Skip to content

chore(deps): install openframe-frontend-core from pkg.pr.new (0.0.697) #1643

chore(deps): install openframe-frontend-core from pkg.pr.new (0.0.697)

chore(deps): install openframe-frontend-core from pkg.pr.new (0.0.697) #1643

Workflow file for this run

name: Openframe Test
# =============================================================================
# WORKFLOW CONFIGURATION
# =============================================================================
on:
pull_request:
types: [opened, synchronize, reopened, ready_for_review, closed]
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
cancel-in-progress: true
env:
REGISTRY: 'ghcr.io'
ORGANISATION: ${{ github.repository_owner }}
REPOSITORY: ${{ github.event.repository.name }}
# =============================================================================
# JOBS
# =============================================================================
jobs:
scan:
name: "Scan Code"
runs-on: ubuntu-latest
permissions:
contents: read
packages: read
if: github.event_name == 'pull_request'
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha }}
persist-credentials: false
- name: Scan code
uses: ./.github/steps/trivy
with:
scan: code
lint:
name: 'Lint'
runs-on: ubuntu-latest
if: github.event.pull_request.state == 'open' && !github.event.pull_request.draft
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha }}
persist-credentials: false
- name: Set up Node
uses: actions/setup-node@v4
with:
node-version: 24
cache: npm
- name: Install dependencies
run: npm ci --no-audit --no-fund
# No codegen step on purpose: the fast pass carries no type-aware rules, so
# it reports the same findings with or without `src/__generated__` and
# `src/generated` present (verified). Skipping relay-compiler and
# generate-enums keeps this job a fraction of the image build's cost.
- name: ESLint
run: npm run lint:ci
build_image:
name: 'Test Frontend'
runs-on: ubuntu-latest
if: github.event.pull_request.state == 'open' && !github.event.pull_request.draft
permissions:
contents: read
packages: write
statuses: write
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha }}
persist-credentials: false
- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
with:
platforms: linux/amd64,linux/arm64
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Generate metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.ORGANISATION }}/${{ env.REPOSITORY }}/${{ env.REPOSITORY }}
tags: |
type=raw,value=pr-${{ github.event.pull_request.number }}
type=raw,value=pr-${{ github.event.pull_request.number }}-${{ github.event.pull_request.head.sha }}
- name: Build image pr-${{ github.event.pull_request.number }}
id: docker_build
uses: nick-fields/retry@v4
env:
META_TAGS: ${{ steps.meta.outputs.tags }}
PR_NUMBER: ${{ github.event.pull_request.number }}
PR_SHA: ${{ github.event.pull_request.head.sha }}
with:
max_attempts: 3
retry_wait_seconds: 5
timeout_minutes: 12
shell: bash
command: |
args=(--platform linux/amd64,linux/arm64
--build-arg GITHUB_ACTOR=${{ github.actor }}
--build-arg OPENFRAME_BUNDLE_VERSION="pr-${PR_NUMBER}-${PR_SHA::7}"
-f "./Dockerfile")
while IFS= read -r t; do [ -n "$t" ] && args+=(--tag "$t"); done <<< "$META_TAGS"
docker buildx build "${args[@]}" "."
- name: Scan image
uses: ./.github/steps/trivy
with:
scan: image
image-name: ${{ env.REPOSITORY }}
dockerfile: ./Dockerfile
context: .
- name: Push image pr-${{ github.event.pull_request.number }}-${{ github.event.pull_request.head.sha }} (pr-${{ github.event.pull_request.number }} tag)
id: docker_push
uses: nick-fields/retry@v4
env:
META_TAGS: ${{ steps.meta.outputs.tags }}
PR_NUMBER: ${{ github.event.pull_request.number }}
PR_SHA: ${{ github.event.pull_request.head.sha }}
with:
max_attempts: 3
retry_wait_seconds: 5
timeout_minutes: 12
shell: bash
command: |
args=(--platform linux/amd64,linux/arm64
--build-arg GITHUB_ACTOR=${{ github.actor }}
--build-arg OPENFRAME_BUNDLE_VERSION="pr-${PR_NUMBER}-${PR_SHA::7}"
-f "./Dockerfile")
while IFS= read -r t; do [ -n "$t" ] && args+=(--tag "$t"); done <<< "$META_TAGS"
docker buildx build "${args[@]}" --push --provenance=false --sbom=true "."
cleanup:
name: Cleanup
runs-on: ubuntu-latest
if: github.event.pull_request.state != 'open'
steps:
- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ github.token }}
- name: Delete pr-${{ github.event.pull_request.number }} images
uses: dataaxiom/ghcr-cleanup-action@v1
with:
packages: ${{ env.REPOSITORY }}/${{ env.REPOSITORY }}
delete-tags: pr-${{ github.event.pull_request.number }},pr-${{ github.event.pull_request.number }}-*
delete-ghost-images: true
all-checks:
name: 'All Checks'
needs: [lint, build_image]
runs-on: ubuntu-latest
if: |
always() &&
(contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') || !contains(needs.*.result, 'skipped'))
steps:
- if: ${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}
run: exit 1
- run: echo "All checks passed"