forked from Talenttrust/Talenttrust-Backend
-
Notifications
You must be signed in to change notification settings - Fork 0
176 lines (149 loc) · 5.21 KB
/
Copy pathci.yml
File metadata and controls
176 lines (149 loc) · 5.21 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
##
# CI Pipeline — TalentTrust Backend
#
# Gates (all must pass before merge):
# 1. lint — ESLint with TypeScript rules
# 2. test — Jest + coverage (application code only; thresholds in jest.config.js)
# 3. build — TypeScript compilation (strict)
# 4. security — npm audit (fails on HIGH or CRITICAL vulnerabilities);
# uploads npm-audit-report.json as a workflow artifact for
# review and triage (retained 30 days, visible in Actions UI)
#
# Branch protection: configure GitHub to require all four status checks
# before merging into `main`. See docs/backend/branch-protection.md.
##
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
# Cancel in-progress runs for the same branch to save CI minutes.
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
# ── 1. Lint ────────────────────────────────────────────────────────────────
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
cache: 'npm'
- name: Install dependencies
run: npm ci
- name: Run ESLint
run: npm run lint
# ── 2. Test (with coverage) ────────────────────────────────────────────────
test:
name: Test
runs-on: ubuntu-latest
services:
redis:
image: redis:7-alpine
ports:
- 6379:6379
options: >-
--health-cmd "redis-cli ping"
--health-interval 2s
--health-timeout 5s
--health-retries 5
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
cache: 'npm'
- name: Install dependencies
run: npm ci
env:
REDIS_HOST: localhost
REDIS_PORT: "6379"
- name: Run tests with coverage
run: npm run test:ci
env:
CI: "true"
REDIS_HOST: localhost
REDIS_PORT: "6379"
- name: Upload coverage report
uses: actions/upload-artifact@v4
if: always()
with:
name: coverage-report
path: coverage/
retention-days: 14
# ── 3. Build ───────────────────────────────────────────────────────────────
build:
name: Build
runs-on: ubuntu-latest
needs: [lint, test]
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
cache: 'npm'
- name: Install dependencies
run: npm ci
- name: Compile TypeScript
run: npm run build
- name: Upload build artifact
uses: actions/upload-artifact@v4
with:
name: dist
path: dist/
retention-days: 7
# ── 4. Security audit ─────────────────────────────────────────────────────
security:
name: Security Audit
runs-on: ubuntu-latest
# Least-privilege: read-only checkout; no tokens needed for npm audit.
permissions:
contents: read
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
cache: 'npm'
- name: Install dependencies
run: npm ci
- name: Generate JSON audit report
# Always write the report regardless of exit code so the artifact is
# available for triage even when the policy gate below fails.
# No registry credentials are passed; npm audit queries the public
# advisory database over HTTPS without authentication.
run: npm run security:audit:json > npm-audit-report.json || true
- name: Upload audit report artifact
uses: actions/upload-artifact@v4
if: always()
with:
name: npm-audit-report
path: npm-audit-report.json
retention-days: 30
- name: npm audit policy gate (HIGH + CRITICAL)
# This step enforces the hard failure threshold. It runs after the
# artifact is uploaded so reviewers always have the report available.
run: npm run audit:ci
# ── 5. OpenAPI Validation ──────────────────────────────────────────────────
openapi:
name: OpenAPI Spec Validation
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
cache: 'npm'
- name: Install dependencies
run: npm ci
- name: Generate and Validate Spec
run: npm run test:docs