Compare commits
3 Commits
fix/ci-lgt
...
9cf7ea1f15
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9cf7ea1f15 | ||
|
|
3dd044029e | ||
|
|
cb86bf55b3 |
150
.github/workflows/admin-web-docker.yml
vendored
Normal file
150
.github/workflows/admin-web-docker.yml
vendored
Normal file
@@ -0,0 +1,150 @@
|
||||
name: Admin Web Docker
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
paths:
|
||||
- 'admin-web/**'
|
||||
- '.github/workflows/admin-web-docker.yml'
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: admin-web-docker-${{ github.ref }}
|
||||
cancel-in-progress: false
|
||||
|
||||
env:
|
||||
NODE_VERSION: "22"
|
||||
|
||||
jobs:
|
||||
build-validation:
|
||||
name: Docker Build Validation
|
||||
if: github.event_name == 'pull_request'
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
|
||||
|
||||
- name: Install Docker CLI
|
||||
run: apt-get update -qq && apt-get install -y -qq docker.io
|
||||
|
||||
- name: Build admin-web image (no push)
|
||||
env:
|
||||
NEXT_PUBLIC_SUPABASE_URL: ${{ vars.NEXT_PUBLIC_SUPABASE_URL }}
|
||||
NEXT_PUBLIC_SUPABASE_ANON_KEY: ${{ vars.NEXT_PUBLIC_SUPABASE_ANON_KEY }}
|
||||
run: |
|
||||
set -e
|
||||
docker build \
|
||||
--file admin-web/Dockerfile \
|
||||
--build-arg "NEXT_PUBLIC_SUPABASE_URL=${NEXT_PUBLIC_SUPABASE_URL}" \
|
||||
--build-arg "NEXT_PUBLIC_SUPABASE_ANON_KEY=${NEXT_PUBLIC_SUPABASE_ANON_KEY}" \
|
||||
--tag "tabatago-admin-web:pr-validation" \
|
||||
admin-web
|
||||
|
||||
semantic-release:
|
||||
name: Semantic Release
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
if: |
|
||||
github.event_name != 'pull_request' &&
|
||||
(
|
||||
github.event_name == 'workflow_dispatch' ||
|
||||
(
|
||||
!contains(github.event.head_commit.message, '[skip ci]') &&
|
||||
!contains(github.event.head_commit.message, '[ci skip]')
|
||||
)
|
||||
)
|
||||
outputs:
|
||||
released: ${{ steps.release.outputs.released }}
|
||||
version: ${{ steps.release.outputs.version }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Setup Node.js
|
||||
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
|
||||
with:
|
||||
node-version: ${{ env.NODE_VERSION }}
|
||||
cache: npm
|
||||
cache-dependency-path: package-lock.json
|
||||
|
||||
- name: Install release tooling
|
||||
run: npm ci
|
||||
|
||||
- name: Record version before release
|
||||
id: before
|
||||
run: echo "version=$(node -p "require('./version.json').version")" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Run semantic-release
|
||||
env:
|
||||
GITEA_TOKEN: ${{ secrets.CI_GITEA_TOKEN }}
|
||||
GITEA_URL: https://gitea.1000co.fr
|
||||
run: npx semantic-release
|
||||
|
||||
- name: Check if released
|
||||
id: release
|
||||
run: |
|
||||
VERSION="$(node -p "require('./version.json').version")"
|
||||
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
|
||||
if [ "${{ steps.before.outputs.version }}" != "$VERSION" ]; then
|
||||
echo "released=true" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "released=false" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
|
||||
build-and-push:
|
||||
name: Build & Push Docker Image
|
||||
needs: semantic-release
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
if: |
|
||||
github.event_name == 'workflow_dispatch' ||
|
||||
(
|
||||
!contains(github.event.head_commit.message, '[skip ci]') &&
|
||||
!contains(github.event.head_commit.message, '[ci skip]') &&
|
||||
needs.semantic-release.outputs.released == 'true'
|
||||
)
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
|
||||
|
||||
- name: Install Docker CLI
|
||||
run: apt-get update -qq && apt-get install -y -qq docker.io
|
||||
|
||||
- name: Login to Gitea registry
|
||||
# Secret referenced via env (never inline in the run command) so it
|
||||
# cannot leak into logs. It is then piped to --password-stdin.
|
||||
env:
|
||||
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
|
||||
DOCKER_USER: ${{ secrets.DOCKER_LOGIN }}
|
||||
run: echo "$DOCKER_PASSWORD" | docker login gitea.1000co.fr -u "$DOCKER_USER" --password-stdin
|
||||
|
||||
- name: Build and push admin-web image
|
||||
env:
|
||||
VERSION: ${{ needs.semantic-release.outputs.version }}
|
||||
NEXT_PUBLIC_SUPABASE_URL: ${{ vars.NEXT_PUBLIC_SUPABASE_URL }}
|
||||
NEXT_PUBLIC_SUPABASE_ANON_KEY: ${{ vars.NEXT_PUBLIC_SUPABASE_ANON_KEY }}
|
||||
run: |
|
||||
set -e
|
||||
if [ -z "${VERSION}" ]; then
|
||||
echo "::error::VERSION is empty — semantic-release produced no version."
|
||||
exit 1
|
||||
fi
|
||||
docker build \
|
||||
--file admin-web/Dockerfile \
|
||||
--build-arg "NEXT_PUBLIC_SUPABASE_URL=${NEXT_PUBLIC_SUPABASE_URL}" \
|
||||
--build-arg "NEXT_PUBLIC_SUPABASE_ANON_KEY=${NEXT_PUBLIC_SUPABASE_ANON_KEY}" \
|
||||
--tag "gitea.1000co.fr/millianlmx/admin-web:${VERSION}" \
|
||||
--tag "gitea.1000co.fr/millianlmx/admin-web:latest" \
|
||||
admin-web
|
||||
docker push "gitea.1000co.fr/millianlmx/admin-web:${VERSION}"
|
||||
docker push "gitea.1000co.fr/millianlmx/admin-web:latest"
|
||||
21
.releaserc.json
Normal file
21
.releaserc.json
Normal file
@@ -0,0 +1,21 @@
|
||||
{
|
||||
"branches": ["main"],
|
||||
"plugins": [
|
||||
"@semantic-release/commit-analyzer",
|
||||
"@semantic-release/release-notes-generator",
|
||||
[
|
||||
"@semantic-release/exec",
|
||||
{
|
||||
"prepareCmd": "node scripts/prepare-release.cjs ${nextRelease.version}"
|
||||
}
|
||||
],
|
||||
[
|
||||
"@semantic-release/git",
|
||||
{
|
||||
"assets": ["version.json", "admin-web/package.json"],
|
||||
"message": "chore(release): ${nextRelease.version} [skip ci]\n\n${nextRelease.notes}"
|
||||
}
|
||||
],
|
||||
"@markwylde/semantic-release-gitea"
|
||||
]
|
||||
}
|
||||
28
admin-web/.dockerignore
Normal file
28
admin-web/.dockerignore
Normal file
@@ -0,0 +1,28 @@
|
||||
# Dépendances & caches
|
||||
node_modules
|
||||
.next
|
||||
out
|
||||
build
|
||||
|
||||
# VCS & IDE
|
||||
.git
|
||||
.gitignore
|
||||
.vscode
|
||||
|
||||
# Env locaux
|
||||
.env
|
||||
.env.*
|
||||
!.env.test.example
|
||||
|
||||
# Tests & couverture
|
||||
e2e
|
||||
test
|
||||
test-results
|
||||
playwright-report
|
||||
coverage
|
||||
*.tsbuildinfo
|
||||
|
||||
# Divers
|
||||
.DS_Store
|
||||
npm-debug.log*
|
||||
README.md
|
||||
32
admin-web/Dockerfile
Normal file
32
admin-web/Dockerfile
Normal file
@@ -0,0 +1,32 @@
|
||||
# syntax=docker/dockerfile:1
|
||||
# TODO(security): pin node:22-alpine by digest in a follow-up.
|
||||
|
||||
# ---- deps ----
|
||||
FROM node:22-alpine AS deps
|
||||
WORKDIR /app
|
||||
COPY package.json package-lock.json ./
|
||||
RUN npm ci
|
||||
|
||||
# ---- builder ----
|
||||
FROM node:22-alpine AS builder
|
||||
WORKDIR /app
|
||||
COPY --from=deps /app/node_modules ./node_modules
|
||||
COPY . .
|
||||
ARG NEXT_PUBLIC_SUPABASE_URL
|
||||
ARG NEXT_PUBLIC_SUPABASE_ANON_KEY
|
||||
ENV NEXT_PUBLIC_SUPABASE_URL=$NEXT_PUBLIC_SUPABASE_URL
|
||||
ENV NEXT_PUBLIC_SUPABASE_ANON_KEY=$NEXT_PUBLIC_SUPABASE_ANON_KEY
|
||||
RUN npm run build
|
||||
|
||||
# ---- runner ----
|
||||
FROM node:22-alpine AS runner
|
||||
WORKDIR /app
|
||||
ENV NODE_ENV=production
|
||||
COPY --from=builder --chown=node:node /app/.next/standalone ./
|
||||
COPY --from=builder --chown=node:node /app/.next/static ./.next/static
|
||||
COPY --from=builder --chown=node:node /app/public ./public
|
||||
USER node
|
||||
EXPOSE 3000
|
||||
ENV PORT=3000
|
||||
ENV HOSTNAME="0.0.0.0"
|
||||
CMD ["node", "server.js"]
|
||||
@@ -1,7 +1,7 @@
|
||||
import type { NextConfig } from "next";
|
||||
|
||||
const nextConfig: NextConfig = {
|
||||
/* config options here */
|
||||
output: "standalone",
|
||||
};
|
||||
|
||||
export default nextConfig;
|
||||
|
||||
6928
package-lock.json
generated
Normal file
6928
package-lock.json
generated
Normal file
File diff suppressed because it is too large
Load Diff
17
package.json
Normal file
17
package.json
Normal file
@@ -0,0 +1,17 @@
|
||||
{
|
||||
"name": "tabatago-release-tooling",
|
||||
"version": "1.0.0",
|
||||
"private": true,
|
||||
"description": "Tooling de release monorepo (semantic-release). NE PAS confondre avec l'app iOS ni admin-web.",
|
||||
"scripts": {
|
||||
"semantic-release": "semantic-release"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@markwylde/semantic-release-gitea": "^2.2.0",
|
||||
"@semantic-release/commit-analyzer": "^13.0.0",
|
||||
"@semantic-release/exec": "^7.0.0",
|
||||
"@semantic-release/git": "^10.0.0",
|
||||
"@semantic-release/release-notes-generator": "^14.0.0",
|
||||
"semantic-release": "^24.0.0"
|
||||
}
|
||||
}
|
||||
46
scripts/prepare-release.cjs
Normal file
46
scripts/prepare-release.cjs
Normal file
@@ -0,0 +1,46 @@
|
||||
'use strict';
|
||||
|
||||
const fs = require('node:fs');
|
||||
const path = require('node:path');
|
||||
|
||||
const SEMVER_PATTERN = /^\d+\.\d+\.\d+(?:-[\dA-Za-z.-]+)?(?:\+[\dA-Za-z.-]+)?$/;
|
||||
|
||||
const nextVersion = process.argv[2];
|
||||
|
||||
if (!nextVersion) {
|
||||
throw new Error(
|
||||
'Usage: node scripts/prepare-release.cjs <version> — version argument is required.',
|
||||
);
|
||||
}
|
||||
|
||||
if (!SEMVER_PATTERN.test(nextVersion)) {
|
||||
throw new Error(
|
||||
`Invalid semver "${nextVersion}". Expected e.g. 1.2.3 or 1.2.3-beta.1.`,
|
||||
);
|
||||
}
|
||||
|
||||
const workspaceRoot = path.resolve(__dirname, '..');
|
||||
|
||||
const versionJsonPath = path.join(workspaceRoot, 'version.json');
|
||||
const adminWebPackagePath = path.join(workspaceRoot, 'admin-web', 'package.json');
|
||||
|
||||
writeVersionJson(versionJsonPath, nextVersion);
|
||||
bumpPackageVersion(adminWebPackagePath, nextVersion);
|
||||
|
||||
console.log(`[prepare-release] Updated version to ${nextVersion}`);
|
||||
console.log('[prepare-release] - version.json');
|
||||
console.log('[prepare-release] - admin-web/package.json');
|
||||
|
||||
function writeVersionJson(filePath, version) {
|
||||
const versionJson = { version };
|
||||
fs.writeFileSync(filePath, `${JSON.stringify(versionJson, null, 2)}\n`, 'utf8');
|
||||
}
|
||||
|
||||
function bumpPackageVersion(filePath, version) {
|
||||
if (!fs.existsSync(filePath)) {
|
||||
throw new Error(`Package manifest not found: ${filePath}`);
|
||||
}
|
||||
const manifest = JSON.parse(fs.readFileSync(filePath, 'utf8'));
|
||||
manifest.version = version;
|
||||
fs.writeFileSync(filePath, `${JSON.stringify(manifest, null, 2)}\n`, 'utf8');
|
||||
}
|
||||
228
scripts/prepare-release.test.cjs
Normal file
228
scripts/prepare-release.test.cjs
Normal file
@@ -0,0 +1,228 @@
|
||||
/*
|
||||
* prepare-release.test.cjs — Test standalone (zero deps) pour scripts/prepare-release.cjs
|
||||
*
|
||||
* Contrat vérifié (issu du planner / critères d'acceptation) :
|
||||
* - `node scripts/prepare-release.cjs <semver>` met à jour `version.json` (racine)
|
||||
* ET `admin-web/package.json` (champ `version`) avec la valeur passée.
