ci: add quality gates (semgrep, lint, e2e smoke, advisory PR-Agent) #1
@@ -0,0 +1,108 @@
|
|||||||
|
name: CI
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
schedule:
|
||||||
|
- cron: "0 3 * * 1"
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
# Static analysis. Also the only job that runs on the weekly schedule, so newly published
|
||||||
|
# Semgrep registry rules are applied to main even when nothing is pushed.
|
||||||
|
security:
|
||||||
|
runs-on: bongbetic-ci
|
||||||
|
timeout-minutes: 15
|
||||||
|
container:
|
||||||
|
image: docker.io/semgrep/semgrep:1.178.0
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
run: |
|
||||||
|
git init -q . && git remote add origin "${{ gitea.server_url }}/${{ gitea.repository }}.git" \
|
||||||
|
&& git -c http.extraheader="Authorization: token ${{ gitea.token }}" fetch -q --depth=1 origin "${{ gitea.sha }}" \
|
||||||
|
&& git checkout -q FETCH_HEAD
|
||||||
|
- name: Semgrep
|
||||||
|
run: semgrep scan --config p/default --config p/owasp-top-ten --metrics off --error
|
||||||
|
|
||||||
|
lint:
|
||||||
|
if: gitea.event_name != 'schedule'
|
||||||
|
runs-on: bongbetic-ci
|
||||||
|
timeout-minutes: 20
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
run: |
|
||||||
|
git init -q . && git remote add origin "${{ gitea.server_url }}/${{ gitea.repository }}.git" \
|
||||||
|
&& git -c http.extraheader="Authorization: token ${{ gitea.token }}" fetch -q --depth=1 origin "${{ gitea.sha }}" \
|
||||||
|
&& git checkout -q FETCH_HEAD
|
||||||
|
- name: Install dependencies
|
||||||
|
run: npm ci
|
||||||
|
- name: Typecheck
|
||||||
|
run: npx tsc --noEmit
|
||||||
|
- name: ESLint
|
||||||
|
run: npx eslint .
|
||||||
|
- name: Rust format check
|
||||||
|
# rustfmt only. clippy is deliberately not run: it needs the webkit2gtk/gtk system libraries
|
||||||
|
# and a full compile of the Tauri crate, which is too heavy for the shared CI host.
|
||||||
|
working-directory: src-tauri
|
||||||
|
run: |
|
||||||
|
base=https://static.rust-lang.org/rustup/dist/x86_64-unknown-linux-gnu
|
||||||
|
curl --proto '=https' --tlsv1.2 -sSfO "$base/rustup-init" -O "$base/rustup-init.sha256"
|
||||||
|
sha256sum -c rustup-init.sha256
|
||||||
|
chmod +x rustup-init
|
||||||
|
./rustup-init -y --no-modify-path --profile minimal --default-toolchain 1.99.0 -c rustfmt
|
||||||
|
rm -f rustup-init rustup-init.sha256
|
||||||
|
"$HOME/.cargo/bin/cargo" fmt --check
|
||||||
|
- name: Duplicate code (jscpd)
|
||||||
|
run: npx --yes jscpd@4.3.0
|
||||||
|
|
||||||
|
e2e:
|
||||||
|
if: gitea.event_name != 'schedule'
|
||||||
|
runs-on: bongbetic-ci
|
||||||
|
timeout-minutes: 25
|
||||||
|
container:
|
||||||
|
# Keep this tag in step with the @playwright/test version in package.json.
|
||||||
|
image: mcr.microsoft.com/playwright:v1.63.0-noble
|
||||||
|
env:
|
||||||
|
CI: "true"
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
run: |
|
||||||
|
git init -q . && git remote add origin "${{ gitea.server_url }}/${{ gitea.repository }}.git" \
|
||||||
|
&& git -c http.extraheader="Authorization: token ${{ gitea.token }}" fetch -q --depth=1 origin "${{ gitea.sha }}" \
|
||||||
|
&& git checkout -q FETCH_HEAD
|
||||||
|
- name: Install dependencies
|
||||||
|
run: npm ci
|
||||||
|
- name: Build
|
||||||
|
run: npm run build
|
||||||
|
- name: Playwright smoke tests
|
||||||
|
run: npx playwright test
|
||||||
|
|
||||||
|
# Advisory only: never blocks a merge.
|
||||||
|
ai-review:
|
||||||
|
if: gitea.event_name == 'pull_request'
|
||||||
|
runs-on: bongbetic-ci
|
||||||
|
timeout-minutes: 10
|
||||||
|
continue-on-error: true
|
||||||
|
container:
|
||||||
|
image: docker.io/pragent/pr-agent:0.47.0
|
||||||
|
options: --entrypoint ""
|
||||||
|
env:
|
||||||
|
config__git_provider: gitea
|
||||||
|
gitea__url: https://git.bongbetic.com
|
||||||
|
gitea__personal_access_token: ${{ secrets.PR_AGENT_GITEA_TOKEN }}
|
||||||
|
openrouter__key: ${{ secrets.OPENROUTER_API_KEY }}
|
||||||
|
config__model: ${{ vars.PR_AGENT_MODEL || 'openrouter/anthropic/claude-sonnet-5' }}
