Skip to content

Adds CI/CD workflows - #1

Merged
lissy93 merged 1 commit into
mainfrom
add-ci-cd-workflows
Jul 3, 2026
Merged

Adds CI/CD workflows#1
lissy93 merged 1 commit into
mainfrom
add-ci-cd-workflows

Conversation

@lissy93

@lissy93 lissy93 commented Jul 3, 2026

Copy link
Copy Markdown

CI

Whenever a PR is opened, will run tests and other checks.
Uses a files-changed matrix, to only run the checks needed based on what changed.

  • Runs test suite (if code changed)
  • Does a source build and docker build smoke test
  • Run dependency audit (only on newly added dependencies)
  • Does secret scan on additions
  • Runs workflow audit - actionlint and zizmor security scan (only if workflows changed)

Docker

Builds and published the Docker image to GHRC (and optionally DockerHub if credentials specified). Does a multi-arch build in parallel (amd64, arm64, armv7), and attests both the build prevenance and SBOM for GHCR.

Triggered by:

  • push to main updates :latest
  • creation of git tag updates corresponding docker tag
  • weekly cron, to keep deps/supply chain updated (if trivy sec scan passes)
  • or workflow dispatch with custom options

Tag

Whenever a PR gets merged, will update the version in package.json (unless PR already did that), then create and publish a new git tag for that.

Release

Creates a new GitHub release, with changelog for a given tag, and builds and attaches the compiled app as well as SHA256 and SLSA build-prevenance attestion to the release.

This is what non-Docker self-hosters will use to run the app without needing to setup NPM and build themselves.

Publish

I've left this blank for now. I started drafting how it should go, but I'll leave it to you to complete that :)

Mirror

Delete if you don't want this, but it can be useful to not be locked-in to GitHub, and to have a backup of your repo. It just mirrors it to an alternate git forge.

@lissy93
lissy93 merged commit a8a1fec into main Jul 3, 2026
15 of 16 checks passed
lissy93 pushed a commit that referenced this pull request Jul 4, 2026
fix: allow proceeding even when offline check fails/wrong
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant