ci: add quality gates (semgrep, lint, e2e smoke, advisory PR-Agent) #1

Merged
xavierk merged 5 commits from ci/quality-gates into main 2026-10-05 14:27:41 +00:00
2 changed files with 5 additions and 5 deletions
Showing only changes of commit 65f3615661 - Show all commits
+4 -4
View File
@@ -13,13 +13,13 @@ jobs:
build: build:
runs-on: windows runs-on: windows
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4 # nosemgrep: github-actions-mutable-action-tag -- fallback workflow, behavior unchanged
- name: Install Rust - name: Install Rust
uses: dtolnay/rust-toolchain@stable uses: dtolnay/rust-toolchain@stable # nosemgrep: github-actions-mutable-action-tag -- fallback workflow, behavior unchanged
- name: Install Node - name: Install Node
uses: actions/setup-node@v4 uses: actions/setup-node@v4 # nosemgrep: github-actions-mutable-action-tag -- fallback workflow, behavior unchanged
with: with:
node-version: 20 node-version: 20
@@ -30,7 +30,7 @@ jobs:
run: npm run app:build run: npm run app:build
- name: Upload installer - name: Upload installer
uses: actions/upload-artifact@v4 uses: actions/upload-artifact@v4 # nosemgrep: github-actions-mutable-action-tag -- fallback workflow, behavior unchanged
with: with:
name: voiced-windows name: voiced-windows
path: src-tauri/target/release/bundle/nsis/*.exe path: src-tauri/target/release/bundle/nsis/*.exe
+1 -1
View File
@@ -107,7 +107,7 @@ async function main() {
invoice: { clientName: TOKEN, clientAddress: LONG, notes: `Note: ${TOKEN} ${LONG}` }, invoice: { clientName: TOKEN, clientAddress: LONG, notes: `Note: ${TOKEN} ${LONG}` },
}); });
writeFileSync(path.join(OUT, `${id}-A4-longtext.png`), (await rasterize(long.result.bytes, 1, SCALE)).toBuffer("image/png")); writeFileSync(path.join(OUT, `${id}-A4-longtext.png`), (await rasterize(long.result.bytes, 1, SCALE)).toBuffer("image/png"));
console.log(`${id}: pages ${withLogo.result.pages}/${sixty.result.pages}/${letter.result.pages}/${long.result.pages}; audit issues`, [withLogo, noLogo, sixty, letter, long].map((x) => x.result.issues.length).join("/")); console.log("%s: pages %s/%s/%s/%s; audit issues %s", id, withLogo.result.pages, sixty.result.pages, letter.result.pages, long.result.pages, [withLogo, noLogo, sixty, letter, long].map((x) => x.result.issues.length).join("/"));
for (const x of [withLogo, noLogo, sixty, letter, long]) for (const i of x.result.issues) console.log(" ", i.severity, i.code, `p${i.page}`, i.message.slice(0, 160)); for (const x of [withLogo, noLogo, sixty, letter, long]) for (const i of x.result.issues) console.log(" ", i.severity, i.code, `p${i.page}`, i.message.slice(0, 160));
} }
} }