|
||||
* - Sans argument -> exit code != 0.
|
||||
* - Version non-semver -> exit code != 0.
|
||||
* - semver simple (1.2.3) ou avec prerelease (1.2.3-beta.1) -> succès.
|
||||
* - Les autres clés de `admin-web/package.json` (name, dependencies, scripts...)
|
||||
* sont préservées (pas écrasées).
|
||||
*
|
||||
* Ce test s'exécute AVANT l'implémentation (le script n'existe pas encore).
|
||||
* Dans ce cas, chaque test échoue proprement avec "[FAIL] ... script not implemented yet",
|
||||
* ce qui confirme l'état rouge attendu (TDD spec-first).
|
||||
*
|
||||
* Usage : node scripts/prepare-release.test.cjs
|
||||
* Exit : 0 si tous les tests passent, 1 sinon.
|
||||
*/
|
||||
|
||||
"use strict";
|
||||
|
||||
const assert = require("node:assert");
|
||||
const fs = require("node:fs");
|
||||
const path = require("node:path");
|
||||
const { spawnSync } = require("node:child_process");
|
||||
|
||||
const ROOT = path.resolve(__dirname, "..");
|
||||
const SCRIPT = path.join(ROOT, "scripts", "prepare-release.cjs");
|
||||
const VERSION_JSON = path.join(ROOT, "version.json");
|
||||
const ADMIN_PKG = path.join(ROOT, "admin-web", "package.json");
|
||||
|
||||
let passed = 0;
|
||||
let failed = 0;
|
||||
|
||||
function ok(name) {
|
||||
console.log(`[PASS] ${name}`);
|
||||
passed++;
|
||||
}
|
||||
function ko(name, detail) {
|
||||
console.log(`[FAIL] ${name}${detail ? " — " + detail : ""}`);
|
||||
failed++;
|
||||
}
|
||||
|
||||
/**
|
||||
* Exécute prepare-release.cjs via node et renvoie { status, stdout, stderr }.
|
||||
* Si le script n'existe pas, on simule un échec avec status null.
|
||||
*/
|
||||
function runScript(args) {
|
||||
if (!fs.existsSync(SCRIPT)) {
|
||||
return {
|
||||
status: null,
|
||||
stdout: "",
|
||||
stderr: "scripts/prepare-release.cjs not implemented yet",
|
||||
missing: true,
|
||||
};
|
||||
}
|
||||
const res = spawnSync(process.execPath, [SCRIPT, ...args], {
|
||||
cwd: ROOT,
|
||||
encoding: "utf8",
|
||||
timeout: 15000,
|
||||
});
|
||||
return {
|
||||
status: res.status,
|
||||
stdout: res.stdout ?? "",
|
||||
stderr: res.stderr ?? "",
|
||||
missing: false,
|
||||
};
|
||||
}
|
||||
|
||||
/* ------------------------------------------------------------------ *
|
||||
* Backup / restore : on ne veut PAS polluer le working tree.
|
||||
* On backup les fichiers AVANT les tests d'écriture et on restore à la fin,
|
||||
* même si une assertion throw.
|
||||
* ------------------------------------------------------------------ */
|
||||
|
||||
const backup = {};
|
||||
|
||||
function backupFile(file) {
|
||||
if (fs.existsSync(file)) {
|
||||
backup[file] = { existed: true, content: fs.readFileSync(file) };
|
||||
} else {
|
||||
backup[file] = { existed: false };
|
||||
}
|
||||
}
|
||||
|
||||
function restoreFile(file) {
|
||||
const b = backup[file];
|
||||
if (!b) return;
|
||||
if (b.existed) {
|
||||
fs.writeFileSync(file, b.content);
|
||||
} else if (fs.existsSync(file)) {
|
||||
fs.unlinkSync(file);
|
||||
}
|
||||
}
|
||||
|
||||
function readJSON(file) {
|
||||
return JSON.parse(fs.readFileSync(file, "utf8"));
|
||||
}
|
||||
|
||||
/* ------------------------------------------------------------------ *
|
||||
* TEST CASES
|
||||
* ------------------------------------------------------------------ */
|
||||
|
||||
// (a) succès semver simple
|
||||
function test_simple_semver_updates_both_files() {
|
||||
const name = "simple semver (9.9.9) updates version.json + admin-web/package.json";
|
||||
const r = runScript(["9.9.9"]);
|
||||
if (r.missing) return ko(name, "script not implemented yet");
|
||||
try {
|
||||
assert.strictEqual(r.status, 0, `expected exit 0, got ${r.status} (stderr=${r.stderr.trim()})`);
|
||||
const v = readJSON(VERSION_JSON);
|
||||
assert.strictEqual(v.version, "9.9.9", `version.json.version=${v.version}`);
|
||||
const p = readJSON(ADMIN_PKG);
|
||||
assert.strictEqual(p.version, "9.9.9", `admin-web/package.json.version=${p.version}`);
|
||||
ok(name);
|
||||
} catch (e) {
|
||||
ko(name, e.message);
|
||||
}
|
||||
}
|
||||
|
||||
// (b) succès prerelease
|
||||
function test_prerelease_semver_accepted() {
|
||||
const name = "prerelease semver (1.2.3-beta.1) accepted";
|
||||
const r = runScript(["1.2.3-beta.1"]);
|
||||
if (r.missing) return ko(name, "script not implemented yet");
|
||||
try {
|
||||
assert.strictEqual(r.status, 0, `expected exit 0, got ${r.status} (stderr=${r.stderr.trim()})`);
|
||||
const v = readJSON(VERSION_JSON);
|
||||
assert.strictEqual(v.version, "1.2.3-beta.1", `version.json.version=${v.version}`);
|
||||
const p = readJSON(ADMIN_PKG);
|
||||
assert.strictEqual(p.version, "1.2.3-beta.1", `admin-web/package.json.version=${p.version}`);
|
||||
ok(name);
|
||||
} catch (e) {
|
||||
ko(name, e.message);
|
||||
}
|
||||
}
|
||||
|
||||
// (c) échec sans arg
|
||||
function test_no_arg_fails() {
|
||||
const name = "no argument -> exit != 0";
|
||||
const r = runScript([]);
|
||||
if (r.missing) return ko(name, "script not implemented yet");
|
||||
try {
|
||||
assert.notStrictEqual(r.status, 0, `expected non-zero exit, got ${r.status}`);
|
||||
ok(name);
|
||||
} catch (e) {
|
||||
ko(name, e.message);
|
||||
}
|
||||
}
|
||||
|
||||
// (d) échec version invalide
|
||||
function test_invalid_version_fails() {
|
||||
const name = "invalid version ('not-a-version') -> exit != 0";
|
||||
const r = runScript(["not-a-version"]);
|
||||
if (r.missing) return ko(name, "script not implemented yet");
|
||||
try {
|
||||
assert.notStrictEqual(r.status, 0, `expected non-zero exit, got ${r.status}`);
|
||||
// fichiers ne doivent pas avoir été modifiés avec une version invalide
|
||||
if (fs.existsSync(VERSION_JSON)) {
|
||||
const v = readJSON(VERSION_JSON);
|
||||
assert.notStrictEqual(v.version, "not-a-version", "version.json should not contain invalid version");
|
||||
}
|
||||
ok(name);
|
||||
} catch (e) {
|
||||
ko(name, e.message);
|
||||
}
|
||||
}
|
||||
|
||||
// (e) préservation des autres clés du package.json
|
||||
function test_preserves_other_keys() {
|
||||
const name = "other keys of admin-web/package.json preserved (name, scripts, dependencies)";
|
||||
const r = runScript(["7.7.7"]);
|
||||
if (r.missing) return ko(name, "script not implemented yet");
|
||||
try {
|
||||
assert.strictEqual(r.status, 0, `expected exit 0, got ${r.status}`);
|
||||
const p = readJSON(ADMIN_PKG);
|
||||
// Le package.json actuel contient name, scripts, dependencies, devDependencies.
