Compare commits
No commits in common. "main" and "training-mode-notice" have entirely different histories.
main
...
training-m
@ -1,78 +0,0 @@
|
|||||||
name: Caterium QA
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
pull_request:
|
|
||||||
concurrency:
|
|
||||||
group: caterium-qa-${{ github.ref }}
|
|
||||||
cancel-in-progress: true
|
|
||||||
jobs:
|
|
||||||
qa:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
env:
|
|
||||||
# registry.npmjs.org sits behind Cloudflare IPs that this self-hosted
|
|
||||||
# runner cannot reach (times out on both IPv4 and IPv6). npmmirror.com
|
|
||||||
# mirrors the full npm registry and is reachable, so point npm at it
|
|
||||||
# instead of failing every install. GitHub-hosted runners don't need
|
|
||||||
# this, which is why .github/workflows/qa.yml doesn't set it.
|
|
||||||
NPM_CONFIG_REGISTRY: https://registry.npmmirror.com
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
- uses: actions/setup-node@v4
|
|
||||||
with:
|
|
||||||
node-version: 22
|
|
||||||
- run: npm ci
|
|
||||||
- name: Audit dependencies (retry service errors only)
|
|
||||||
# npmmirror.com (see NPM_CONFIG_REGISTRY above) doesn't implement
|
|
||||||
# npm's bulk security-advisories endpoint, so this always reports
|
|
||||||
# "audit endpoint returned an error" here even though installs
|
|
||||||
# work fine. The real audit still runs on GitHub-hosted runners
|
|
||||||
# against registry.npmjs.org (.github/workflows/qa.yml), so don't
|
|
||||||
# fail the whole Gitea pipeline over a check this runner can't
|
|
||||||
# physically perform.
|
|
||||||
continue-on-error: true
|
|
||||||
timeout-minutes: 4
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
report="$(mktemp)"
|
|
||||||
trap 'rm -f "$report"' EXIT
|
|
||||||
for attempt in 1 2 3; do
|
|
||||||
set +e
|
|
||||||
npm audit --audit-level=high --loglevel=verbose > "$report" 2>&1
|
|
||||||
status=$?
|
|
||||||
set -e
|
|
||||||
cat "$report"
|
|
||||||
if [ "$status" -eq 0 ]; then exit 0; fi
|
|
||||||
# An actual vulnerability report fails immediately. A failed
|
|
||||||
# registry response is retried, never accepted as a clean audit.
|
|
||||||
if ! grep -Eq 'audit endpoint returned an error|ENOTFOUND|ECONNRESET|EAI_AGAIN|ETIMEDOUT|E429|E503' "$report"; then
|
|
||||||
exit "$status"
|
|
||||||
fi
|
|
||||||
if [ "$attempt" -eq 3 ]; then exit "$status"; fi
|
|
||||||
echo "Audit service unavailable; retry $attempt/3 after a delay."
|
|
||||||
sleep "$((attempt * 20))"
|
|
||||||
done
|
|
||||||
exit 1
|
|
||||||
- run: npm run check:deploy
|
|
||||||
- name: Install PHP CLI
|
|
||||||
# The self-hosted act_runner image (unlike GitHub's ubuntu-latest)
|
|
||||||
# ships without PHP at all, so the lint/proxy steps below fail with
|
|
||||||
# "php: command not found" unless we install it first. php-curl is
|
|
||||||
# needed too: tests/proxy-http.php calls CURLOPT_* constants, which
|
|
||||||
# the bare php-cli package doesn't define.
|
|
||||||
run: |
|
|
||||||
apt-get update -y
|
|
||||||
apt-get install -y --no-install-recommends php-cli php-curl
|
|
||||||
- run: php -l public/api/index.php && php -l ops/timeweb/api-proxy.php
|
|
||||||
- run: php tests/proxy-http.php app && php tests/proxy-http.php api
|
|
||||||
- run: npx playwright install --with-deps chromium webkit
|
|
||||||
- name: Run e2e tests
|
|
||||||
# This VPS (2 CPU / 4GB) also runs Gitea + Postgres + Caddy. Playwright's
|
|
||||||
# default worker count (one per CPU, all projects in parallel) spins up
|
|
||||||
# chromium and webkit processes concurrently and has twice now driven the
|
|
||||||
# host into an unresponsive state (server needed a hard reboot) partway
|
|
||||||
# through this step. --workers=1 runs the same test suite serially
|
|
||||||
# instead of in parallel — slower, but it keeps peak memory/CPU to one
|
|
||||||
# browser process at a time. GitHub-hosted runners have real headroom,
|
|
||||||
# so .github/workflows/qa.yml keeps full parallelism.
|
|
||||||
run: npx playwright test --config=tests/playwright.config.mjs --workers=1
|
|
||||||
Loading…
Reference in New Issue
Block a user