From 34c511c8d0746985699808f8037b9b3e9dab8f51 Mon Sep 17 00:00:00 2001 From: Claude Date: Sun, 12 Jul 2026 10:07:16 -0500 Subject: [PATCH] ci: gate PRs into main on server tests + client build MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add .gitea/workflows/pr-checks.yml running on pull_request into main. Three parallel jobs on the existing ubuntu-latest runner: • server-tests — npm ci + node --test (164 tests, no DB needed: the suite stubs models and points the pool at a dead port) • client-build — npm ci + vite build • bot-install — npm ci only (catches a broken/stale lockfile) No ESLint exists in the repo yet, so no lint step. Complements build-images.yml, which publishes images post-merge. Enable in Branch Protection with status check pattern: PR Checks / * Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_0114TpmrNW4wNXsHq5CR72jQ --- .gitea/workflows/pr-checks.yml | 70 ++++++++++++++++++++++++++++++++++ 1 file changed, 70 insertions(+) create mode 100644 .gitea/workflows/pr-checks.yml diff --git a/.gitea/workflows/pr-checks.yml b/.gitea/workflows/pr-checks.yml new file mode 100644 index 0000000..b11ceb7 --- /dev/null +++ b/.gitea/workflows/pr-checks.yml @@ -0,0 +1,70 @@ +# Gate every pull request into `main` on a fast, DB-free check suite so a broken +# build or failing test can't reach the deployable branch. Complements +# build-images.yml, which runs only AFTER merge (on push to main) to publish +# images — this one runs BEFORE merge. +# +# Enforcement (one-time, in the Gitea UI): +# Repository Settings → Branches → Branch Protection (rule for `main`) +# • Enable Status Check +# • Status check patterns: PR Checks / * +# Note: Gitea only lists a context in its dropdown after it has reported once, +# so let this workflow run on one PR first. The `PR Checks / *` glob matches +# without needing the dropdown. +# +# Runner: reuses the existing self-hosted `ubuntu-latest` runner. These jobs need +# only Node (no Docker socket), and the server tests stub their models + point the +# DB pool at a dead port, so no MariaDB service is required. + +name: PR Checks + +on: + pull_request: + branches: [main] + +# A newer push to the same PR cancels the in-flight run. +concurrency: + group: pr-checks-${{ github.ref }} + cancel-in-progress: true + +jobs: + server-tests: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 20 + cache: npm + cache-dependency-path: server/package-lock.json + - name: Install server deps + run: npm ci --prefix server + - name: Run server tests + run: npm test --prefix server + + client-build: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 20 + cache: npm + cache-dependency-path: client/package-lock.json + - name: Install client deps + run: npm ci --prefix client + - name: Build client + run: npm run build --prefix client + + bot-install: + # No tests/build to run; a clean install still catches a broken or + # out-of-sync lockfile before it ships in the bot image. + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 20 + cache: npm + cache-dependency-path: bot/package-lock.json + - name: Install bot deps + run: npm ci --prefix bot