|
||||||
|
# PR-Agent needs this for OpenRouter models it has no built-in context window for.
|
||||||
|
config__custom_model_max_tokens: "200000"
|
||||||
|
steps:
|
||||||
|
- name: PR-Agent review
|
||||||
|
run: |
|
||||||
|
if [ -z "$gitea__personal_access_token" ] || [ -z "$openrouter__key" ]; then
|
||||||
|
echo "::notice::PR-Agent secrets not configured; skipping AI review."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
pr-agent --pr_url="${{ gitea.event.pull_request.html_url }}" review
|
||||||
@@ -31,3 +31,7 @@ xwin/
|
|||||||
CLAUDE.md
|
CLAUDE.md
|
||||||
handoff.md
|
handoff.md
|
||||||
.commandcode/
|
.commandcode/
|
||||||
|
|
||||||
|
# Playwright
|
||||||
|
test-results/
|
||||||
|
playwright-report/
|
||||||
|
|||||||
+21
@@ -0,0 +1,21 @@
|
|||||||
|
{
|
||||||
|
"threshold": 4.5,
|
||||||
|
"reporters": ["console"],
|
||||||
|
"absolute": false,
|
||||||
|
"gitignore": true,
|
||||||
|
"path": ["."],
|
||||||
|
"ignore": [
|
||||||
|
"**/node_modules/**",
|
||||||
|
"**/package-lock.json",
|
||||||
|
"**/Cargo.lock",
|
||||||
|
"**/dist/**",
|
||||||
|
"**/target/**",
|
||||||
|
"public/**",
|
||||||
|
"docs/**",
|
||||||
|
"src-tauri/gen/**",
|
||||||
|
"src-tauri/icons/**",
|
||||||
|
"**/*.{woff,woff2,ttf,otf,png,jpg,jpeg,gif,ico,icns,svg,pdf}",
|
||||||
|
"**/playwright-report/**",
|
||||||
|
"**/test-results/**"
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
# CI
|
||||||
|
|
||||||
|
Workflow: `.gitea/workflows/ci.yml`, runner label `bongbetic-ci`. It runs on pull requests, pushes to `main` and manual dispatch. A weekly schedule (Monday 03:00 UTC) runs the `security` job only.
|
||||||
|
|
||||||
|
## Jobs
|
||||||
|
|
||||||
|
| Job | What it runs | Blocks merge? |
|
||||||
|
| --- | --- | --- |
|
||||||
|
| `security` | Semgrep (`p/default`, `p/owasp-top-ten`), fails on any finding | Yes |
|
||||||
|
| `lint` | `npm ci`, `tsc --noEmit`, ESLint, `cargo fmt --check` (src-tauri), jscpd (threshold 4.5%) | Yes |
|
||||||
|
| `e2e` | `npm run build`, then the Playwright smoke test (chromium) against `vite preview` | Yes |
|
||||||
|
| `ai-review` | PR-Agent review comment, pull requests only | No (advisory, `continue-on-error`) |
|
||||||
|
|
||||||
|
There is no deploy job: Voiced ships release assets, not a hosted app.
|
||||||
|
|
||||||
|
Semgrep registry rules are fetched at run time, so a new rule can fail a previously green `main`. The weekly schedule surfaces that early. Triage with a fix or a narrow `// nosemgrep: <rule-id> -- reason`.
|
||||||
|
|
||||||
|
Rust clippy is deferred. It needs the webkit2gtk/gtk system libraries and a full compile of the Tauri crate, which is too heavy for the shared CI host (jobs are limited to 3 GB RAM / 2 CPU). Only `cargo fmt --check` runs, with a pinned minimal rustup toolchain (rustfmt only).
|
||||||
|
|
||||||
|
## Run locally
|
||||||
|
|
||||||
|
```sh
|
||||||
|
# Semgrep (same image and rules as CI)
|
||||||
|
podman run --rm -v "$PWD:/src:ro,Z" -w /src docker.io/semgrep/semgrep:1.178.0 \
|
||||||
|
semgrep scan --config p/default --config p/owasp-top-ten --metrics off --error
|
||||||
|
|
||||||
|
npm run lint # ESLint
|
||||||
|
npx tsc --noEmit # typecheck
|
||||||
|
(cd src-tauri && cargo fmt --check)
|
||||||
|
npx jscpd@4.3.0 # duplicate code, reads .jscpd.json
|
||||||
|
|
||||||
|
npx playwright install chromium # once
|
||||||
|
npm run build && npm run e2e
|
||||||
|
```
|
||||||
|
|
||||||
|
Keep the `mcr.microsoft.com/playwright` image tag in the `e2e` job in step with the `@playwright/test` version in `package.json`.