|
||||
// On vérifie que ces clés sont toujours là et non vides.
|
||||
assert.ok(typeof p.name === "string" && p.name.length > 0, `name missing/empty: ${p.name}`);
|
||||
assert.ok(p.scripts && typeof p.scripts === "object", "scripts object missing");
|
||||
assert.ok(Object.keys(p.scripts).length > 0, "scripts object empty");
|
||||
assert.ok(p.dependencies && typeof p.dependencies === "object", "dependencies object missing");
|
||||
assert.ok(Object.keys(p.dependencies).length > 0, "dependencies object empty");
|
||||
// La version, elle, doit avoir été bumpée
|
||||
assert.strictEqual(p.version, "7.7.7", `version should be 7.7.7, got ${p.version}`);
|
||||
ok(name);
|
||||
} catch (e) {
|
||||
ko(name, e.message);
|
||||
}
|
||||
}
|
||||
|
||||
/* ------------------------------------------------------------------ *
|
||||
* RUN
|
||||
* ------------------------------------------------------------------ */
|
||||
|
||||
function main() {
|
||||
console.log("# prepare-release.cjs — test suite (standalone, zero deps)");
|
||||
console.log(`# script: ${path.relative(ROOT, SCRIPT)}`);
|
||||
console.log(`# exists: ${fs.existsSync(SCRIPT)}`);
|
||||
console.log("");
|
||||
|
||||
// Backup AVANT les tests d'écriture
|
||||
backupFile(VERSION_JSON);
|
||||
backupFile(ADMIN_PKG);
|
||||
|
||||
let crashed = false;
|
||||
try {
|
||||
test_simple_semver_updates_both_files();
|
||||
test_prerelease_semver_accepted();
|
||||
test_no_arg_fails();
|
||||
test_invalid_version_fails();
|
||||
test_preserves_other_keys();
|
||||
} catch (e) {
|
||||
crashed = true;
|
||||
console.error("[ERROR] unexpected exception in test runner:", e);
|
||||
} finally {
|
||||
// Restore TOUJOURS
|
||||
restoreFile(VERSION_JSON);
|
||||
restoreFile(ADMIN_PKG);
|
||||
}
|
||||
|
||||
console.log("");
|
||||
console.log(`# Summary: ${passed} passed, ${failed} failed${crashed ? " (+runner crash)" : ""}`);
|
||||
process.exit(failed === 0 && !crashed ? 0 : 1);
|
||||
}
|
||||
|
||||
main();
|
||||
685
scripts/verify-admin-web-docker.sh
Executable file
685
scripts/verify-admin-web-docker.sh
Executable file
@@ -0,0 +1,685 @@
|
||||
#!/usr/bin/env bash
|
||||
# verify-admin-web-docker.sh — Validation structurelle de la feature
|
||||
# "Pipeline CI/CD Docker pour admin-web (build + push registry)".
|
||||
#
|
||||
# Encode TOUS les critères d'acceptation structurels issus du planner :
|
||||
# - existence + contenu des fichiers créés par la feature
|
||||
# - validité YAML / JSON
|
||||
# - patterns de sécurité (secrets, login password-stdin, pas de GITEA_TOKEN…)
|
||||
# - actions pinnées par SHA
|
||||
# - garde anti-[skip ci] sur chaque job
|
||||
# - contextes git (branche feat/admin-web-docker + commit feat:)
|
||||
#
|
||||
# Usage :
|
||||
# ./scripts/verify-admin-web-docker.sh # run complet
|
||||
# ./scripts/verify-admin-web-docker.sh --summary # run + total final uniquement
|
||||
#
|
||||
# Exit : 0 si 0 échec, 1 si ≥1 échec.
|
||||
# Idempotent / ré-entrant : lancé avant implé (tout rouge) ET après (tout vert).
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
cd "$ROOT"
|
||||
|
||||
SUMMARY_ONLY=0
|
||||
[[ "${1:-}" == "--summary" ]] && SUMMARY_ONLY=1
|
||||
|
||||
PASS_COUNT=0
|
||||
FAIL_COUNT=0
|
||||
declare -a FAIL_NAMES=()
|
||||
|
||||
# --- helpers -------------------------------------------------------- #
|
||||
|
||||
pass() { # name
|
||||
PASS_COUNT=$((PASS_COUNT + 1))
|
||||
if [[ "$SUMMARY_ONLY" -eq 0 ]]; then
|
||||
printf '[PASS] %s\n' "$1"
|
||||
fi
|
||||
}
|
||||
|
||||
fail() { # name [detail...]
