mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-08 17:06:15 -08:00
Pipeline audit follow-up: reduce wasted runner time on PRs and tighten CI security, without reducing what actually gets validated. Runner-time waste: - Concurrency with PR-only cancel-in-progress on CI, E2E, and docker-build, so a new push cancels the previous commit's still-running checks. Non-PR runs use the unique run_id as the group, because GitHub keeps at most one pending run per group even with cancel-in-progress: false — a shared ref group could silently drop a queued master run. - paths-ignore for docs-only changes (Markdown, docs/, .plans/, .codex/, .claude/) on the Electron build matrix and the E2E suites; E2E also skips apps/website/**. The build workflow keeps apps/website/** because its Linux job builds the website to verify AppStream assets. Tag pushes are unaffected: GitHub does not evaluate paths filters for tags. - PRs lint affected projects only; master pushes keep the full run-many. Lint-global inputs (eslint.config.mjs, tools/eslint/**) now mark all 41 lint projects affected, including the run-commands targets database and packaging, so the max-lines baseline cannot be widened without lint. Hardening: - Explicit least-privilege permissions on CI, E2E, and build-and-make; the create-release job keeps its job-level contents: write. The repository default workflow token was switched to read-only. - New actionlint job (image pinned by digest, shellcheck at warning+), with the shared-anchor false positive suppressed in .github/actionlint.yaml. Fixed one real finding: unquoted $GITHUB_OUTPUT. - .github/dependabot.yml: weekly cadence, minor+patch grouped per ecosystem (npm, GitHub Actions, Docker), majors stay individual PRs. Docs updated: CLAUDE.md, docs/architecture/nx-workspace-boundaries.md, and docs/architecture/validation-map.md now describe affected-lint on PRs and the E2E path-filter exceptions.
142 lines
4.3 KiB
YAML
142 lines
4.3 KiB
YAML
name: 'Cross-Platform E2E Tests'
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- master
|
|
paths-ignore:
|
|
- '**/*.md'
|
|
- 'docs/**'
|
|
- '.plans/**'
|
|
- '.codex/**'
|
|
- '.claude/**'
|
|
- 'apps/website/**'
|
|
pull_request:
|
|
branches:
|
|
- master
|
|
paths-ignore:
|
|
- '**/*.md'
|
|
- 'docs/**'
|
|
- '.plans/**'
|
|
- '.codex/**'
|
|
- '.claude/**'
|
|
- 'apps/website/**'
|
|
workflow_dispatch:
|
|
|
|
# Superseded PR pushes cancel their still-running E2E matrix (the most
|
|
# expensive per-PR runner time). Non-PR runs get a unique group (run_id):
|
|
# GitHub keeps at most one pending run per group even with
|
|
# cancel-in-progress: false, so a shared ref group could silently drop a
|
|
# queued master run between two rapid pushes.
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
|
|
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
electron-e2e-tests:
|
|
name: Electron E2E on ${{ matrix.os }}
|
|
runs-on: ${{ matrix.os }}
|
|
timeout-minutes: 45
|
|
env:
|
|
IPTVNATOR_ALLOW_PRIVATE_NETWORK_URLS: '1'
|
|
NX_SKIP_NX_CACHE: true
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
os: [ubuntu-latest, macos-latest, windows-latest]
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install pnpm
|
|
uses: pnpm/action-setup@v4
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
cache: 'pnpm'
|
|
|
|
- name: Install Dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Build Backend
|
|
run: pnpm nx build electron-backend
|
|
|
|
- name: Install Playwright Browsers
|
|
run: pnpm exec playwright install --with-deps
|
|
|
|
- name: Run Electron E2E Tests (Linux)
|
|
if: runner.os == 'Linux'
|
|
run: xvfb-run --auto-servernum --server-args="-screen 0 1280x960x24" pnpm nx run electron-backend-e2e:e2e
|
|
env:
|
|
CI: true
|
|
|
|
- name: Run Electron E2E Tests (Windows/Mac)
|
|
if: runner.os != 'Linux'
|
|
run: pnpm nx run electron-backend-e2e:e2e
|
|
env:
|
|
CI: true
|
|
|
|
- name: Summarize Electron E2E semantic coverage
|
|
if: always()
|
|
run: pnpm run coverage:e2e:summary -- --project=electron-backend-e2e
|
|
|
|
- name: Upload Electron Test Results
|
|
if: always()
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: playwright-report-electron-${{ matrix.os }}
|
|
path: |
|
|
dist/playwright-report/electron-backend-e2e/
|
|
dist/test-results/electron-backend-e2e/
|
|
coverage/e2e/
|
|
retention-days: 7
|
|
|
|
web-e2e-tests:
|
|
name: Web E2E on Ubuntu Chromium
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
NX_SKIP_NX_CACHE: true
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install pnpm
|
|
uses: pnpm/action-setup@v4
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
cache: 'pnpm'
|
|
|
|
- name: Install Dependencies
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Install Chromium
|
|
run: pnpm exec playwright install --with-deps chromium
|
|
|
|
- name: Run Web E2E Tests
|
|
run: pnpm nx run web-e2e:e2e -- --project=chromium
|
|
env:
|
|
CI: true
|
|
|
|
- name: Summarize Web E2E semantic coverage
|
|
if: always()
|
|
run: pnpm run coverage:e2e:summary -- --project=web-e2e
|
|
|
|
- name: Upload Web Test Results
|
|
if: always()
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: playwright-report-web-ubuntu
|
|
path: |
|
|
dist/playwright-report/web-e2e/
|
|
dist/test-results/web-e2e/
|
|
coverage/e2e/
|
|
retention-days: 7
|