Repository navigation
Bump vite from 8.2.2 to 8.3.0 in the vite group #11151
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| workflow_dispatch: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| jobs: | |
| install: | |
| name: Install Dependencies | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version-file: '.nvmrc' | |
| - name: Lookup node_modules cache | |
| id: node-modules-cache | |
| uses: actions/cache@v6.1.0 | |
| with: | |
| path: node_modules | |
| key: node-modules-cache-${{ hashFiles('package-lock.json', '.npmrc') }} | |
| lookup-only: true | |
| save-always: true | |
| - name: Install dependencies | |
| if: steps.node-modules-cache.outputs.cache-hit != 'true' | |
| run: npm ci --no-audit --no-fund --prefer-offline | |
| audit: | |
| name: Security Audit | |
| needs: install | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version-file: '.nvmrc' | |
| - name: Restore node_modules cache | |
| id: node-modules-cache | |
| uses: actions/cache/restore@v6.1.0 | |
| with: | |
| path: node_modules | |
| key: node-modules-cache-${{ hashFiles('package-lock.json', '.npmrc') }} | |
| fail-on-cache-miss: true | |
| - name: Run npm audit | |
| run: npm audit --audit-level=critical | |
| lint: | |
| name: Lint | |
| needs: install | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version-file: '.nvmrc' | |
| - name: Restore node_modules cache | |
| id: node-modules-cache | |
| uses: actions/cache/restore@v6.1.0 | |
| with: | |
| path: node_modules | |
| key: node-modules-cache-${{ hashFiles('package-lock.json', '.npmrc') }} | |
| fail-on-cache-miss: true | |
| - name: Restore NX cache | |
| uses: actions/cache@v6.1.0 | |
| with: | |
| path: .nx/cache | |
| key: nx-lint-${{ github.sha }} | |
| restore-keys: nx-lint- | |
| - name: Lint | |
| if: steps.nx-lint-cache.outputs.cache-hit != 'true' | |
| env: | |
| NX_REJECT_UNKNOWN_LOCAL_CACHE: 0 | |
| # server-api is large enough that type-aware ESLint exceeds Node's | |
| # default heap; match the headroom already used in chromatic.yml. | |
| NODE_OPTIONS: --max-old-space-size=4096 | |
| run: | | |
| npx nx run-many --target=lint --exclude openops --quiet | |
| - name: Truncate NX cache | |
| run: ./tools/truncate-nx-cache.sh | |
| check-licenses: | |
| name: Check Licenses | |
| needs: install | |
| permissions: | |
| contents: write | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout for Dependabot PR | |
| if: ${{ startsWith(github.head_ref || '', 'dependabot/') }} | |
| uses: actions/checkout@v7.0.1 | |
| with: | |
| ref: ${{ github.head_ref }} | |
| - name: Checkout for others | |
| if: ${{ !startsWith(github.head_ref || '', 'dependabot/') }} | |
| uses: actions/checkout@v7.0.1 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version-file: '.nvmrc' | |
| - name: Restore node_modules cache | |
| id: node-modules-cache | |
| uses: actions/cache/restore@v6.1.0 | |
| with: | |
| path: node_modules | |
| key: node-modules-cache-${{ hashFiles('package-lock.json', '.npmrc') }} | |
| fail-on-cache-miss: true | |
| - name: Check licenses | |
| run: | | |
| npm run license-check | |
| if ! git diff --exit-code THIRD_PARTY_LICENSES.txt; then | |
| echo "Please update THIRD_PARTY_LICENSES.txt by running 'npm run license-check'" >> $GITHUB_STEP_SUMMARY | |
| exit 1 | |
| fi | |
| - name: Commit changes for dependabot | |
| if: failure() && startsWith(github.head_ref, 'dependabot/') | |
