Skip to content

chore(main): release 0.4.2 #293

chore(main): release 0.4.2

chore(main): release 0.4.2 #293

Workflow file for this run

name: CI
on:
pull_request:
# Also run on pushes to main so the default branch always has a green (or red)
# signal, independent of the release-triggered container build.
push:
branches: [main]
concurrency:
group: '${{ github.workflow }}-${{ github.ref }}'
cancel-in-progress: true
permissions:
contents: read
jobs:
test:
name: Quality
runs-on: ubuntu-latest
env:
# pnpm's minimumReleaseAge re-validates every lockfile entry's publish
# date even for frozen installs. That cooldown is a resolution-time guard
# for adopting new versions; CI merely reproduces an already-gated,
# PR-reviewed lockfile, so it should not be re-gated here.
PNPM_CONFIG_MINIMUM_RELEASE_AGE: 0
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Node
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
# pnpm is pinned via the packageManager field, so corepack resolves the
# exact version the lockfile was written with.
- name: Enable corepack
run: corepack enable
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Formatting
run: pnpm run format:check
- name: Lint
run: pnpm run lint
- name: Typecheck
run: pnpm run typecheck
# Catches an architecture model that no longer parses or that references an
# element which has been renamed or removed.
- name: Architecture diagrams
run: pnpm run diagrams:check
- name: Unit tests
run: pnpm test
- name: End-to-end tests
run: pnpm test:e2e
docker_build:
name: Docker Build
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
# Build the image exactly as the release workflow does, but for a single
# native platform and without pushing. This exercises the frozen pnpm
# installs and `nest build`, catching dependency, lockfile-cooldown and
# compiler-compatibility breakage before it reaches a published release.
- name: Build image
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
push: false
platforms: linux/amd64
cache-from: type=gha
cache-to: type=gha,mode=max