Skip to content

Bump node from 26.6.0-slim to 26.7.0-slim #9890

Bump node from 26.6.0-slim to 26.7.0-slim

Bump node from 26.6.0-slim to 26.7.0-slim #9890

Workflow file for this run

name: "Push"
on:
push:
branches:
- main
pull_request:
release:
types:
- published
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.ref }}
cancel-in-progress: true
permissions: {}
jobs:
build:
name: Build and cache Docker image
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: read
steps:
- name: "Checkout"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
- name: "Login to Docker Hub"
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
continue-on-error: true
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Build Docker Image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
target: dev
push: false
tags: gmri/neracoos-mariners-dashboard:latest
cache-from: type=gha
cache-to: type=gha,mode=max
outputs: type=docker,dest=/tmp/myimage.tar
- name: Upload dev image artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: dev-image
path: /tmp/myimage.tar
retention-days: 1
build-prod:
name: Build production Docker image
runs-on: ubuntu-24.04
needs: build
timeout-minutes: 10
permissions:
contents: read
steps:
- name: "Checkout"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
- name: Download dev image artifact
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: dev-image
path: /tmp
- name: Load Docker image
run: |
docker load --input /tmp/myimage.tar
docker image ls -a
- name: Build Docker Image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
target: runner
push: false
tags: gmri/neracoos-mariners-dashboard:latest
cache-from: type=gha
cache-to: type=gha,mode=max
outputs: type=docker,dest=/tmp/prodimage.tar
- name: Upload production image artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: prod-image
path: /tmp/prodimage.tar
retention-days: 1
unit_tests:
name: Unit tests, typecheck and coverage
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: read
steps:
- name: "Checkout"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: mise action
uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
- name: Cache node modules
id: cache-npm
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
env:
cache-name: cache-node-modules
with:
# npm cache files are stored in `~/.npm` on Linux/macOS
path: ~/.npm
key: ${{ runner.os }}-build-${{ env.cache-name }}-${{ hashFiles('**/package-lock.json') }}
restore-keys: |
${{ runner.os }}-build-${{ env.cache-name }}-
${{ runner.os }}-build-
${{ runner.os }}-
- name: Install dependencies
run: npm install --frozen-lockfile
- name: Install Playwright
run: npx playwright install chromium
- name: Run unit and Storybook tests and coverage
env:
CODACY_PROJECT_TOKEN: ${{ secrets.CODACY_PROJECT_TOKEN }}
if: env.CODACY_PROJECT_TOKEN != null
run: npm run test:coverage
- name: Codacy Coverage Reporter
if: env.CODACY_PROJECT_TOKEN != null
uses: codacy/codacy-coverage-reporter-action@89d6c85cfafaec52c72b6c5e8b2878d33104c699 # v1.3.0
with:
project-token: ${{ secrets.CODACY_PROJECT_TOKEN }}
coverage-reports: ./coverage/lcov.info
- name: Run unit and Storybook test (and skip coverage if no project token secret)
env:
CODACY_PROJECT_TOKEN: ${{ secrets.CODACY_PROJECT_TOKEN }}
if: env.CODACY_PROJECT_TOKEN == null
run: npm run test-ci
- name: npm run Build
run: npm run build
- name: Build Storybook Pages
run: npm run build-storybook
# - name: Cache Storybook Build
# uses: actions/cache@v6.1.0
# with:
# path: /tmp/storybook-public/
# key: mariners-dashboard-storybook-${{ github.sha }}
# - name: Copy Storybook Build to cache directory
# run: |
# rm -rf /tmp/storybook-public
# cp -r storybook-public /tmp/storybook-public
playwright:
name: Playwright integration tests