| uses: stefanzweifel/git-auto-commit-action@4a55954c782fc1ea30b9056cd3e7a2b40ca8887d # v7.2.0 | |
| with: | |
| commit_message: Update THIRD_PARTY_LICENSES.txt | |
| check-node-version: | |
| name: Check Node Version | |
| permissions: | |
| contents: write | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout for Dependabot PR | |
| if: ${{ startsWith(github.head_ref || '', 'dependabot/') }} | |
| uses: actions/checkout@v7.0.1 | |
| with: | |
| ref: ${{ github.head_ref }} | |
| - name: Checkout for others | |
| if: ${{ !startsWith(github.head_ref || '', 'dependabot/') }} | |
| uses: actions/checkout@v7.0.1 | |
| # Dependabot bumps the node base images but never .nvmrc, so on its own | |
| # branches we sync .nvmrc and push it back into the PR. | |
| - name: Check .nvmrc matches the Dockerfile node images | |
| run: | | |
| if ! ./tools/check-node-version.sh; then | |
| echo "Run './tools/check-node-version.sh --fix' to sync .nvmrc with the Dockerfiles." >> $GITHUB_STEP_SUMMARY | |
| exit 1 | |
| fi | |
| - name: Sync .nvmrc for dependabot | |
| if: failure() && startsWith(github.head_ref, 'dependabot/') | |
| run: ./tools/check-node-version.sh --fix | |
| - name: Commit changes for dependabot | |
| if: failure() && startsWith(github.head_ref, 'dependabot/') | |
| uses: stefanzweifel/git-auto-commit-action@4a55954c782fc1ea30b9056cd3e7a2b40ca8887d # v7.2.0 | |
| with: | |
| file_pattern: .nvmrc | |
| commit_message: Sync .nvmrc with the Dockerfile node version | |
| test: | |
| strategy: | |
| matrix: | |
| test-suits: | |
| - name: UI | |
| include: ui-*,*-ui | |
| - name: Blocks Shard 1 | |
| include: blocks-a*,blocks-c*,blocks-d*, | |
| - name: Blocks Shard 2 | |
| include: blocks-f*,blocks-g*,blocks-m*, | |
| - name: Blocks Shard 3 | |
| include: blocks-* | |
| exclude: blocks-a*,blocks-c*,blocks-d*,blocks-f*,blocks-g*,blocks-m*, | |
| - name: Server API Unit Tests | |
| key: server-api-unit | |
| target: test-unit | |
| include: server-api | |
| - name: Server API Integration Tests (Cloud) | |
| key: server-api-integration-cloud | |
| target: test-integration-cloud | |
| include: server-api | |
| - name: Server API Integration Tests (CE) | |
| key: server-api-integration-ce | |
| target: test-integration-ce | |
| include: server-api | |
| - name: Engine and Libraries | |
| key: others | |
| exclude: ui-*,*-ui,blocks-*,server-api | |
| name: Test ${{ matrix.test-suits.name }} | |
| needs: install | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version-file: '.nvmrc' | |
| - name: Restore node_modules cache | |
| id: node-modules-cache | |
| uses: actions/cache/restore@v6.1.0 | |
| with: | |
| path: node_modules | |
| key: node-modules-cache-${{ hashFiles('package-lock.json', '.npmrc') }} | |
| fail-on-cache-miss: true | |
| - name: Restore NX cache | |
| uses: actions/cache@v6.1.0 | |
| with: | |
| path: .nx/cache | |
| key: nx-test-${{ matrix.test-suits.key || matrix.test-suits.name }}-${{ github.sha }} | |
| restore-keys: nx-test-${{ matrix.test-suits.key || matrix.test-suits.name }}- | |
| save-always: true | |
| - name: Test | |
| if: steps.nx-test-cache.outputs.cache-hit != 'true' | |
| continue-on-error: false | |
| uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0 | |
| with: | |
| timeout_minutes: 10 | |
| max_attempts: 3 | |
| retry_on: error | |
| command: npx nx run-many --target ${{ matrix.test-suits.target || 'test' }} --projects "${{ matrix.test-suits.include }}" --exclude "${{ matrix.test-suits.exclude }}" --quiet -- --silent | |
