mirror of
https://github.com/tiennm99/noitu.git
synced 2026-10-11 03:13:45 +00:00
HEALTHCHECK via noitu-server -healthcheck; the root LICENSE ships next to NOTICE and the CI image check requires it; .claude and .env files stay out of the build context. CI uses go-version stable, runs govulncheck and npm audit, checks out without persisted credentials, and proto.yml moves off the archived buf-setup-action. dependabot.yml is dropped; the audit steps are the dependency signal. deployment.md gains the Coolify/Traefik recipe, the stop-grace rule, the hello deadline and per-address room budget, and the suppressed-log counter.
67 lines
2.2 KiB
YAML
67 lines
2.2 KiB
YAML
# Guards the WebSocket wire contract: the schema is well-formed, it has not
|
|
# broken compatibility, and the committed generated code matches it.
|
|
#
|
|
# The suites that decode the cross-language fixtures run in ci.yml, where the
|
|
# rest of the tests are. Nothing here downloads the upstream wordlist.
|
|
name: proto
|
|
|
|
on:
|
|
push:
|
|
branches: [main, dev]
|
|
pull_request:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
contract:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
persist-credentials: false
|
|
# buf breaking compares against main, which needs real history.
|
|
fetch-depth: 0
|
|
|
|
# No version input, so the newest buf is used rather than an exact pin,
|
|
# per house rule: updates arrive on the next run, and a breaking major
|
|
# would surface here before it could surprise a contributor's own
|
|
# machine.
|
|
- uses: bufbuild/buf-action@v1
|
|
with:
|
|
setup_only: true
|
|
|
|
- uses: actions/setup-go@v5
|
|
with:
|
|
go-version: stable
|
|
cache-dependency-path: server/go.sum
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 24
|
|
cache: npm
|
|
cache-dependency-path: web/package-lock.json
|
|
|
|
- run: npm ci
|
|
working-directory: web
|
|
|
|
- name: Lint the schema
|
|
run: buf lint
|
|
|
|
# ref=origin/main, not branch=main: a pull_request checkout is a detached
|
|
# HEAD with no local main, and branch=main fails there with a git clone
|
|
# error rather than a breaking-change report.
|
|
- name: Reject breaking changes
|
|
run: buf breaking --against '.git#ref=origin/main'
|
|
|
|
# A committed generated tree that no longer matches the schema is worse
|
|
# than no generated tree at all: it compiles, and it is wrong.
|
|
# --intent-to-add first: git diff ignores untracked files, so without it
|
|
# a plugin that starts emitting a new file passes this check while the
|
|
# committed tree is incomplete.
|
|
- name: Verify the committed generated code is in sync
|
|
run: |
|
|
buf generate
|
|
git add --intent-to-add -- server/gen web/src/lib/proto
|
|
git diff --exit-code -- server/gen web/src/lib/proto
|