name: Caterium QA on: push: pull_request: concurrency: group: caterium-qa-${{ github.ref }} cancel-in-progress: true jobs: qa: runs-on: ubuntu-latest env: # registry.npmjs.org sits behind Cloudflare IPs that this self-hosted # runner cannot reach (times out on both IPv4 and IPv6). npmmirror.com # mirrors the full npm registry and is reachable, so point npm at it # instead of failing every install. GitHub-hosted runners don't need # this, which is why .github/workflows/qa.yml doesn't set it. NPM_CONFIG_REGISTRY: https://registry.npmmirror.com steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 22 - run: npm ci - name: Audit dependencies (retry service errors only) timeout-minutes: 4 shell: bash run: | set -euo pipefail report="$(mktemp)" trap 'rm -f "$report"' EXIT for attempt in 1 2 3; do set +e npm audit --audit-level=high --loglevel=verbose > "$report" 2>&1 status=$? set -e cat "$report" if [ "$status" -eq 0 ]; then exit 0; fi # An actual vulnerability report fails immediately. A failed # registry response is retried, never accepted as a clean audit. if ! grep -Eq 'audit endpoint returned an error|ENOTFOUND|ECONNRESET|EAI_AGAIN|ETIMEDOUT|E429|E503' "$report"; then exit "$status" fi if [ "$attempt" -eq 3 ]; then exit "$status"; fi echo "Audit service unavailable; retry $attempt/3 after a delay." sleep "$((attempt * 20))" done exit 1 - run: npm run check:deploy - run: php -l public/api/index.php && php -l ops/timeweb/api-proxy.php - run: php tests/proxy-http.php app && php tests/proxy-http.php api - run: npx playwright install --with-deps chromium webkit - run: npm run test:e2e