Files
noitu/.github/workflows/proto.yml
T
tiennm99 00d3dadad4 build: container health check, licence in the image, CI hardening
HEALTHCHECK via noitu-server -healthcheck; the root LICENSE ships next
to NOTICE and the CI image check requires it; .claude and .env files
stay out of the build context. CI uses go-version stable, runs
govulncheck and npm audit, checks out without persisted credentials, and
proto.yml moves off the archived buf-setup-action. dependabot.yml is
dropped; the audit steps are the dependency signal. deployment.md gains
the Coolify/Traefik recipe, the stop-grace rule, the hello deadline and
per-address room budget, and the suppressed-log counter.
2026-09-29 20:33:16 +07:00

67 lines
2.2 KiB
YAML

# Guards the WebSocket wire contract: the schema is well-formed, it has not
# broken compatibility, and the committed generated code matches it.
#
# The suites that decode the cross-language fixtures run in ci.yml, where the
# rest of the tests are. Nothing here downloads the upstream wordlist.
name: proto
on:
push:
branches: [main, dev]
pull_request:
permissions:
contents: read
jobs:
contract:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
# buf breaking compares against main, which needs real history.
fetch-depth: 0
# No version input, so the newest buf is used rather than an exact pin,
# per house rule: updates arrive on the next run, and a breaking major
# would surface here before it could surprise a contributor's own
# machine.
- uses: bufbuild/buf-action@v1
with:
setup_only: true
- uses: actions/setup-go@v5
with:
go-version: stable
cache-dependency-path: server/go.sum
- uses: actions/setup-node@v4
with:
node-version: 24
cache: npm
cache-dependency-path: web/package-lock.json
- run: npm ci
working-directory: web
- name: Lint the schema
run: buf lint
# ref=origin/main, not branch=main: a pull_request checkout is a detached
# HEAD with no local main, and branch=main fails there with a git clone
# error rather than a breaking-change report.
- name: Reject breaking changes
run: buf breaking --against '.git#ref=origin/main'
# A committed generated tree that no longer matches the schema is worse
# than no generated tree at all: it compiles, and it is wrong.
# --intent-to-add first: git diff ignores untracked files, so without it
# a plugin that starts emitting a new file passes this check while the
# committed tree is incomplete.
- name: Verify the committed generated code is in sync
run: |
buf generate
git add --intent-to-add -- server/gen web/src/lib/proto
git diff --exit-code -- server/gen web/src/lib/proto