|
||||||
|
|
||||||
|
## PR-Agent (advisory)
|
||||||
|
|
||||||
|
`ai-review` posts a review through PR-Agent using OpenRouter. It never pushes code and is skipped (with a notice) when the secrets are empty.
|
||||||
|
|
||||||
|
Repository secrets and variables:
|
||||||
|
|
||||||
|
- `OPENROUTER_API_KEY` (secret): OpenRouter API key.
|
||||||
|
- `PR_AGENT_GITEA_TOKEN` (secret): Gitea personal access token of the account that posts the review.
|
||||||
|
- `PR_AGENT_MODEL` (variable, optional): defaults to `openrouter/anthropic/claude-sonnet-5`.
|
||||||
|
|
||||||
|
## Rollback
|
||||||
|
|
||||||
|
Revert the workflow PR. If branch protection requires these checks (`security`, `lint`, `e2e`), relax it first, otherwise PRs will wait forever for checks that no longer run.
|
||||||
@@ -0,0 +1,69 @@
|
|||||||
|
import { expect, test, type Page } from "@playwright/test";
|
||||||
|
|
||||||
|
// The app talks to its Rust backend through Tauri's `invoke`, which does not exist in a plain
|
||||||
|
// browser. These smoke tests cover the web build in both situations: without the backend (the app
|
||||||
|
// must fail gracefully) and with a minimal stubbed backend (the app shell must render).
|
||||||
|
|
||||||
|
const SETTINGS = {
|
||||||
|
vendorName: "Smoke Test Studio",
|
||||||
|
vendorAddress: "1 Test Street",
|
||||||
|
vendorEmail: "smoke@example.com",
|
||||||
|
vendorPhone: "",
|
||||||
|
vendorPan: "",
|
||||||
|
vendorGstin: "",
|
||||||
|
vendorStateCode: "",
|
||||||
|
logoPath: null,
|
||||||
|
signaturePath: null,
|
||||||
|
defaultBankId: null,
|
||||||
|
defaultTaxRate: 0,
|
||||||
|
defaultTaxType: "none",
|
||||||
|
paymentTermsDays: 15,
|
||||||
|
currency: "INR",
|
||||||
|
onboarded: true,
|
||||||
|
theme: "g10",
|
||||||
|
gstRegistration: "unregistered",
|
||||||
|
defaultHsnSac: "",
|
||||||
|
signatoryName: "",
|
||||||
|
signatoryDesignation: "",
|
||||||
|
renderPrefs: "",
|
||||||
|
logoOriginalPath: null,
|
||||||
|
logoKnockoutPath: null,
|
||||||
|
logoMeta: "",
|
||||||
|
logoIncludesName: "auto",
|
||||||
|
};
|
||||||
|
|
||||||
|
function collectPageErrors(page: Page): string[] {
|
||||||
|
const errors: string[] = [];
|
||||||
|
page.on("pageerror", (err) => errors.push(err.message));
|
||||||
|
return errors;
|
||||||
|
}
|
||||||
|
|
||||||
|
test("web build loads without a backend and fails gracefully", async ({ page }) => {
|
||||||
|
const errors = collectPageErrors(page);
|
||||||
|
await page.goto("/");
|
||||||
|
await expect(page).toHaveTitle("Voiced");
|
||||||
|
await expect(page.getByText("Could not start Voiced")).toBeVisible();
|
||||||
|
expect(errors).toEqual([]);
|
||||||
|
});
|
||||||
|
|
||||||
|
test("app shell renders with a stubbed backend", async ({ page }) => {
|
||||||
|
const errors = collectPageErrors(page);
|
||||||
|
await page.addInitScript((settings) => {
|
||||||
|
const w = window as unknown as { __TAURI_INTERNALS__: unknown };
|
||||||
|
w.__TAURI_INTERNALS__ = {
|
||||||
|
transformCallback: () => 0,
|
||||||
|
invoke: async (cmd: string) => {
|
||||||
|
if (cmd === "get_settings") return settings;
|
||||||
|
if (cmd.startsWith("list_")) return [];
|
||||||
|
return null;
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}, SETTINGS);
|
||||||
|
await page.goto("/");
|
||||||
|
const nav = page.getByRole("navigation", { name: "Voiced navigation" });
|
||||||
|
await expect(nav).toBeVisible();
|
||||||
|
for (const label of ["Clients", "Settings"]) {
|
||||||
|
await expect(nav.getByText(label, { exact: true })).toBeVisible();
|
||||||
|
}
|
||||||