| env: | |
| NX_REJECT_UNKNOWN_LOCAL_CACHE: 0 | |
| - name: Truncate NX cache | |
| run: ./tools/truncate-nx-cache.sh | |
| build: | |
| name: Build Project | |
| needs: install | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version-file: '.nvmrc' | |
| - name: Restore node_modules cache | |
| id: node-modules-cache | |
| uses: actions/cache/restore@v6.1.0 | |
| with: | |
| path: node_modules | |
| key: node-modules-cache-${{ hashFiles('package-lock.json', '.npmrc') }} | |
| fail-on-cache-miss: true | |
| - name: Restore NX cache | |
| uses: actions/cache@v6.1.0 | |
| with: | |
| path: .nx/cache | |
| key: nx-build-${{ github.sha }} | |
| restore-keys: nx-build- | |
| - name: Build project | |
| env: | |
| NX_REJECT_UNKNOWN_LOCAL_CACHE: 0 | |
| run: | | |
| npm run prepare | |
| npx nx run-many --target=build | |
| ./tools/truncate-nx-cache.sh | |
| - name: Save build cache | |
| uses: actions/cache/save@v6.1.0 | |
| with: | |
| path: dist | |
| key: dist-${{ github.sha }} | |
| build-images: | |
| strategy: | |
| matrix: | |
| target: | |
| - name: App | |
| file: Dockerfile | |
| repository: openops-app | |
| - name: Worker | |
| file: worker.Dockerfile | |
| repository: openops-worker | |
| platform: [amd64, arm64] | |
| name: Build ${{ matrix.target.name }} Image for ${{ matrix.platform }} | |
| needs: build | |
| runs-on: ${{ matrix.platform == 'amd64' && 'ubuntu-latest' || 'ubuntu-arm64' }} | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - name: Restore build cache | |
| uses: actions/cache/restore@v6.1.0 | |
| with: | |
| path: dist | |
| key: dist-${{ github.sha }} | |
| fail-on-cache-miss: true | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v4.3.0 | |
| # Dependabot-triggered runs get a read-only GITHUB_TOKEN that no permissions block can | |
| # raise, so azure/login cannot obtain an OIDC token and the push path has to be skipped for | |
| # them. Keyed on the actor rather than the dependabot/ branch prefix used elsewhere in this | |
| # file: the actor is what actually determines the token, so a branch of Dependabot's that | |
| # someone pushes themselves still publishes. | |
| - name: Azure login | |
| if: ${{ vars.ACR_NAME && github.actor != 'dependabot[bot]' }} | |
| uses: azure/login@7ddb5af1ef8758cf1353cf3b42f940aee27ba21c # v3.0.2 | |
| with: | |
| client-id: ${{ secrets.AZURE_ACR_CLIENT_ID }} | |
| tenant-id: ${{ secrets.AZURE_TENANT_ID }} | |
| subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }} | |
| - name: Login to Azure Container Registry | |
| if: ${{ vars.ACR_NAME && github.actor != 'dependabot[bot]' }} | |
| env: | |
| # The push path builds its tags and cache refs from ACR_LOGIN_SERVER while this gate | |
| # keys on ACR_NAME, so a half-configured environment would otherwise push to a | |
| # registry-less reference and fail somewhere less obvious. create-manifest needs this | |
| # job, so guarding here covers it too. | |
| ACR_LOGIN_SERVER: ${{ vars.ACR_LOGIN_SERVER }} | |
| run: | | |
| : "${ACR_LOGIN_SERVER:?must be set whenever ACR_NAME is}" | |
| az acr login --name ${{ vars.ACR_NAME }} | |
| - name: Format image tag parts | |
| env: | |
| BRANCH: ${{ github.head_ref || github.ref_name }} | |
| SHA: ${{ github.event.pull_request.head.sha || github.sha }} | |
| REGISTRY: ${{ vars.ACR_LOGIN_SERVER }} | |
| run: | | |
| echo SANITIZED_BRANCH=${BRANCH//[\/.:_]/-} >> "$GITHUB_ENV" | |
