Files
iptvnator/.github/workflows/e2e-tests.yaml
T
4gray cfa602d5b1 ci: cut PR runner waste and harden workflow permissions (#1226)
Pipeline audit follow-up: reduce wasted runner time on PRs and tighten CI
security, without reducing what actually gets validated.

Runner-time waste:
- Concurrency with PR-only cancel-in-progress on CI, E2E, and docker-build,
  so a new push cancels the previous commit's still-running checks. Non-PR
  runs use the unique run_id as the group, because GitHub keeps at most one
  pending run per group even with cancel-in-progress: false — a shared ref
  group could silently drop a queued master run.
- paths-ignore for docs-only changes (Markdown, docs/, .plans/, .codex/,
  .claude/) on the Electron build matrix and the E2E suites; E2E also skips
  apps/website/**. The build workflow keeps apps/website/** because its Linux
  job builds the website to verify AppStream assets. Tag pushes are
  unaffected: GitHub does not evaluate paths filters for tags.
- PRs lint affected projects only; master pushes keep the full run-many.
  Lint-global inputs (eslint.config.mjs, tools/eslint/**) now mark all 41
  lint projects affected, including the run-commands targets database and
  packaging, so the max-lines baseline cannot be widened without lint.

Hardening:
- Explicit least-privilege permissions on CI, E2E, and build-and-make; the
  create-release job keeps its job-level contents: write. The repository
  default workflow token was switched to read-only.
- New actionlint job (image pinned by digest, shellcheck at warning+), with
  the shared-anchor false positive suppressed in .github/actionlint.yaml.
  Fixed one real finding: unquoted $GITHUB_OUTPUT.
- .github/dependabot.yml: weekly cadence, minor+patch grouped per ecosystem
  (npm, GitHub Actions, Docker), majors stay individual PRs.

Docs updated: CLAUDE.md, docs/architecture/nx-workspace-boundaries.md, and
docs/architecture/validation-map.md now describe affected-lint on PRs and the
E2E path-filter exceptions.
2026-07-25 14:37:40 +02:00

142 lines
4.3 KiB
YAML

name: 'Cross-Platform E2E Tests'
on:
push:
branches:
- master
paths-ignore:
- '**/*.md'
- 'docs/**'
- '.plans/**'
- '.codex/**'
- '.claude/**'
- 'apps/website/**'
pull_request:
branches:
- master
paths-ignore:
- '**/*.md'
- 'docs/**'
- '.plans/**'
- '.codex/**'
- '.claude/**'
- 'apps/website/**'
workflow_dispatch:
# Superseded PR pushes cancel their still-running E2E matrix (the most
# expensive per-PR runner time). Non-PR runs get a unique group (run_id):
# GitHub keeps at most one pending run per group even with
# cancel-in-progress: false, so a shared ref group could silently drop a
# queued master run between two rapid pushes.
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
jobs:
electron-e2e-tests:
name: Electron E2E on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
timeout-minutes: 45
env:
IPTVNATOR_ALLOW_PRIVATE_NETWORK_URLS: '1'
NX_SKIP_NX_CACHE: true
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
steps:
- uses: actions/checkout@v4
- name: Install pnpm
uses: pnpm/action-setup@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '22'
cache: 'pnpm'
- name: Install Dependencies
run: pnpm install --frozen-lockfile
- name: Build Backend
run: pnpm nx build electron-backend
- name: Install Playwright Browsers
run: pnpm exec playwright install --with-deps
- name: Run Electron E2E Tests (Linux)
if: runner.os == 'Linux'
run: xvfb-run --auto-servernum --server-args="-screen 0 1280x960x24" pnpm nx run electron-backend-e2e:e2e
env:
CI: true
- name: Run Electron E2E Tests (Windows/Mac)
if: runner.os != 'Linux'
run: pnpm nx run electron-backend-e2e:e2e
env:
CI: true
- name: Summarize Electron E2E semantic coverage
if: always()
run: pnpm run coverage:e2e:summary -- --project=electron-backend-e2e
- name: Upload Electron Test Results
if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report-electron-${{ matrix.os }}
path: |
dist/playwright-report/electron-backend-e2e/
dist/test-results/electron-backend-e2e/
coverage/e2e/
retention-days: 7
web-e2e-tests:
name: Web E2E on Ubuntu Chromium
runs-on: ubuntu-latest
env:
NX_SKIP_NX_CACHE: true
steps:
- uses: actions/checkout@v4
- name: Install pnpm
uses: pnpm/action-setup@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '22'
cache: 'pnpm'
- name: Install Dependencies
run: pnpm install --frozen-lockfile
- name: Install Chromium
run: pnpm exec playwright install --with-deps chromium
- name: Run Web E2E Tests
run: pnpm nx run web-e2e:e2e -- --project=chromium
env:
CI: true
- name: Summarize Web E2E semantic coverage
if: always()
run: pnpm run coverage:e2e:summary -- --project=web-e2e
- name: Upload Web Test Results
if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report-web-ubuntu
path: |
dist/playwright-report/web-e2e/
dist/test-results/web-e2e/
coverage/e2e/
retention-days: 7