runs-on: ubuntu-24.04
needs: build-prod
timeout-minutes: 30
permissions:
contents: read
env:
# Playwright uses this env var for the browser install path. See:
# https://playwright.dev/docs/ci#directories-to-cache
# It makes most sense to default this to something cross-platform
PLAYWRIGHT_BROWSERS_PATH: ${{ github.workspace }}/ms-playwright
steps:
- name: "Checkout"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22"
cache: npm
- name: Download production image artifact
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: prod-image
path: /tmp
- name: Load Docker image
run: |
docker load --input /tmp/prodimage.tar
docker image ls -a
- name: Start container
run: docker compose up -d client
- run: npm install --frozen-lockfile
# Use Playwright version as part of the cache key
# AFAIK this is a x-platform way to get your installed Playwright version.
# Be sure to be diligent in specifying ^, ~, or locked versions.
- run: |
echo "PLAYWRIGHT_VERSION=$(node -e "process.stdout.write(require('@playwright/test/package.json').version)")" >> $GITHUB_OUTPUT
id: playwright-version
# Cache action
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
id: playwright-cache
with:
key: ${{ runner.os }}-playwright-${{ steps.playwright-version.outputs.PLAYWRIGHT_VERSION }}
path: ${{ env.PLAYWRIGHT_BROWSERS_PATH }}
# This command should work and only be ran on cold cache
- run: npx playwright install
if: steps.playwright-cache.outputs.cache-hit != 'true'
- name: Wait for container to become available
run: npx wait-on http://localhost:3000
timeout-minutes: 1
- name: Run Playwright tests
run: npm run test:e2e
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: playwright-report
path: playwright-report/
retention-days: 30
# pages:
# name: Deploy Storybook to Github Pages on version tag
# runs-on: ubuntu-24.04
# needs: [unit_tests, playwright]
# timeout-minutes: 10
# if: |
# github.repository == 'gulfofmaine/Neracoos-1-Buoy-App'
# && contains(github.ref, 'refs/tags/v')
# steps:
# - name: "Checkout"
# uses: actions/checkout@v7.0.0
# - name: Cache Storybook Build
# uses: actions/cache@v6.1.0
# with:
# path: /tmp/storybook-public/
# key: mariners-dashboard-storybook-${{ github.sha }}
# - name: Deploy Storybook to Github Pages 🚀
# uses: JamesIves/github-pages-deploy-action@v4.4.3
# with:
# branch: gh-pages
# folder: /tmp/storybook-public/
push_image:
name: Build and push tagged image to Docker Hub
runs-on: ubuntu-24.04
needs: [unit_tests, playwright]
timeout-minutes: 20
environment: Deploy with ArgoCD
outputs:
tag: ${{ steps.tagName.outputs.tag }}
image_digest: ${{ steps.push.outputs.digest }}
if: |
github.repository == 'gulfofmaine/Neracoos-1-Buoy-App'
&& github.event_name == 'release'
permissions:
contents: read
steps:
- name: "Checkout"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
- name: Download production image artifact
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: prod-image
path: /tmp
- name: Load Docker image
run: |
docker load --input /tmp/prodimage.tar
docker image ls -a
- name: "Login to Docker Hub"
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Get tag name
id: tagName
run: echo "tag=${GITHUB_EVENT_RELEASE_TAG_NAME}" >> $GITHUB_OUTPUT
env:
GITHUB_EVENT_RELEASE_TAG_NAME: ${{ github.event.release.tag_name }}
- name: Build and push Docker Image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
id: push
with:
context: .
push: true
tags: gmri/neracoos-mariners-dashboard:${{ steps.tagName.outputs.tag }}
no-cache: true
build-args: |
NEXT_PUBLIC_ERDDAP_SERVICE=https://buoybarn.neracoos.org
NEXT_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN_PROD }}
- name: Copy Next.JS sourcemaps
run: docker run -v $PWD:/opt/mount --rm --entrypoint cp gmri/neracoos-mariners-dashboard -r /app/.next /opt/mount/next-build
