3d418a9482
Adds zizmor alongside the actionlint job from #3503. Both now run as parallel jobs in a single `.github/workflows/workflow-checks.yml`, triggered on `.github/workflows/**` and `.github/actions/**` changes. Zizmor is configured with `unpinned-uses: hash-pin` policy via `.github/zizmor.yml`, so any future unpinned action will fail CI. Findings upload SARIF to the Security tab alongside CodeQL. Bulk of the diff is cleanup of the findings zizmor surfaced on first run. `zizmor --fix=all` handled most of them mechanically; the rest were judgment calls.
61 lines
1.6 KiB
YAML
61 lines
1.6 KiB
YAML
name: "E2E"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
package:
|
|
description: The identifier of the job to run
|
|
default: webapp
|
|
required: false
|
|
type: string
|
|
|
|
jobs:
|
|
cli-v3:
|
|
name: "🧪 CLI v3 tests (${{ matrix.os }} - ${{ matrix.package-manager }})"
|
|
if: inputs.package == 'cli-v3' || inputs.package == ''
|
|
runs-on: ${{ matrix.os }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
os: [ubuntu-latest, windows-latest]
|
|
package-manager: ["npm", "pnpm"]
|
|
steps:
|
|
- name: ⬇️ Checkout repo
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
fetch-depth: 0
|
|
persist-credentials: false
|
|
|
|
- name: ⎔ Setup pnpm
|
|
uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5.0.0
|
|
with:
|
|
version: 10.33.2
|
|
|
|
- name: ⎔ Setup node
|
|
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
|
with:
|
|
node-version: 20.20.0
|
|
|
|
- name: 📥 Download deps
|
|
run: pnpm install --frozen-lockfile --filter trigger.dev...
|
|
|
|
- name: 📀 Generate Prisma Client
|
|
run: pnpm run generate
|
|
|
|
- name: 🔧 Build v3 cli monorepo dependencies
|
|
run: pnpm run build --filter trigger.dev^...
|
|
|
|
- name: 🔧 Build worker template files
|
|
run: pnpm --filter trigger.dev run --if-present build:workers
|
|
|
|
- name: Enable corepack
|
|
run: corepack enable
|
|
|
|
- name: Run E2E Tests
|
|
shell: bash
|
|
run: |
|
|
LOG=debug PM=${{ matrix.package-manager }} pnpm --filter trigger.dev run test:e2e
|