From 98fa5e9d3050145646f084f5acd5189cfa943bbb Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Sat, 31 Jan 2026 22:22:10 +0800 Subject: [PATCH] ci: add CI workflow and gate deployments on CI success - Add ci.yml with lint, test, and typecheck jobs - Update workers.yml to trigger on CI workflow completion - Update sync.yml to trigger on CI workflow completion - Update image.yml to trigger on CI workflow completion - Fix pages-eo.yml secret name to match README (EDGEONE_PAGES_API_TOKEN) Deployment workflows now only run after CI passes, preventing broken code from being deployed to any platform. --- .github/workflows/ci.yml | 102 +++++++++++++++++++++++++++++++++ .github/workflows/image.yml | 32 ++--------- .github/workflows/pages-eo.yml | 2 +- .github/workflows/sync.yml | 20 +++---- .github/workflows/workers.yml | 17 ++---- 5 files changed, 121 insertions(+), 52 deletions(-) create mode 100644 .github/workflows/ci.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..944709f --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,102 @@ +name: CI + +on: + push: + branches: + - main + paths-ignore: + - "**.md" + - "LICENSE" + - ".gitignore" + - ".editorconfig" + - ".vscode/**" + - "docs/**" + - ".prettierrc*" + - ".eslintrc*" + - ".github/ISSUE_TEMPLATE/**" + - ".github/PULL_REQUEST_TEMPLATE/**" + pull_request: + branches: + - main + paths-ignore: + - "**.md" + - "LICENSE" + - ".gitignore" + - ".editorconfig" + - ".vscode/**" + - "docs/**" + - ".prettierrc*" + - ".eslintrc*" + - ".github/ISSUE_TEMPLATE/**" + - ".github/PULL_REQUEST_TEMPLATE/**" + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + lint: + name: Lint + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Checkout + uses: actions/checkout@v6 + + - name: Setup Node.js + uses: actions/setup-node@v6 + with: + node-version: "20" + cache: "npm" + + - name: Install dependencies + run: npm ci + + - name: Run ESLint + run: npm run lint + + - name: Check formatting + run: npm run format:check + + test: + name: Test + runs-on: ubuntu-latest + timeout-minutes: 15 + steps: + - name: Checkout + uses: actions/checkout@v6 + + - name: Setup Node.js + uses: actions/setup-node@v6 + with: + node-version: "20" + cache: "npm" + + - name: Install dependencies + run: npm ci + + - name: Run tests + run: npm run test:run + env: + CI: true + + typecheck: + name: Type Check + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Checkout + uses: actions/checkout@v6 + + - name: Setup Node.js + uses: actions/setup-node@v6 + with: + node-version: "20" + cache: "npm" + + - name: Install dependencies + run: npm ci + + - name: Run type check + run: npm run type-check diff --git a/.github/workflows/image.yml b/.github/workflows/image.yml index 0c1293f..8e52f83 100644 --- a/.github/workflows/image.yml +++ b/.github/workflows/image.yml @@ -1,36 +1,15 @@ name: Build and Push Image on: - push: + workflow_run: + workflows: ["CI"] + types: + - completed branches: - main + push: tags: - "v*" - paths-ignore: - - "**.md" - - "LICENSE" - - ".gitignore" - - ".editorconfig" - - ".vscode/**" - - "docs/**" - - ".prettierrc*" - - ".eslintrc*" - - ".github/ISSUE_TEMPLATE/**" - - ".github/PULL_REQUEST_TEMPLATE/**" - pull_request: - branches: - - main - paths-ignore: - - "**.md" - - "LICENSE" - - ".gitignore" - - ".editorconfig" - - ".vscode/**" - - "docs/**" - - ".prettierrc*" - - ".eslintrc*" - - ".github/ISSUE_TEMPLATE/**" - - ".github/PULL_REQUEST_TEMPLATE/**" workflow_dispatch: concurrency: @@ -50,6 +29,7 @@ jobs: packages: write id-token: write attestations: write + if: ${{ github.event.workflow_run.conclusion == 'success' || github.event_name == 'workflow_dispatch' || startsWith(github.ref, 'refs/tags/v') }} steps: - name: Checkout repository diff --git a/.github/workflows/pages-eo.yml b/.github/workflows/pages-eo.yml index b618af0..8f4abb1 100644 --- a/.github/workflows/pages-eo.yml +++ b/.github/workflows/pages-eo.yml @@ -34,4 +34,4 @@ jobs: node-version: "22.11.0" - name: Deploy to EdgeOne Pages - run: npx edgeone pages deploy . -n xget6 -t ${{ secrets.EDGEONE_API_TOKEN }} + run: npx edgeone pages deploy . -n xget6 -t ${{ secrets.EDGEONE_PAGES_API_TOKEN }} diff --git a/.github/workflows/sync.yml b/.github/workflows/sync.yml index 45b7176..9ecec56 100644 --- a/.github/workflows/sync.yml +++ b/.github/workflows/sync.yml @@ -1,20 +1,12 @@ name: Sync to Pages and Functions on: - push: + workflow_run: + workflows: ["CI"] + types: + - completed branches: - main - paths-ignore: - - "**.md" - - "LICENSE" - - ".gitignore" - - ".editorconfig" - - ".vscode/**" - - "docs/**" - - ".prettierrc*" - - ".eslintrc*" - - ".github/ISSUE_TEMPLATE/**" - - ".github/PULL_REQUEST_TEMPLATE/**" workflow_dispatch: concurrency: @@ -27,6 +19,7 @@ jobs: timeout-minutes: 15 permissions: contents: write + if: ${{ github.event.workflow_run.conclusion == 'success' || github.event_name == 'workflow_dispatch' }} steps: - name: Checkout main branch @@ -44,7 +37,7 @@ jobs: run: | mkdir -p /tmp/pages-conversion cp -r adapters/pages/* /tmp/pages-conversion/ - + - name: Copy source code files run: | cp -r src /tmp/pages-conversion/ @@ -98,6 +91,7 @@ jobs: timeout-minutes: 15 permissions: contents: write + if: ${{ github.event.workflow_run.conclusion == 'success' || github.event_name == 'workflow_dispatch' }} steps: - name: Checkout main branch diff --git a/.github/workflows/workers.yml b/.github/workflows/workers.yml index 81c74e5..6e62c7d 100644 --- a/.github/workflows/workers.yml +++ b/.github/workflows/workers.yml @@ -1,20 +1,12 @@ name: Deploy to Cloudflare Workers on: - push: + workflow_run: + workflows: ["CI"] + types: + - completed branches: - main - paths-ignore: - - "**.md" - - "LICENSE" - - ".gitignore" - - ".editorconfig" - - ".vscode/**" - - "docs/**" - - ".prettierrc*" - - ".eslintrc*" - - ".github/ISSUE_TEMPLATE/**" - - ".github/PULL_REQUEST_TEMPLATE/**" workflow_dispatch: concurrency: @@ -28,6 +20,7 @@ jobs: permissions: contents: read deployments: write + if: ${{ github.event.workflow_run.conclusion == 'success' || github.event_name == 'workflow_dispatch' }} steps: - name: Checkout main branch uses: actions/checkout@v6