Files
Voiced/CI.md

51 lines
2.4 KiB
Markdown

# CI
Workflow: `.gitea/workflows/ci.yml`, runner label `bongbetic-ci`. It runs on pull requests, pushes to `main` and manual dispatch. A weekly schedule (Monday 03:00 UTC) runs the `security` job only.
## Jobs
| Job | What it runs | Blocks merge? |
| --- | --- | --- |
| `security` | Semgrep (`p/default`, `p/owasp-top-ten`), fails on any finding | Yes |
| `lint` | `npm ci`, `tsc --noEmit`, ESLint, `cargo fmt --check` (src-tauri), jscpd (threshold 4.5%) | Yes |
| `e2e` | `npm run build`, then the Playwright smoke test (chromium) against `vite preview` | Yes |
| `ai-review` | PR-Agent review comment, pull requests only | No (advisory, `continue-on-error`) |
There is no deploy job: Voiced ships release assets, not a hosted app.
Semgrep registry rules are fetched at run time, so a new rule can fail a previously green `main`. The weekly schedule surfaces that early. Triage with a fix or a narrow `// nosemgrep: <rule-id> -- reason`.
Rust clippy is deferred. It needs the webkit2gtk/gtk system libraries and a full compile of the Tauri crate, which is too heavy for the shared CI host (jobs are limited to 3 GB RAM / 2 CPU). Only `cargo fmt --check` runs, with a pinned minimal rustup toolchain (rustfmt only).
## Run locally
```sh
# Semgrep (same image and rules as CI)
podman run --rm -v "$PWD:/src:ro,Z" -w /src docker.io/semgrep/semgrep:1.178.0 \
semgrep scan --config p/default --config p/owasp-top-ten --metrics off --error
npm run lint # ESLint
npx tsc --noEmit # typecheck
(cd src-tauri && cargo fmt --check)
npx jscpd@4.3.0 # duplicate code, reads .jscpd.json
npx playwright install chromium # once
npm run build && npm run e2e
```
Keep the `mcr.microsoft.com/playwright` image tag in the `e2e` job in step with the `@playwright/test` version in `package.json`.
## PR-Agent (advisory)
`ai-review` posts a review through PR-Agent using OpenRouter. It never pushes code and is skipped (with a notice) when the secrets are empty.
Repository secrets and variables:
- `OPENROUTER_API_KEY` (secret): OpenRouter API key.
- `PR_AGENT_GITEA_TOKEN` (secret): Gitea personal access token of the account that posts the review.
- `PR_AGENT_MODEL` (variable, optional): defaults to `openrouter/anthropic/claude-sonnet-5`.
## Rollback
Revert the workflow PR. If branch protection requires these checks (`security`, `lint`, `e2e`), relax it first, otherwise PRs will wait forever for checks that no longer run.