Skip to content

Site maintenance sweep: security headers, tests, and refactors #36

Site maintenance sweep: security headers, tests, and refactors

Site maintenance sweep: security headers, tests, and refactors #36

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
ci:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Install PNPM
uses: pnpm/action-setup@v6
with:
run_install: false
- name: Install NodeJS
uses: actions/setup-node@v7
with:
node-version-file: '.nvmrc'
cache: 'pnpm'
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Run ESLint
run: pnpm tcd-scripts lint --only=eslint
- name: Run Prettier
run: pnpm tcd-scripts lint --only=prettier
- name: Run TypeScript
run: pnpm tcd-scripts lint --only=tsc
# Ahead of the build on purpose: these need no bundler and no browser, so
# a broken rule fails in seconds rather than after a build and a boot.
- name: Run unit tests
run: pnpm test:unit
# Without this every run is a cold build: a full bundler compile, a fresh
# `next/font` fetch and a full sharp re-optimisation of the profile image.
- name: Cache Next build
uses: actions/cache@v6
with:
path: .next/cache
key: next-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}-${{ hashFiles('src/**', 'public/**', 'next.config.ts') }}
restore-keys: |
next-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}-
next-${{ runner.os }}-
- name: Build
run: pnpm build
# Keyed on the lockfile so a Playwright version bump busts the cache. The
# `restore-keys` prefix keeps the browsers on an unrelated dependency bump.
- name: Cache Playwright browsers
id: playwright-cache
uses: actions/cache@v6
with:
path: ~/.cache/ms-playwright
key: playwright-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}
restore-keys: |
playwright-${{ runner.os }}-
# The browser binaries are cached; the system libraries are not (the
# runner is fresh), so `install-deps` still runs on a cache hit.
- name: Install Playwright Chromium
run: pnpm exec playwright install --with-deps chromium
if: steps.playwright-cache.outputs.cache-hit != 'true'
- name: Install Playwright system dependencies
run: pnpm exec playwright install-deps chromium
if: steps.playwright-cache.outputs.cache-hit == 'true'
# `playwright.config.ts` boots `pnpm start` against the build above.
- name: Run E2E tests
id: e2e
run: pnpm test:e2e
- name: Upload Playwright report
if: failure() && steps.e2e.outcome == 'failure'
uses: actions/upload-artifact@v7
with:
name: playwright-report
path: playwright-report/
retention-days: 7