|
||||
FAIL_COUNT=$((FAIL_COUNT + 1))
|
||||
FAIL_NAMES+=("$1 :: ${2:-}")
|
||||
if [[ "$SUMMARY_ONLY" -eq 0 ]]; then
|
||||
printf '[FAIL] %s' "$1"
|
||||
[[ $# -ge 2 ]] && printf ' — %s' "${@:2}"
|
||||
printf '\n'
|
||||
fi
|
||||
}
|
||||
|
||||
# file_contains <file> <label> <pattern> (uses grep -E)
|
||||
file_contains() {
|
||||
local file="$1" label="$2" pattern="$3"
|
||||
if [[ ! -f "$file" ]]; then
|
||||
fail "$label" "file missing: $file"
|
||||
return
|
||||
fi
|
||||
if grep -Eq "$pattern" "$file"; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "pattern not found: $pattern"
|
||||
fi
|
||||
}
|
||||
|
||||
# file_not_contains <file> <label> <pattern>
|
||||
file_not_contains() {
|
||||
local file="$1" label="$2" pattern="$3"
|
||||
if [[ ! -f "$file" ]]; then
|
||||
fail "$label" "file missing: $file"
|
||||
return
|
||||
fi
|
||||
if grep -Eq "$pattern" "$file"; then
|
||||
fail "$label" "forbidden pattern found: $pattern"
|
||||
else
|
||||
pass "$label"
|
||||
fi
|
||||
}
|
||||
|
||||
# json_valid <file> <label>
|
||||
json_valid() {
|
||||
local file="$1" label="$2"
|
||||
if [[ ! -f "$file" ]]; then
|
||||
fail "$label" "file missing: $file"
|
||||
return
|
||||
fi
|
||||
if python3 -c "import json,sys; json.load(open(sys.argv[1]))" "$file" 2>/dev/null; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "invalid JSON"
|
||||
fi
|
||||
}
|
||||
|
||||
# yaml_valid <file> <label>
|
||||
yaml_valid() {
|
||||
local file="$1" label="$2"
|
||||
if [[ ! -f "$file" ]]; then
|
||||
fail "$label" "file missing: $file"
|
||||
return
|
||||
fi
|
||||
if ! python3 -c "import yaml" 2>/dev/null; then
|
||||
fail "$label" "pyyaml not installed (cannot validate)"
|
||||
return
|
||||
fi
|
||||
if python3 -c "import yaml,sys; yaml.safe_load(open(sys.argv[1]))" "$file" 2>/dev/null; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "invalid YAML"
|
||||
fi
|
||||
}
|
||||
|
||||
# =================================================================== #
|
||||
# CHECKS
|
||||
# =================================================================== #
|
||||
|
||||
# --- version.json --------------------------------------------------- #
|
||||
check_version_json() {
|
||||
local label="version.json exists with {\"version\":\"1.0.0\"}"
|
||||
if [[ ! -f version.json ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local v
|
||||
v="$(node -p "require('./version.json').version" 2>/dev/null || true)"
|
||||
if [[ "$v" == "1.0.0" ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "version.json.version='$v' (expected 1.0.0)"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- root package.json ---------------------------------------------- #
|
||||
check_root_package_json() {
|
||||
local label="root package.json: private + semantic-release deps + script"
|
||||
if [[ ! -f package.json ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local missing=()
|
||||
node -e '
|
||||
const p = require("./package.json");
|
||||
const want = [
|
||||
["private === true", p.private === true],
|
||||
["scripts.semantic-release", typeof p.scripts?.["semantic-release"] === "string"],
|
||||
["devDependencies.semantic-release", !!(p.devDependencies?.["semantic-release"] || p.dependencies?.["semantic-release"])],
|
||||
["@semantic-release/exec", !!(p.devDependencies?.["@semantic-release/exec"] || p.dependencies?.["@semantic-release/exec"])],
|
||||
["@semantic-release/git", !!(p.devDependencies?.["@semantic-release/git"] || p.dependencies?.["@semantic-release/git"])],
|
||||
["@semantic-release/commit-analyzer", !!(p.devDependencies?.["@semantic-release/commit-analyzer"] || p.dependencies?.["@semantic-release/commit-analyzer"])],
|
||||
["@semantic-release/release-notes-generator", !!(p.devDependencies?.["@semantic-release/release-notes-generator"] || p.dependencies?.["@semantic-release/release-notes-generator"])],
|
||||
["@markwylde/semantic-release-gitea", !!(p.devDependencies?.["@markwylde/semantic-release-gitea"] || p.dependencies?.["@markwylde/semantic-release-gitea"])],
|
||||
];
|
||||
for (const [name, ok] of want) if (!ok) console.log(name);
|
||||
' > /tmp/_pkgcheck 2>/dev/null || { fail "$label" "node parse failed"; return; }
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] && missing+=("$line")
|
||||
done < /tmp/_pkgcheck
|
||||
rm -f /tmp/_pkgcheck
|
||||
if [[ ${#missing[@]} -eq 0 ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "missing: ${missing[*]}"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- root package-lock.json ----------------------------------------- #
|
||||
check_root_pkg_lock() {
|
||||
if [[ -f package-lock.json ]]; then
|
||||
pass "root package-lock.json exists"
|
||||
else
|
||||
fail "root package-lock.json exists" "file missing"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- .releaserc.json ------------------------------------------------ #
|
||||
check_releaserc() {
|
||||
local label1=".releaserc.json valid JSON"
|
||||
if [[ ! -f .releaserc.json ]]; then
|
||||
fail "$label1" "file missing"
|
||||
fail ".releaserc.json assets include version.json + admin-web/package.json" "file missing"
|
||||
fail ".releaserc.json git plugin message contains [skip ci]" "file missing"
|
||||
return
|
||||
fi
|
||||
if python3 -c "import json,sys; json.load(open(sys.argv[1]))" .releaserc.json 2>/dev/null; then
|
||||
pass "$label1"
|
||||
else
|
||||
fail "$label1" "invalid JSON"
|
||||
fi
|
||||
|
||||
# assets contain version.json + admin-web/package.json
|
||||
local label2=".releaserc.json assets include version.json + admin-web/package.json"
|
||||
if grep -Eq '"version\.json"' .releaserc.json && grep -Eq '"admin-web/package\.json"' .releaserc.json; then
|
||||
pass "$label2"
|
||||
else
|
||||
fail "$label2" "assets should reference both version.json and admin-web/package.json"
|
||||
fi
|
||||
|
||||
# git plugin message contains literal [skip ci]
|
||||
local label3=".releaserc.json git plugin message contains [skip ci]"
|
||||
if grep -Fq "[skip ci]" .releaserc.json; then
|
||||
pass "$label3"
|
||||
else
|
||||
fail "$label3" "literal [skip ci] not found"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- Dockerfile ----------------------------------------------------- #
|
||||
check_dockerfile() {
|
||||
local f="admin-web/Dockerfile"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "Dockerfile exists" "file missing: $f"
