Bump node from 26.6.0-slim to 26.7.0-slim #9890
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: "Push" | |
| on: | |
| push: | |
| branches: | |
| - main | |
| pull_request: | |
| release: | |
| types: | |
| - published | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} | |
| cancel-in-progress: true | |
| permissions: {} | |
| jobs: | |
| build: | |
| name: Build and cache Docker image | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: "Checkout" | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 | |
| - name: "Login to Docker Hub" | |
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| continue-on-error: true | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_PASSWORD }} | |
| - name: Build Docker Image | |
| uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 | |
| with: | |
| context: . | |
| target: dev | |
| push: false | |
| tags: gmri/neracoos-mariners-dashboard:latest | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max | |
| outputs: type=docker,dest=/tmp/myimage.tar | |
| - name: Upload dev image artifact | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: dev-image | |
| path: /tmp/myimage.tar | |
| retention-days: 1 | |
| build-prod: | |
| name: Build production Docker image | |
| runs-on: ubuntu-24.04 | |
| needs: build | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: "Checkout" | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 | |
| - name: Download dev image artifact | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: dev-image | |
| path: /tmp | |
| - name: Load Docker image | |
| run: | | |
| docker load --input /tmp/myimage.tar | |
| docker image ls -a | |
| - name: Build Docker Image | |
| uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 | |
| with: | |
| context: . | |
| target: runner | |
| push: false | |
| tags: gmri/neracoos-mariners-dashboard:latest | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max | |
| outputs: type=docker,dest=/tmp/prodimage.tar | |
| - name: Upload production image artifact | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: prod-image | |
| path: /tmp/prodimage.tar | |
| retention-days: 1 | |
| unit_tests: | |
| name: Unit tests, typecheck and coverage | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: "Checkout" | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: mise action | |
| uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4 | |
| - name: Cache node modules | |
| id: cache-npm | |
| uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| env: | |
| cache-name: cache-node-modules | |
| with: | |
| # npm cache files are stored in `~/.npm` on Linux/macOS | |
| path: ~/.npm | |
| key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ hashFiles('**/package-lock.json') }} | |
| restore-keys: | | |
| ${{ runner.os }}-build-${{ env.cache-name }}- | |
| ${{ runner.os }}-build- | |
| ${{ runner.os }}- | |
| - name: Install dependencies | |
| run: npm install --frozen-lockfile | |
| - name: Install Playwright | |
| run: npx playwright install chromium | |
| - name: Run unit and Storybook tests and coverage | |
| env: | |
| CODACY_PROJECT_TOKEN: ${{ secrets.CODACY_PROJECT_TOKEN }} | |
| if: env.CODACY_PROJECT_TOKEN != null | |
| run: npm run test:coverage | |
| - name: Codacy Coverage Reporter | |
| if: env.CODACY_PROJECT_TOKEN != null | |
| uses: codacy/codacy-coverage-reporter-action@89d6c85cfafaec52c72b6c5e8b2878d33104c699 # v1.3.0 | |
| with: | |
| project-token: ${{ secrets.CODACY_PROJECT_TOKEN }} | |
| coverage-reports: ./coverage/lcov.info | |
| - name: Run unit and Storybook test (and skip coverage if no project token secret) | |
| env: | |
| CODACY_PROJECT_TOKEN: ${{ secrets.CODACY_PROJECT_TOKEN }} | |
| if: env.CODACY_PROJECT_TOKEN == null | |
| run: npm run test-ci | |
| - name: npm run Build | |
| run: npm run build | |
| - name: Build Storybook Pages | |
| run: npm run build-storybook | |
| # - name: Cache Storybook Build | |
| # uses: actions/cache@v6.1.0 | |
| # with: | |
| # path: /tmp/storybook-public/ | |
| # key: mariners-dashboard-storybook-${{ github.sha }} | |
| # - name: Copy Storybook Build to cache directory | |
| # run: | | |
| # rm -rf /tmp/storybook-public | |
| # cp -r storybook-public /tmp/storybook-public | |
| playwright: | |
| name: Playwright integration tests | |
| runs-on: ubuntu-24.04 | |
| needs: build-prod | |
| timeout-minutes: 30 | |