- name: Create Sentry Release
uses: getsentry/action-release@ff07929a6537bac57790c3451cf4d364aca38528 # v3.7.0
env:
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
SENTRY_ORG: ${{ secrets.SENTRY_ORG }}
SENTRY_PROJECT: ${{ secrets.SENTRY_PROJECT }}
with:
environment: production
release: ${{ steps.tagName.outputs.tag }}
sourcemaps: ./next-build
inject: false
release:
name: Notify deploy repo of new release
needs: [push_image]
uses: gulfofmaine/odp-releaser/.github/workflows/notify.yml@52b11709c1fb73c142b24b62ce7a11ecb37f7da3
permissions:
contents: read
pull-requests: read # ODP Releaser wants to figure out who made a PR
if: |
github.repository == 'gulfofmaine/Neracoos-1-Buoy-App'
&& github.event_name == 'release'
with:
image_name: gmri/neracoos-mariners-dashboard
tag: ${{ needs.push_image.outputs.tag }}
digest: ${{ needs.push_image.outputs.image_digest }}
environment: notify # optional gate
# deploy_targets_path: .github/deploy_targets.yaml # optional
verbosity: 3 # optional, default
secrets:
dispatch_app_id: ${{ secrets.GULFOFMAINE_ODP_DISPATCH_APP_ID }}
dispatch_app_private_key: ${{ secrets.GULFOFMAINE_ODP_DISPATCH_PRIVATE_KEY }}
push_dev_image:
name: Build and push dev image to Docker Hub
runs-on: ubuntu-24.04
needs: [unit_tests, playwright]
timeout-minutes: 20
environment: Deploy with ArgoCD
outputs:
tag: ${{ steps.tagName.outputs.tag }}
image_digest: ${{ steps.push.outputs.digest }}
if: |
github.repository == 'gulfofmaine/Neracoos-1-Buoy-App'
&& github.ref == 'refs/heads/main'
permissions:
contents: read
steps:
- name: "Checkout"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
- name: Download production image artifact
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: prod-image
path: /tmp
- name: Load Docker image
run: |
docker load --input /tmp/prodimage.tar
docker image ls -a
- name: "Login to Docker Hub"
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Get tag name
id: tagName
run: echo "tag=$(git rev-parse --short HEAD)" >> $GITHUB_OUTPUT
- name: Build and push Docker Image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
id: push
with:
context: .
push: true
tags: gmri/neracoos-mariners-dashboard:${{ steps.tagName.outputs.tag }}
cache-from: type=local,src=/tmp/.buildx-cache
build-args: |
NEXT_PUBLIC_ERDDAP_SERVICE=https://buoybarn.neracoos.org
NEXT_PUBLIC_SENTRY_DSN=${{ secrets.SENTRY_DSN_DEV }}
- name: Copy Next.JS sourcemaps
run: docker run -v $PWD:/opt/mount --rm --entrypoint cp gmri/neracoos-mariners-dashboard -r /app/.next /opt/mount/next-build
- name: Create Sentry Release
uses: getsentry/action-release@ff07929a6537bac57790c3451cf4d364aca38528 # v3.7.0
env:
SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }}
SENTRY_ORG: ${{ secrets.SENTRY_ORG }}
SENTRY_PROJECT: ${{ secrets.SENTRY_PROJECT }}
with:
environment: dev
release: ${{ steps.tagName.outputs.tag }}
sourcemaps: ./next-build
inject: false
release_dev:
name: Notify deploy repo of new dev
needs: [push_dev_image]
uses: gulfofmaine/odp-releaser/.github/workflows/notify.yml@fef1724a2cdd7725a519ebb059a60aca71e24e68 # main
permissions:
contents: read
pull-requests: read # ODP Releaser wants to figure out who made a PR
if: |
github.repository == 'gulfofmaine/Neracoos-1-Buoy-App'
&& github.ref == 'refs/heads/main'
with:
image_name: gmri/neracoos-mariners-dashboard
tag: ${{ needs.push_dev_image.outputs.tag }}
digest: ${{ needs.push_dev_image.outputs.image_digest }}
environment: notify # optional gate
# deploy_targets_path: .github/deploy_targets.yaml # optional
verbosity: 3 # optional, default
secrets:
dispatch_app_id: ${{ secrets.GULFOFMAINE_ODP_DISPATCH_APP_ID }}
dispatch_app_private_key: ${{ secrets.GULFOFMAINE_ODP_DISPATCH_PRIVATE_KEY }}