|
||||
return
|
||||
fi
|
||||
pass "Dockerfile exists"
|
||||
|
||||
# 3 stages FROM node:22-alpine
|
||||
local count
|
||||
count=$(grep -Ec '^FROM node:22-alpine' "$f" || true)
|
||||
if [[ "$count" -eq 3 ]]; then
|
||||
pass "Dockerfile has exactly 3 'FROM node:22-alpine' stages"
|
||||
else
|
||||
fail "Dockerfile has exactly 3 'FROM node:22-alpine' stages" "found $count"
|
||||
fi
|
||||
|
||||
file_contains "$f" "Dockerfile uses USER node" '^USER node\b'
|
||||
file_contains "$f" "Dockerfile EXPOSE 3000" '^EXPOSE 3000\b'
|
||||
file_contains "$f" 'Dockerfile CMD ["node","server.js"]' 'CMD \[ ?"node" ?, ?"server\.js" ?\]'
|
||||
|
||||
# build-args NEXT_PUBLIC_SUPABASE_URL + NEXT_PUBLIC_SUPABASE_ANON_KEY
|
||||
file_contains "$f" "Dockerfile ARG NEXT_PUBLIC_SUPABASE_URL" 'ARG[[:space:]]+NEXT_PUBLIC_SUPABASE_URL'
|
||||
file_contains "$f" "Dockerfile ARG NEXT_PUBLIC_SUPABASE_ANON_KEY" 'ARG[[:space:]]+NEXT_PUBLIC_SUPABASE_ANON_KEY'
|
||||
}
|
||||
|
||||
# --- next.config.ts standalone -------------------------------------- #
|
||||
check_next_config() {
|
||||
local f="admin-web/next.config.ts"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "next.config.ts contains output: \"standalone\"" "file missing"
|
||||
return
|
||||
fi
|
||||
if grep -Eq "output:[[:space:]]*[\"']standalone[\"']" "$f"; then
|
||||
pass 'next.config.ts contains output: "standalone"'
|
||||
else
|
||||
fail 'next.config.ts contains output: "standalone"' "pattern not found"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- .dockerignore -------------------------------------------------- #
|
||||
check_dockerignore() {
|
||||
local f="admin-web/.dockerignore"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail ".dockerignore exists" "file missing"
|
||||
return
|
||||
fi
|
||||
pass ".dockerignore exists"
|
||||
file_contains "$f" ".dockerignore excludes node_modules" '^node_modules$'
|
||||
file_contains "$f" ".dockerignore excludes .next" '^\.next(/.*)?$'
|
||||
file_contains "$f" ".dockerignore excludes .git" '^\.git(/.*)?$'
|
||||
file_contains "$f" ".dockerignore excludes .env" '^\.env(\..*)?$'
|
||||
file_not_contains "$f" ".dockerignore does NOT exclude package-lock.json" '^package-lock\.json$'
|
||||
}
|
||||
|
||||
# --- workflow YAML validity ----------------------------------------- #
|
||||
check_workflow_valid() {
|
||||
yaml_valid ".github/workflows/admin-web-docker.yml" "admin-web-docker.yml is valid YAML"
|
||||
}
|
||||
|
||||
# --- workflow: exactly 3 jobs --------------------------------------- #
|
||||
check_workflow_jobs() {
|
||||
local label="workflow has exactly 3 jobs: build-validation + semantic-release + build-and-push"
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local out
|
||||
if ! out=$(python3 -c "
|
||||
import yaml,sys
|
||||
d=yaml.safe_load(open(sys.argv[1]))
|
||||
jobs=list((d.get('jobs') or {}).keys())
|
||||
print(','.join(sorted(jobs)))
|
||||
" "$f" 2>/dev/null); then
|
||||
fail "$label" "could not parse jobs"
|
||||
return
|
||||
fi
|
||||
if [[ "$out" == "build-and-push,build-validation,semantic-release" ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "jobs=[$out]"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- workflow: build-and-push needs semantic-release --------------- #
|
||||
check_workflow_needs() {
|
||||
local label="build-and-push needs: semantic-release"
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local out
|
||||
out=$(python3 -c "
|
||||
import yaml,sys
|
||||
d=yaml.safe_load(open(sys.argv[1]))
|
||||
bp=d.get('jobs',{}).get('build-and-push',{})
|
||||
n=bp.get('needs')
|
||||
if isinstance(n,list): print(','.join(n))
|
||||
else: print(str(n))
|
||||
" "$f" 2>/dev/null || true)
|
||||
if [[ "$out" == "semantic-release" ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "needs='$out'"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- workflow: skip-ci guard on both jobs -------------------------- #
|
||||
check_skip_ci_guard() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "both jobs guard against [skip ci] + [ci skip]" "file missing"
|
||||
return
|
||||
fi
|
||||
# Need at least 2 occurrences of each literal pattern (one per job minimum).
|
||||
# We accept "≥2" rather than "exactly 2" to stay robust to multi-line ifs.
|
||||
local c_skip c_ciskip
|
||||
c_skip=$(grep -Fc "[skip ci]" "$f" || true)
|
||||
c_ciskip=$(grep -Fc "[ci skip]" "$f" || true)
|
||||
if [[ "$c_skip" -ge 2 && "$c_ciskip" -ge 2 ]]; then
|
||||
pass "both jobs guard against [skip ci] + [ci skip]"
|
||||
else
|
||||
fail "both jobs guard against [skip ci] + [ci skip]" "[skip ci] x$c_skip, [ci skip] x$c_ciskip (need >=2 each)"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- workflow: build-and-push if condition ------------------------- #
|
||||
check_bp_if_condition() {
|
||||
local label="build-and-push if = skip-ci guard AND (released || workflow_dispatch)"
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
# On extrait la condition `if:` du job build-and-push.
|
||||
local cond
|
||||
cond=$(python3 -c "
|
||||
import yaml,sys
|
||||
d=yaml.safe_load(open(sys.argv[1]))
|
||||
print(d.get('jobs',{}).get('build-and-push',{}).get('if','') or '')
|
||||
" "$f" 2>/dev/null || true)
|
||||
if [[ -z "$cond" ]]; then
|
||||
fail "$label" "no 'if' on build-and-push"
|
||||
return
|
||||
fi
|
||||
# La condition doit mentionner : [skip ci], [ci skip], released, workflow_dispatch
|
||||
local miss=()
|
||||
grep -Fq "[skip ci]" <<<"$cond" || miss+=("[skip ci]")
|
||||
grep -Fq "[ci skip]" <<<"$cond" || miss+=("[ci skip]")
|
||||
grep -Eq "released" <<<"$cond" || miss+=("released")
|
||||
grep -Eq "workflow_dispatch" <<<"$cond" || miss+=("workflow_dispatch")
|
||||
if [[ ${#miss[@]} -eq 0 ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "condition missing: ${miss[*]} (cond=$cond)"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- workflow: docker login uses --password-stdin + env, no inline --#
|
||||
check_docker_login() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "docker login uses --password-stdin + env (no inline secret)" "file missing"
|
||||
return
|
||||
fi
|
||||
# doit contenir --password-stdin et echo "$DOCKER_PASSWORD"
|
||||
if grep -Eq -- '--password-stdin' "$f" && grep -Fq 'echo "$DOCKER_PASSWORD"' "$f"; then