| permissions: | |
| contents: read | |
| env: | |
| # Playwright uses this env var for the browser install path. See: | |
| # https://playwright.dev/docs/ci#directories-to-cache | |
| # It makes most sense to default this to something cross-platform | |
| PLAYWRIGHT_BROWSERS_PATH: ${{ github.workspace }}/ms-playwright | |
| steps: | |
| - name: "Checkout" | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: "22" | |
| cache: npm | |
| - name: Download production image artifact | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: prod-image | |
| path: /tmp | |
| - name: Load Docker image | |
| run: | | |
| docker load --input /tmp/prodimage.tar | |
| docker image ls -a | |
| - name: Start container | |
| run: docker compose up -d client | |
| - run: npm install --frozen-lockfile | |
| # Use Playwright version as part of the cache key | |
| # AFAIK this is a x-platform way to get your installed Playwright version. | |
| # Be sure to be diligent in specifying ^, ~, or locked versions. | |
| - run: | | |
| echo "PLAYWRIGHT_VERSION=$(node -e "process.stdout.write(require('@playwright/test/package.json').version)")" >> $GITHUB_OUTPUT | |
| id: playwright-version | |
| # Cache action | |
| - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| id: playwright-cache | |
| with: | |
| key: ${{ runner.os }}-playwright-${{ steps.playwright-version.outputs.PLAYWRIGHT_VERSION }} | |
| path: ${{ env.PLAYWRIGHT_BROWSERS_PATH }} | |
| # This command should work and only be ran on cold cache | |
| - run: npx playwright install | |
| if: steps.playwright-cache.outputs.cache-hit != 'true' | |
| - name: Wait for container to become available | |
| run: npx wait-on http://localhost:3000 | |
| timeout-minutes: 1 | |
| - name: Run Playwright tests | |
| run: npm run test:e2e | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: always() | |
| with: | |
| name: playwright-report | |
| path: playwright-report/ | |
| retention-days: 30 | |
| # pages: | |
| # name: Deploy Storybook to Github Pages on version tag | |
| # runs-on: ubuntu-24.04 | |
| # needs: [unit_tests, playwright] | |
| # timeout-minutes: 10 | |
| # if: | | |
| # github.repository == 'gulfofmaine/Neracoos-1-Buoy-App' | |
| # && contains(github.ref, 'refs/tags/v') | |
| # steps: | |
| # - name: "Checkout" | |
| # uses: actions/checkout@v7.0.0 | |
| # - name: Cache Storybook Build | |
| # uses: actions/cache@v6.1.0 | |
| # with: | |
| # path: /tmp/storybook-public/ | |
| # key: mariners-dashboard-storybook-${{ github.sha }} | |
| # - name: Deploy Storybook to Github Pages 🚀 | |
| # uses: JamesIves/github-pages-deploy-action@v4.4.3 | |
| # with: | |
| # branch: gh-pages | |
| # folder: /tmp/storybook-public/ | |
| push_image: | |
| name: Build and push tagged image to Docker Hub | |
| runs-on: ubuntu-24.04 | |
| needs: [unit_tests, playwright] | |
| timeout-minutes: 20 | |
| environment: Deploy with ArgoCD | |
| outputs: | |
| tag: ${{ steps.tagName.outputs.tag }} | |
| image_digest: ${{ steps.push.outputs.digest }} | |
| if: | | |
| github.repository == 'gulfofmaine/Neracoos-1-Buoy-App' | |
| && github.event_name == 'release' | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: "Checkout" | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 | |
| - name: Download production image artifact | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: prod-image | |
| path: /tmp | |
| - name: Load Docker image | |
| run: | | |
| docker load --input /tmp/prodimage.tar | |
| docker image ls -a | |
| - name: "Login to Docker Hub" | |
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_PASSWORD }} | |
| - name: Get tag name | |
| id: tagName | |
| run: echo "tag=${GITHUB_EVENT_RELEASE_TAG_NAME}" >> $GITHUB_OUTPUT | |
| env: | |
| GITHUB_EVENT_RELEASE_TAG_NAME: ${{ github.event.release.tag_name }} | |
| - name: Build and push Docker Image | |
| uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 | |
| id: push | |
| with: | |
| context: . | |
| push: true | |
| tags: gmri/neracoos-mariners-dashboard:${{ steps.tagName.outputs.tag }} | |
| no-cache: true | |
| build-args: | | |
| NEXT_PUBLIC_ERDDAP_SERVICE=https://buoybarn.neracoos.org | |
| NEXT_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN_PROD }} | |
| - name: Copy Next.JS sourcemaps | |
| run: docker run -v $PWD:/opt/mount --rm --entrypoint cp gmri/neracoos-mariners-dashboard -r /app/.next /opt/mount/next-build | |
