# Gate every pull request into `main` on a fast, DB-free check suite so a broken # build or failing test can't reach the deployable branch. Complements # build-images.yml, which runs only AFTER merge (on push to main) to publish # images — this one runs BEFORE merge. # # Enforcement (one-time, in the Gitea UI): # Repository Settings → Branches → Branch Protection (rule for `main`) # • Enable Status Check # • Status check patterns: PR Checks / * # Note: Gitea only lists a context in its dropdown after it has reported once, # so let this workflow run on one PR first. The `PR Checks / *` glob matches # without needing the dropdown. # # Runner: reuses the existing self-hosted `ubuntu-latest` runner. These jobs need # only Node (no Docker socket), and the server tests stub their models + point the # DB pool at a dead port, so no MariaDB service is required. name: PR Checks on: pull_request: branches: [main] # A newer push to the same PR cancels the in-flight run. concurrency: group: pr-checks-${{ github.ref }} cancel-in-progress: true jobs: server-tests: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 20 cache: npm cache-dependency-path: server/package-lock.json - name: Install server deps run: npm ci --prefix server - name: Run server tests run: npm test --prefix server - name: Check the route manifest is current # The URL surface is frozen while admin.routes.js is carved up by capability # (docs/website/API_V2_PLAN.md § Phase 2). Regenerating from the live Express # stack and diffing proves a "mechanical" refactor moved no URL. A PR that # really does change one has to commit the new manifest, putting it in front # of a reviewer instead of letting it pass silently. run: npm run routes:manifest --prefix server -- --check client-build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 20 cache: npm cache-dependency-path: client/package-lock.json - name: Install client deps run: npm ci --prefix client - name: Run client tests # Pure-logic unit tests on Node's built-in runner (no browser/DOM). run: npm test --prefix client - name: Build client run: npm run build --prefix client bot-install: # No tests/build to run; a clean install still catches a broken or # out-of-sync lockfile before it ships in the bot image. runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 20 cache: npm cache-dependency-path: bot/package-lock.json - name: Install bot deps run: npm ci --prefix bot