|
||||
# On n'interdit ${{ secrets.DOCKER_PASSWORD }} que DANS les blocs run:
|
||||
# (secret inline = fuite potentielle dans les logs). Une référence dans un
|
||||
# bloc env: est au contraire la bonne pratique et ne doit PAS échouer.
|
||||
# On extrait donc le contenu des run: via awk, puis on grep ce contenu.
|
||||
# Cas couverts : run: <cmd> (mono-ligne) et run: | ou run: > (multi-lignes).
|
||||
local runs
|
||||
runs=$(awk '
|
||||
/^[[:space:]]*run:[[:space:]]*[|>][-+]?[[:space:]]*$/ { in_run=1; next }
|
||||
/^[[:space:]]*run:[[:space:]].+/ { in_run=0; print; next }
|
||||
in_run && /^[[:space:]]+/ { print; next }
|
||||
in_run { in_run=0 }
|
||||
' "$f")
|
||||
# Regex tolérante au whitespace : ${{ secrets.DOCKER_PASSWORD }}, ${{secrets.DOCKER_PASSWORD}}, etc.
|
||||
if echo "$runs" | grep -Eq '\$\{\{\s*secrets\.DOCKER_PASSWORD\s*\}\}'; then
|
||||
fail "docker login uses --password-stdin + env (no inline secret)" \
|
||||
"secrets.DOCKER_PASSWORD must not be used inline in a run: block — pass via env + --password-stdin"
|
||||
else
|
||||
pass "docker login uses --password-stdin + env (no inline secret)"
|
||||
fi
|
||||
else
|
||||
fail "docker login uses --password-stdin + env (no inline secret)" "missing --password-stdin or echo \"\$DOCKER_PASSWORD\""
|
||||
fi
|
||||
}
|
||||
|
||||
# --- workflow: login uses DOCKER_LOGIN (not DOCKER_USERNAME) ------- #
|
||||
check_docker_login_secret_name() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "docker login uses secrets.DOCKER_LOGIN" "file missing"
|
||||
return
|
||||
fi
|
||||
if grep -Fq 'secrets.DOCKER_LOGIN' "$f"; then
|
||||
pass "docker login uses secrets.DOCKER_LOGIN"
|
||||
else
|
||||
fail "docker login uses secrets.DOCKER_LOGIN" "secrets.DOCKER_LOGIN not referenced"
|
||||
fi
|
||||
file_not_contains "$f" "workflow does not use secrets.DOCKER_USERNAME" 'secrets\.DOCKER_USERNAME'
|
||||
}
|
||||
|
||||
# --- workflow: push :VERSION + :latest + set -e ------------------- #
|
||||
check_push_tags() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "workflow pushes :VERSION and :latest with set -e" "file missing"
|
||||
return
|
||||
fi
|
||||
local has_version=0 has_latest=0 has_set_e=0
|
||||
grep -Eq '\$\{?VERSION\}?|:\$\{VERSION\}' "$f" && has_version=1 || true
|
||||
grep -Eq ':latest' "$f" && has_latest=1 || true
|
||||
grep -Eq 'set -e' "$f" && has_set_e=1 || true
|
||||
if [[ $has_version -eq 1 && $has_latest -eq 1 && $has_set_e -eq 1 ]]; then
|
||||
pass "workflow pushes :VERSION and :latest with set -e"
|
||||
else
|
||||
fail "workflow pushes :VERSION and :latest with set -e" "VERSION=$has_version latest=$has_latest set-e=$has_set_e"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- workflow: forbidden secrets ----------------------------------- #
|
||||
check_forbidden_secrets() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "workflow forbids secrets.(GITEA_TOKEN|GITHUB_TOKEN) (use CI_GITEA_TOKEN)" "file missing"
|
||||
fail "workflow forbids GEMINI_API_KEY + SUPABASE_SERVICE_ROLE_KEY" "file missing"
|
||||
return
|
||||
fi
|
||||
file_not_contains "$f" "workflow forbids secrets.(GITEA_TOKEN|GITHUB_TOKEN) (use CI_GITEA_TOKEN)" 'secrets\.(GITEA_TOKEN|GITHUB_TOKEN)'
|
||||
file_not_contains "$f" "workflow forbids GEMINI_API_KEY + SUPABASE_SERVICE_ROLE_KEY" '(GEMINI_API_KEY|SUPABASE_SERVICE_ROLE_KEY)'
|
||||
}
|
||||
|
||||
# --- workflow: build-args from vars.NEXT_PUBLIC_* ------------------ #
|
||||
check_buildargs_source() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "build-args fed by vars.NEXT_PUBLIC_* (not secrets.*)" "file missing"
|
||||
return
|
||||
fi
|
||||
if grep -Eq 'vars\.NEXT_PUBLIC_(SUPABASE_URL|SUPABASE_ANON_KEY)' "$f"; then
|
||||
pass "build-args fed by vars.NEXT_PUBLIC_*"
|
||||
else
|
||||
fail "build-args fed by vars.NEXT_PUBLIC_*" "no vars.NEXT_PUBLIC_* reference"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- workflow: actions pinned by SHA (no @vN) --------------------- #
|
||||
check_actions_pinned() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "actions pinned by SHA (no @vN)" "file missing"
|
||||
return
|
||||
fi
|
||||
# Pour checkout / setup-node / setup-buildx-action : aucun @v<digit>
|
||||
local bad
|
||||
bad=$(grep -E 'uses:[[:space:]]+(actions/checkout|actions/setup-node|docker/setup-buildx-action)@v[0-9]' "$f" || true)
|
||||
if [[ -z "$bad" ]]; then
|
||||
pass "actions pinned by SHA (no @vN)"
|
||||
else
|
||||
fail "actions pinned by SHA (no @vN)" "non-pinned: $(echo "$bad" | tr '\n' '|')"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- workflow: no sudo (runner Gitea ubuntu-latest = root, pas de binaire sudo) -- #
|
||||
check_no_sudo() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
local label="workflow contains no 'sudo' (runner Gitea ubuntu-latest is root without sudo)"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local count
|
||||
count=$(grep -Ec '\bsudo\b' "$f" || true)
|
||||
if [[ "$count" -eq 0 ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "found $count occurrence(s) of 'sudo'"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- git context --------------------------------------------------- #
|
||||
check_git_branch() {
|
||||
local label="current branch = feat/admin-web-docker"
|
||||
local b
|
||||
b="$(git rev-parse --abbrev-ref HEAD 2>/dev/null || true)"
|
||||
if [[ "$b" == "feat/admin-web-docker" ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "branch='$b'"
|
||||
fi
|
||||
}
|
||||
|
||||
check_git_commit_prefix() {
|
||||
local label="HEAD commit message starts with 'feat:'"
|
||||
local subj
|
||||
subj="$(git log -1 --format=%s 2>/dev/null || true)"
|
||||
if [[ "$subj" == feat:* ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "subject='$subj'"
|
||||
fi
|
||||
}
|
||||
|
||||
