Skip to content

fix(graphql): lowercase status/role enum + OTP test mock #4

fix(graphql): lowercase status/role enum + OTP test mock

fix(graphql): lowercase status/role enum + OTP test mock #4

Workflow file for this run

name: CI
on:
push:
branches: [main, develop]
pull_request:
defaults:
run:
working-directory: ev_backend
jobs:
test:
runs-on: ubuntu-latest
env:
# Tests and system checks run in debug mode with a throwaway secret.
DJANGO_DEBUG: "True"
DJANGO_SECRET_KEY: ci-test-secret-key-not-for-production
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
cache: pip
cache-dependency-path: ev_backend/requirements-dev.txt
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements-dev.txt
- name: Lint (ruff)
run: ruff check .
- name: Migration check (models match migrations)
run: python manage.py makemigrations --check --dry-run
- name: Django system checks
run: python manage.py check
- name: Deployment security checks
env:
DJANGO_DEBUG: "False"
DJANGO_SKIP_PROD_CHECK: "True"
DJANGO_ALLOWED_HOSTS: example.com
run: python manage.py check --deploy
- name: Tests + coverage
run: |
coverage run manage.py test
coverage report
- name: Security static analysis (bandit)
run: bandit -r accounts bookings stations ev_backend -x tests --severity-level medium || true
- name: Dependency vulnerability audit (pip-audit)
run: pip-audit -r requirements.txt || true
build:
runs-on: ubuntu-latest
needs: test
steps:
- uses: actions/checkout@v4
- name: Build production image
# The workflow default working-directory is already `ev_backend`, so the
# build context is `.` (using `ev_backend` here resolved to
# ev_backend/ev_backend, which has no Dockerfile).
run: docker build -t ev-backend:ci .