITHUB_STEP_SUMMARY echo "| Job | Status |" >> $GITHUB_STEP_SUMMARY echo "|-----|--------|" >> $GITHUB_STEP_SUMMARY echo "| Build Matrix | $(status '${{ needs.build.result }}') |" >> $GITHUB_STEP_SUMMARY # ๐Ÿ”น TESTS echo "" >> $GITHUB_STEP_SUMMARY echo "## ๐Ÿงช Tests" >> $GITHUB_STEP_SUMMARY echo "| Suite | Status |" >> $GITHUB_STEP_SUMMARY echo "|-------|--------|" >> $GITHUB_STEP_SUMMARY echo "| Unit | $(status '${{ needs.test-unit.result }}') |" >> $GITHUB_STEP_SUMMARY echo "| Coverage | $(status '${{ needs.test-coverage.result }}') |" >> $GITHUB_STEP_SUMMARY echo "| E2E | $(status '${{ needs.test-e2e.result }}') |" >> $GITHUB_STEP_SUMMARY echo "| Integration | $(status '${{ needs.test-integration.result }}') |" >> $GITHUB_STEP_SUMMARY echo "| Security Tests | $(status '${{ needs.test-security.result }}') |" >> $GITHUB_STEP_SUMMARY # ๐Ÿ”น I18N echo "" >> $GITHUB_STEP_SUMMARY echo "## ๐ŸŒ Translations" >> $GITHUB_STEP_SUMMARY total=0 langs=0 for dir in results/*; do file="$dir/result.txt" val=$(sed -r 's/\x1B\[[0-9;]*[mK]//g' "$file" | grep "Untranslated:" | awk '{print $2}') val=${val:-0} total=$((total + val)) langs=$((langs + 1)) done echo "" >> $GITHUB_STEP_SUMMARY echo "| Metric | Value |" >> $GITHUB_STEP_SUMMARY echo "|--------|------|" >> $GITHUB_STEP_SUMMARY echo "| Languages checked | $langs |" >> $GITHUB_STEP_SUMMARY echo "| Total untranslated | $total |" >> $GITHUB_STEP_SUMMARY if [ "$total" -gt 0 ]; then echo "" >> $GITHUB_STEP_SUMMARY echo "โš ๏ธ **Translations need attention**" >> $GITHUB_STEP_SUMMARY else echo "" >> $GITHUB_STEP_SUMMARY echo "โœ… **All translations complete**" >> $GITHUB_STEP_SUMMARY fi