| echo REPOSITORY_URI=${REGISTRY}/${{ matrix.target.repository }} >> "$GITHUB_ENV" | |
| echo SHORT_SHA=${SHA::8} >> "$GITHUB_ENV" | |
| - name: Build image | |
| if: ${{ vars.ACR_NAME && github.actor != 'dependabot[bot]' }} | |
| uses: docker/build-push-action@v7.3.0 | |
| with: | |
| context: . | |
| file: ./${{ matrix.target.file }} | |
| build-args: VERSION=${{ env.SHORT_SHA }} | |
| platforms: linux/${{ matrix.platform }} | |
| provenance: false | |
| push: true | |
| tags: | | |
| ${{ env.REPOSITORY_URI }}:${{ env.SHORT_SHA }}-${{ matrix.platform }} | |
| ${{ env.REPOSITORY_URI }}:${{ env.SANITIZED_BRANCH }}-${{ env.SHORT_SHA }}-${{ matrix.platform }} | |
| ${{ env.REPOSITORY_URI }}:${{ env.SANITIZED_BRANCH }}-${{ matrix.platform }} | |
| cache-from: | | |
| type=registry,ref=${{ env.REPOSITORY_URI }}:${{ env.SANITIZED_BRANCH }}-${{ matrix.platform }}-cache | |
| type=registry,ref=${{ env.REPOSITORY_URI }}:main-${{ matrix.platform }}-cache | |
| cache-to: mode=max,image-manifest=true,oci-mediatypes=true,type=registry,ref=${{ env.REPOSITORY_URI }}:${{ env.SANITIZED_BRANCH }}-${{ matrix.platform }}-cache | |
| - name: Build image | |
| if: ${{ !vars.ACR_NAME || github.actor == 'dependabot[bot]' }} | |
| uses: docker/build-push-action@v7.3.0 | |
| with: | |
| context: . | |
| file: ./${{ matrix.target.file }} | |
| build-args: VERSION=${{ env.SHORT_SHA }} | |
| provenance: false | |
| platforms: linux/${{ matrix.platform }} | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max | |
| create-manifest: | |
| if: ${{ vars.ACR_NAME && github.actor != 'dependabot[bot]' }} | |
| strategy: | |
| matrix: | |
| repository: [openops-app, openops-worker] | |
| name: Create and Push Manifest for ${{ matrix.repository }} | |
| runs-on: ubuntu-latest | |
| needs: build-images | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - name: Azure login | |
| uses: azure/login@7ddb5af1ef8758cf1353cf3b42f940aee27ba21c # v3.0.2 | |
| with: | |
| client-id: ${{ secrets.AZURE_ACR_CLIENT_ID }} | |
| tenant-id: ${{ secrets.AZURE_TENANT_ID }} | |
| subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }} | |
| - name: Login to Azure Container Registry | |
| run: az acr login --name ${{ vars.ACR_NAME }} | |
| - name: Format image tag components | |
| env: | |
| BRANCH: ${{ github.head_ref || github.ref_name }} | |
| SHA: ${{ github.event.pull_request.head.sha || github.sha }} | |
| run: | | |
| echo SANITIZED_BRANCH=${BRANCH//[\/.:_]/-} >> "$GITHUB_ENV" | |
| echo BASE_REPOSITORY_URI=${{ vars.ACR_LOGIN_SERVER }}/${{ matrix.repository }} >> "$GITHUB_ENV" | |
| echo SHORT_SHA=${SHA::8} >> "$GITHUB_ENV" | |
| - name: Create and push manifests | |
| run: | | |
| # Create and push SHA manifest | |
| docker manifest create --amend $BASE_REPOSITORY_URI:$SHORT_SHA \ | |
| $BASE_REPOSITORY_URI:${SHORT_SHA}-amd64 \ | |
| $BASE_REPOSITORY_URI:${SHORT_SHA}-arm64 | |
| docker manifest push $BASE_REPOSITORY_URI:$SHORT_SHA | |
| echo "✅ Successfully pushed image $BASE_REPOSITORY_URI:$SHORT_SHA" >> $GITHUB_STEP_SUMMARY | |
| # Create and push branch-manifest | |
| docker manifest create --amend $BASE_REPOSITORY_URI:$SANITIZED_BRANCH \ | |
| $BASE_REPOSITORY_URI:${SANITIZED_BRANCH}-amd64 \ | |
| $BASE_REPOSITORY_URI:${SANITIZED_BRANCH}-arm64 | |
| docker manifest push $BASE_REPOSITORY_URI:$SANITIZED_BRANCH | |
| echo "✅ Successfully pushed image $BASE_REPOSITORY_URI:$SANITIZED_BRANCH" >> $GITHUB_STEP_SUMMARY |