Repository navigation
chore(main): release 0.4.2 #293
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| # Also run on pushes to main so the default branch always has a green (or red) | |
| # signal, independent of the release-triggered container build. | |
| push: | |
| branches: [main] | |
| concurrency: | |
| group: '${{ github.workflow }}-${{ github.ref }}' | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| test: | |
| name: Quality | |
| runs-on: ubuntu-latest | |
| env: | |
| # pnpm's minimumReleaseAge re-validates every lockfile entry's publish | |
| # date even for frozen installs. That cooldown is a resolution-time guard | |
| # for adopting new versions; CI merely reproduces an already-gated, | |
| # PR-reviewed lockfile, so it should not be re-gated here. | |
| PNPM_CONFIG_MINIMUM_RELEASE_AGE: 0 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Node | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 24 | |
| # pnpm is pinned via the packageManager field, so corepack resolves the | |
| # exact version the lockfile was written with. | |
| - name: Enable corepack | |
| run: corepack enable | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Formatting | |
| run: pnpm run format:check | |
| - name: Lint | |
| run: pnpm run lint | |
| - name: Typecheck | |
| run: pnpm run typecheck | |
| # Catches an architecture model that no longer parses or that references an | |
| # element which has been renamed or removed. | |
| - name: Architecture diagrams | |
| run: pnpm run diagrams:check | |
| - name: Unit tests | |
| run: pnpm test | |
| - name: End-to-end tests | |
| run: pnpm test:e2e | |
| docker_build: | |
| name: Docker Build | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 | |
| # Build the image exactly as the release workflow does, but for a single | |
| # native platform and without pushing. This exercises the frozen pnpm | |
| # installs and `nest build`, catching dependency, lockfile-cooldown and | |
| # compiler-compatibility breakage before it reaches a published release. | |
| - name: Build image | |
| uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 | |
| with: | |
| context: . | |
| push: false | |
| platforms: linux/amd64 | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max |