# =================================================================== #
|
||||
# PR BUILD-VALIDATION FEATURE CHECKS
|
||||
# (trigger pull_request + job build-validation build-only/no-secret)
|
||||
# =================================================================== #
|
||||
|
||||
# --- workflow: pull_request trigger with admin-web/** path filter --- #
|
||||
check_pr_trigger() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
local label="workflow triggers on pull_request with admin-web/** path filter"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local out
|
||||
out=$(python3 -c "
|
||||
import yaml,sys
|
||||
d=yaml.safe_load(open(sys.argv[1]))
|
||||
on=d.get(True) or d.get('on') or {}
|
||||
if not isinstance(on,dict): print('NO-PR: on not a dict'); sys.exit()
|
||||
pr=on.get('pull_request')
|
||||
if pr is None: print('NO-PR: no pull_request key'); sys.exit()
|
||||
paths=(pr.get('paths') if isinstance(pr,dict) else None) or []
|
||||
print('|'.join(str(p) for p in paths))
|
||||
" "$f" 2>/dev/null || echo "ERR")
|
||||
if echo "$out" | grep -Eq 'admin-web/\*\*'; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "pull_request.paths=[$out]"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- build-validation job: exists + if: pull_request ---------------- #
|
||||
check_build_validation_if() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
local label="build-validation job if: github.event_name == 'pull_request'"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local cond
|
||||
cond=$(python3 -c "
|
||||
import yaml,sys
|
||||
d=yaml.safe_load(open(sys.argv[1]))
|
||||
bv=d.get('jobs',{}).get('build-validation',{})
|
||||
print(bv.get('if','') or '')
|
||||
" "$f" 2>/dev/null || true)
|
||||
if echo "$cond" | grep -Eq "github\.event_name\s*==\s*'pull_request'"; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "if='$cond'"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- build-validation job: NO docker push (build-only) -------------- #
|
||||
check_build_validation_no_push() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
local label="build-validation does NOT docker push (build-only)"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local out
|
||||
out=$(python3 -c "
|
||||
import yaml,sys,json
|
||||
d=yaml.safe_load(open(sys.argv[1]))
|
||||
bv=d.get('jobs',{}).get('build-validation',{})
|
||||
blob=json.dumps(bv)
|
||||
print('PUSH' if 'docker push' in blob else 'NO-PUSH')
|
||||
" "$f" 2>/dev/null || echo "ERR")
|
||||
if [[ "$out" == "NO-PUSH" ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "docker push found in build-validation job"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- build-validation job: NO secrets (public vars only) ------------ #
|
||||
check_build_validation_no_secrets() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
local label="build-validation references no secrets (build-only, public vars only)"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local out
|
||||
out=$(python3 -c "
|
||||
import yaml,sys,json
|
||||
d=yaml.safe_load(open(sys.argv[1]))
|
||||
bv=d.get('jobs',{}).get('build-validation',{})
|
||||
blob=json.dumps(bv)
|
||||
print('SECRET' if 'secrets.' in blob else 'NO-SECRET')
|
||||
" "$f" 2>/dev/null || echo "ERR")
|
||||
if [[ "$out" == "NO-SECRET" ]]; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "secrets.* referenced in build-validation job"
|
||||
fi
|
||||
}
|
||||
|
||||
# --- semantic-release if excludes pull_request ---------------------- #
|
||||
check_sr_excludes_pr() {
|
||||
local f=".github/workflows/admin-web-docker.yml"
|
||||
local label="semantic-release if excludes pull_request"
|
||||
if [[ ! -f "$f" ]]; then
|
||||
fail "$label" "file missing"
|
||||
return
|
||||
fi
|
||||
local cond
|
||||
cond=$(python3 -c "
|
||||
import yaml,sys
|
||||
d=yaml.safe_load(open(sys.argv[1]))
|
||||
print(d.get('jobs',{}).get('semantic-release',{}).get('if','') or '')
|
||||
" "$f" 2>/dev/null || true)
|
||||
if echo "$cond" | grep -Eq "github\.event_name\s*!=\s*'pull_request'"; then
|
||||
pass "$label"
|
||||
else
|
||||
fail "$label" "if missing pull_request exclusion (if='$cond')"
|
||||
fi
|
||||
}
|
||||
|
||||
# =================================================================== #
|
||||
# RUN ALL
|
||||
# =================================================================== #
|
||||
|
||||
if [[ "$SUMMARY_ONLY" -eq 0 ]]; then
|
||||
echo "# verify-admin-web-docker.sh — structural validation"
|
||||
echo "# repo: $ROOT"
|
||||
echo ""
|
||||
fi
|
||||
|
||||
check_version_json
|
||||
check_root_package_json
|
||||
check_root_pkg_lock
|
||||
check_releaserc
|
||||
check_dockerfile
|
||||
check_next_config
|
||||
check_dockerignore
|
||||
check_workflow_valid
|
||||
check_workflow_jobs
|
||||
check_workflow_needs
|
||||
check_skip_ci_guard
|
||||
check_bp_if_condition
|
||||
check_docker_login
|
||||
check_docker_login_secret_name
|
||||
check_push_tags
|
||||
check_forbidden_secrets
|
||||
check_buildargs_source
|
||||
check_actions_pinned
|
||||
check_no_sudo
|
||||
check_git_branch
|
||||
check_git_commit_prefix
|
||||
# PR build-validation feature checks
|
||||
check_pr_trigger
|
||||
check_build_validation_if
|
||||
check_build_validation_no_push
|
||||
check_build_validation_no_secrets
|
||||
check_sr_excludes_pr
|
||||
|
||||
echo ""
|
||||
echo "# Summary: $PASS_COUNT passed, $FAIL_COUNT failed"
|
||||
if [[ "$FAIL_COUNT" -gt 0 ]]; then
|
||||
echo "# Failures:"
|
||||
for f in "${FAIL_NAMES[@]}"; do
|
||||
echo "# - $f"
|
||||
done
|
||||
fi
|
||||
|
||||
if [[ "$FAIL_COUNT" -gt 0 ]]; then
|
||||
exit 1
|
||||
fi
|
||||
exit 0
|
||||
3
version.json
Normal file
3
version.json
Normal file
@@ -0,0 +1,3 @@
|
||||
{
|
||||
"version": "1.0.0"
|
||||
}
|
||||
Reference in New Issue
Block a user