Site maintenance sweep: security headers, tests, and refactors #36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| ci: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Install PNPM | |
| uses: pnpm/action-setup@v6 | |
| with: | |
| run_install: false | |
| - name: Install NodeJS | |
| uses: actions/setup-node@v7 | |
| with: | |
| node-version-file: '.nvmrc' | |
| cache: 'pnpm' | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Run ESLint | |
| run: pnpm tcd-scripts lint --only=eslint | |
| - name: Run Prettier | |
| run: pnpm tcd-scripts lint --only=prettier | |
| - name: Run TypeScript | |
| run: pnpm tcd-scripts lint --only=tsc | |
| # Ahead of the build on purpose: these need no bundler and no browser, so | |
| # a broken rule fails in seconds rather than after a build and a boot. | |
| - name: Run unit tests | |
| run: pnpm test:unit | |
| # Without this every run is a cold build: a full bundler compile, a fresh | |
| # `next/font` fetch and a full sharp re-optimisation of the profile image. | |
| - name: Cache Next build | |
| uses: actions/cache@v6 | |
| with: | |
| path: .next/cache | |
| key: next-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}-${{ hashFiles('src/**', 'public/**', 'next.config.ts') }} | |
| restore-keys: | | |
| next-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}- | |
| next-${{ runner.os }}- | |
| - name: Build | |
| run: pnpm build | |
| # Keyed on the lockfile so a Playwright version bump busts the cache. The | |
| # `restore-keys` prefix keeps the browsers on an unrelated dependency bump. | |
| - name: Cache Playwright browsers | |
| id: playwright-cache | |
| uses: actions/cache@v6 | |
| with: | |
| path: ~/.cache/ms-playwright | |
| key: playwright-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }} | |
| restore-keys: | | |
| playwright-${{ runner.os }}- | |
| # The browser binaries are cached; the system libraries are not (the | |
| # runner is fresh), so `install-deps` still runs on a cache hit. | |
| - name: Install Playwright Chromium | |
| run: pnpm exec playwright install --with-deps chromium | |
| if: steps.playwright-cache.outputs.cache-hit != 'true' | |
| - name: Install Playwright system dependencies | |
| run: pnpm exec playwright install-deps chromium | |
| if: steps.playwright-cache.outputs.cache-hit == 'true' | |
| # `playwright.config.ts` boots `pnpm start` against the build above. | |
| - name: Run E2E tests | |
| id: e2e | |
| run: pnpm test:e2e | |
| - name: Upload Playwright report | |
| if: failure() && steps.e2e.outcome == 'failure' | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: playwright-report | |
| path: playwright-report/ | |
| retention-days: 7 |