|
expect(errors).toEqual([]);
|
||||||
|
});
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
import js from "@eslint/js";
|
||||||
|
import globals from "globals";
|
||||||
|
import tseslint from "typescript-eslint";
|
||||||
|
import reactHooks from "eslint-plugin-react-hooks";
|
||||||
|
|
||||||
|
export default tseslint.config(
|
||||||
|
{
|
||||||
|
ignores: ["node_modules/", "dist/", "src-tauri/", "public/", "docs/", "playwright-report/", "test-results/"],
|
||||||
|
},
|
||||||
|
js.configs.recommended,
|
||||||
|
tseslint.configs.recommended,
|
||||||
|
reactHooks.configs.flat.recommended,
|
||||||
|
{
|
||||||
|
files: ["src/**/*.{ts,tsx}"],
|
||||||
|
languageOptions: { globals: globals.browser },
|
||||||
|
},
|
||||||
|
{
|
||||||
|
files: ["scripts/**/*.{js,mjs}", "e2e/**/*.ts", "*.config.{js,ts}"],
|
||||||
|
languageOptions: { globals: globals.node },
|
||||||
|
},
|
||||||
|
);
|
||||||
Generated
+1322
-2
File diff suppressed because it is too large
Load Diff
+9
-1
@@ -23,7 +23,9 @@
|
|||||||
"decor:script-word": "node scripts/decor/script-word.mjs",
|
"decor:script-word": "node scripts/decor/script-word.mjs",
|
||||||
"decor:icons": "node scripts/decor/icons.mjs",
|
"decor:icons": "node scripts/decor/icons.mjs",
|
||||||
"thumbnails": "node scripts/thumbnails.mjs",
|
"thumbnails": "node scripts/thumbnails.mjs",
|
||||||
"templates:compare": "node scripts/templates/compare.mjs"
|
"templates:compare": "node scripts/templates/compare.mjs",
|
||||||
|
"lint": "eslint .",
|
||||||
|
"e2e": "playwright test"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@carbon/icons-react": "^11.89.0",
|
"@carbon/icons-react": "^11.89.0",
|
||||||
@@ -40,15 +42,21 @@
|
|||||||
"react-is": "^19.3.0"
|
"react-is": "^19.3.0"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
|
"@eslint/js": "10.0.1",
|
||||||
|
"@playwright/test": "1.63.0",
|
||||||
"@tauri-apps/cli": "^2.12.1",
|
"@tauri-apps/cli": "^2.12.1",
|
||||||
"@types/node": "^26.6.4",
|
"@types/node": "^26.6.4",
|
||||||
"@types/react": "^19.2.0",
|
"@types/react": "^19.2.0",
|
||||||
"@types/react-dom": "^19.2.0",
|
"@types/react-dom": "^19.2.0",
|
||||||
"@vitejs/plugin-react": "^5.2.0",
|
"@vitejs/plugin-react": "^5.2.0",
|
||||||
"clipper-lib": "^6.4.2",
|
"clipper-lib": "^6.4.2",
|
||||||
|
"eslint": "10.12.0",
|
||||||
|
"eslint-plugin-react-hooks": "7.1.1",
|
||||||
|
"globals": "17.13.0",
|
||||||
"pdfjs-dist": "6.4.299",
|
"pdfjs-dist": "6.4.299",
|
||||||
"sass": "^1.105.1",
|
"sass": "^1.105.1",
|
||||||
"typescript": "^5.9.3",
|
"typescript": "^5.9.3",
|
||||||
|
"typescript-eslint": "8.71.0",
|
||||||
"vite": "^7.3.6",
|
"vite": "^7.3.6",
|
||||||
"vitest": "^5.0.3"
|
"vitest": "^5.0.3"
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -0,0 +1,21 @@
|
|||||||
|
import { defineConfig, devices } from "@playwright/test";
|
||||||
|
|
||||||
|
const PORT = 4173;
|
||||||
|
|
||||||
|
export default defineConfig({
|
||||||
|
testDir: "./e2e",
|
||||||
|
workers: 1,
|
||||||
|
retries: process.env.CI ? 1 : 0,
|
||||||
|
reporter: "list",
|
||||||
|
use: {
|
||||||
|
baseURL: `http://localhost:${PORT}`,
|
||||||
|
},
|
||||||
|
projects: [{ name: "chromium", use: { ...devices["Desktop Chrome"] } }],
|
||||||
|
// Serves the production build (run `npm run build` first).
|
||||||
|
webServer: {
|
||||||
|
command: `npx vite preview --port ${PORT} --strictPort`,
|
||||||
|
url: `http://localhost:${PORT}`,
|
||||||
|
reuseExistingServer: !process.env.CI,
|
||||||
|
timeout: 60_000,
|
||||||
|
},
|
||||||
|
});
|
||||||
Reference in New Issue
Block a user