| - name: Create Sentry Release | |
| uses: getsentry/action-release@ff07929a6537bac57790c3451cf4d364aca38528 # v3.7.0 | |
| env: | |
| SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} | |
| SENTRY_ORG: ${{ secrets.SENTRY_ORG }} | |
| SENTRY_PROJECT: ${{ secrets.SENTRY_PROJECT }} | |
| with: | |
| environment: production | |
| release: ${{ steps.tagName.outputs.tag }} | |
| sourcemaps: ./next-build | |
| inject: false | |
| release: | |
| name: Notify deploy repo of new release | |
| needs: [push_image] | |
| uses: gulfofmaine/odp-releaser/.github/workflows/notify.yml@52b11709c1fb73c142b24b62ce7a11ecb37f7da3 | |
| permissions: | |
| contents: read | |
| pull-requests: read # ODP Releaser wants to figure out who made a PR | |
| if: | | |
| github.repository == 'gulfofmaine/Neracoos-1-Buoy-App' | |
| && github.event_name == 'release' | |
| with: | |
| image_name: gmri/neracoos-mariners-dashboard | |
| tag: ${{ needs.push_image.outputs.tag }} | |
| digest: ${{ needs.push_image.outputs.image_digest }} | |
| environment: notify # optional gate | |
| # deploy_targets_path: .github/deploy_targets.yaml # optional | |
| verbosity: 3 # optional, default | |
| secrets: | |
| dispatch_app_id: ${{ secrets.GULFOFMAINE_ODP_DISPATCH_APP_ID }} | |
| dispatch_app_private_key: ${{ secrets.GULFOFMAINE_ODP_DISPATCH_PRIVATE_KEY }} | |
| push_dev_image: | |
| name: Build and push dev image to Docker Hub | |
| runs-on: ubuntu-24.04 | |
| needs: [unit_tests, playwright] | |
| timeout-minutes: 20 | |
| environment: Deploy with ArgoCD | |
| outputs: | |
| tag: ${{ steps.tagName.outputs.tag }} | |
| image_digest: ${{ steps.push.outputs.digest }} | |
| if: | | |
| github.repository == 'gulfofmaine/Neracoos-1-Buoy-App' | |
| && github.ref == 'refs/heads/main' | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: "Checkout" | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 | |
| - name: Download production image artifact | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: prod-image | |
| path: /tmp | |
| - name: Load Docker image | |
| run: | | |
| docker load --input /tmp/prodimage.tar | |
| docker image ls -a | |
| - name: "Login to Docker Hub" | |
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_PASSWORD }} | |
| - name: Get tag name | |
| id: tagName | |
| run: echo "tag=$(git rev-parse --short HEAD)" >> $GITHUB_OUTPUT | |
| - name: Build and push Docker Image | |
| uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 | |
| id: push | |
| with: | |
| context: . | |
| push: true | |
| tags: gmri/neracoos-mariners-dashboard:${{ steps.tagName.outputs.tag }} | |
| cache-from: type=local,src=/tmp/.buildx-cache | |
| build-args: | | |
| NEXT_PUBLIC_ERDDAP_SERVICE=https://buoybarn.neracoos.org | |
| NEXT_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN_DEV }} | |
| - name: Copy Next.JS sourcemaps | |
| run: docker run -v $PWD:/opt/mount --rm --entrypoint cp gmri/neracoos-mariners-dashboard -r /app/.next /opt/mount/next-build | |
| - name: Create Sentry Release | |
| uses: getsentry/action-release@ff07929a6537bac57790c3451cf4d364aca38528 # v3.7.0 | |
| env: | |
| SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} | |
| SENTRY_ORG: ${{ secrets.SENTRY_ORG }} | |
| SENTRY_PROJECT: ${{ secrets.SENTRY_PROJECT }} | |
| with: | |
| environment: dev | |
| release: ${{ steps.tagName.outputs.tag }} | |
| sourcemaps: ./next-build | |
| inject: false | |
| release_dev: | |
| name: Notify deploy repo of new dev | |
| needs: [push_dev_image] | |
| uses: gulfofmaine/odp-releaser/.github/workflows/notify.yml@fef1724a2cdd7725a519ebb059a60aca71e24e68 # main | |
| permissions: | |
| contents: read | |
| pull-requests: read # ODP Releaser wants to figure out who made a PR | |
| if: | | |
| github.repository == 'gulfofmaine/Neracoos-1-Buoy-App' | |
| && github.ref == 'refs/heads/main' | |
| with: | |
| image_name: gmri/neracoos-mariners-dashboard | |
| tag: ${{ needs.push_dev_image.outputs.tag }} | |
| digest: ${{ needs.push_dev_image.outputs.image_digest }} | |
| environment: notify # optional gate | |
| # deploy_targets_path: .github/deploy_targets.yaml # optional | |
| verbosity: 3 # optional, default | |
| secrets: | |
| dispatch_app_id: ${{ secrets.GULFOFMAINE_ODP_DISPATCH_APP_ID }} | |
| dispatch_app_private_key: ${{ secrets.GULFOFMAINE_ODP_DISPATCH_PRIVATE_KEY }} |