name: CI on: push: branches: [main] pull_request: branches: [main] concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true env: NODE_VERSION: '22' jobs: # ─── Lint & Type Check ─────────────────────────────────────────── lint-and-typecheck: name: Lint & Type Check runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - uses: pnpm/action-setup@v6 - uses: actions/setup-node@v6 with: node-version: ${{ env.NODE_VERSION }} cache: pnpm - name: Check pnpm settings location run: node scripts/check-pnpm-settings.mjs - name: Install dependencies run: pnpm install --frozen-lockfile - name: Build shared (dependency for typecheck) run: pnpm --filter @veritas-kanban/shared build - name: Lint run: pnpm lint - name: Enforce lint warning budget run: pnpm lint:budget - name: Check permission coverage run: node scripts/check-permission-coverage.mjs - name: Type check all packages run: pnpm typecheck # ─── Workspace Unit Tests ──────────────────────────────────────── test-workspace: name: Workspace Unit Tests runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - uses: pnpm/action-setup@v6 - uses: actions/setup-node@v6 with: node-version: ${{ env.NODE_VERSION }} cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile - name: Build shared (dependency for workspace tests) run: pnpm --filter @veritas-kanban/shared build - name: Run workspace unit tests run: pnpm test:unit - name: Run dual-storage parity tests run: pnpm --filter @veritas-kanban/server test -- src/__tests__/storage/dual-storage-parity.test.ts # ─── Build ─────────────────────────────────────────────────────── build: name: Build runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - uses: pnpm/action-setup@v6 - uses: actions/setup-node@v6 with: node-version: ${{ env.NODE_VERSION }} cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile - name: Build shared (dependency for all builds) run: pnpm --filter @veritas-kanban/shared build - name: Build all packages run: pnpm build - name: Verify web build output run: | if [ ! -d "web/dist" ]; then echo "::error::Web build output (web/dist) not found" exit 1 fi echo "✅ Web build output exists" ls -la web/dist/ - name: Verify server build output run: | if [ ! -d "server/dist" ]; then echo "::error::Server build output (server/dist) not found" exit 1 fi echo "✅ Server build output exists" ls -la server/dist/ - name: Verify CLI and MCP build output run: | for file in cli/dist/index.js mcp/dist/index.js; do if [ ! -f "$file" ]; then echo "::error::$file not found" exit 1 fi done echo "✅ CLI and MCP build outputs exist" # ─── Security Audit ────────────────────────────────────────────── security-audit: name: Security Audit runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 - uses: pnpm/action-setup@v6 - uses: actions/setup-node@v6 with: node-version: ${{ env.NODE_VERSION }} cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile - name: Audit production dependencies (blocks on high/critical) run: pnpm audit --prod --audit-level=high - name: Audit all dependencies (informational) run: pnpm audit continue-on-error: true