mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-06 10:27:12 +00:00
f1f68e6653
The push/pull_request paths filter didn't include .github/workflows/**, so the previous commit (fixing the Audit step) never actually ran through CI -- editing the workflow itself silently skipped the trigger. A broken workflow-syntax change could merge untested the same way. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
202 lines
6.7 KiB
YAML
202 lines
6.7 KiB
YAML
name: CI
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- "**.go"
|
|
- "go.mod"
|
|
- "go.sum"
|
|
- "frontend/**"
|
|
- ".nvmrc"
|
|
- ".github/workflows/**"
|
|
push:
|
|
branches:
|
|
- main
|
|
paths:
|
|
- "**.go"
|
|
- "go.mod"
|
|
- "go.sum"
|
|
- "frontend/**"
|
|
- ".nvmrc"
|
|
- ".github/workflows/**"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
go-test:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: go.mod
|
|
cache: true
|
|
- name: Stub internal/web/dist for go:embed
|
|
run: mkdir -p internal/web/dist && touch internal/web/dist/.gitkeep
|
|
- name: Test
|
|
run: |
|
|
go list ./... | grep -v '/frontend/node_modules/' > /tmp/go-packages.txt
|
|
go test -shuffle=on -count=1 $(cat /tmp/go-packages.txt)
|
|
|
|
postgres-durable-first:
|
|
runs-on: ubuntu-latest
|
|
services:
|
|
postgres:
|
|
image: postgres:16
|
|
env:
|
|
POSTGRES_USER: postgres
|
|
POSTGRES_PASSWORD: postgres
|
|
POSTGRES_DB: xui_durable
|
|
ports:
|
|
- 5432:5432
|
|
options: >-
|
|
--health-cmd "pg_isready -U postgres -d xui_durable"
|
|
--health-interval 10s
|
|
--health-timeout 5s
|
|
--health-retries 5
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: go.mod
|
|
cache: true
|
|
- name: Stub internal/web/dist for go:embed
|
|
run: mkdir -p internal/web/dist && touch internal/web/dist/.gitkeep
|
|
- name: PostgreSQL durable-first tests
|
|
run: |
|
|
set -o pipefail
|
|
XUI_DB_TYPE=postgres XUI_DB_DSN="host=127.0.0.1 port=5432 user=postgres password=postgres dbname=xui_durable sslmode=disable" \
|
|
go test ./internal/web/service -run 'PostgresCommitFailure' -count=1 -v | tee /tmp/postgres-durable-first.log
|
|
if grep -q -- '--- SKIP' /tmp/postgres-durable-first.log; then
|
|
exit 1
|
|
fi
|
|
|
|
codegen:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: go.mod
|
|
cache: true
|
|
- uses: actions/setup-node@v7
|
|
with:
|
|
node-version-file: .nvmrc
|
|
- name: Regenerate schemas, examples and OpenAPI
|
|
run: npm run gen
|
|
working-directory: frontend
|
|
- name: Fail if generated files are stale (run 'npm run gen' and commit)
|
|
run: git diff --exit-code -- frontend/src/generated frontend/public/openapi.json
|
|
|
|
govulncheck:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: go.mod
|
|
cache: true
|
|
- name: Stub internal/web/dist for go:embed
|
|
run: mkdir -p internal/web/dist && touch internal/web/dist/.gitkeep
|
|
- name: Install govulncheck
|
|
run: go install golang.org/x/vuln/cmd/govulncheck@latest
|
|
- name: Run govulncheck
|
|
run: govulncheck ./...
|
|
|
|
# Race + shuffle hygiene gate: data races and order-dependent tests fail the build.
|
|
race:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: go.mod
|
|
cache: true
|
|
- name: Stub internal/web/dist for go:embed
|
|
run: mkdir -p internal/web/dist && touch internal/web/dist/.gitkeep
|
|
- name: Race + shuffle
|
|
run: |
|
|
go list ./... | grep -v '/frontend/node_modules/' > /tmp/go-packages.txt
|
|
go test -race -shuffle=on -count=1 $(cat /tmp/go-packages.txt)
|
|
|
|
# Brief native-fuzz smoke on the security-/parser-critical decoders. Each runs the
|
|
# generated corpus plus 30s of exploration; a crash here is a real input-handling bug.
|
|
fuzz-smoke:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: go.mod
|
|
cache: true
|
|
- name: Stub internal/web/dist for go:embed
|
|
run: mkdir -p internal/web/dist && touch internal/web/dist/.gitkeep
|
|
- name: Fuzz critical parsers (smoke)
|
|
run: |
|
|
go test -run '^$' -fuzz 'FuzzParseLink$' -fuzztime=30s ./internal/util/link/
|
|
go test -run '^$' -fuzz 'FuzzDecodeCertPin$' -fuzztime=30s ./internal/web/runtime/
|
|
|
|
golangci:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: go.mod
|
|
cache: true
|
|
- name: Stub internal/web/dist for go:embed
|
|
run: mkdir -p internal/web/dist && touch internal/web/dist/.gitkeep
|
|
- name: golangci-lint
|
|
uses: golangci/golangci-lint-action@v9
|
|
with:
|
|
version: latest
|
|
|
|
frontend:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-node@v7
|
|
with:
|
|
node-version-file: .nvmrc
|
|
cache: npm
|
|
cache-dependency-path: frontend/package-lock.json
|
|
- name: Install
|
|
run: npm ci
|
|
working-directory: frontend
|
|
- name: Lint
|
|
run: npm run lint
|
|
working-directory: frontend
|
|
- name: Typecheck
|
|
run: npm run typecheck
|
|
working-directory: frontend
|
|
- name: Install Playwright Chromium (Storybook story tests)
|
|
run: npx playwright install --with-deps chromium
|
|
working-directory: frontend
|
|
- name: Test
|
|
run: npm test
|
|
working-directory: frontend
|
|
- name: Build
|
|
run: npm run build
|
|
working-directory: frontend
|
|
- name: Build Storybook
|
|
run: npm run build-storybook
|
|
working-directory: frontend
|
|
# --omit=dev: the one remaining high advisory (brace-expansion/minimatch
|
|
# via eslint-plugin-jsx-a11y's own pinned minimatch@^3.1.2,
|
|
# GHSA-mh99-v99m-4gvg) lives entirely in devDependencies -- jsx-a11y is
|
|
# lint-only tooling, never shipped in the built panel, and only ever
|
|
# runs against this repo's own hardcoded lint globs, never untrusted
|
|
# input. The eslint-core minimatch@10.x instance of the same advisory
|
|
# is already fixed via the "minimatch@^10" override below (brace-
|
|
# expansion 5.0.8); jsx-a11y's own minimatch is pinned to an old major
|
|
# with no patched release in that line, and forcing it to 10.x via
|
|
# override breaks npm's own dependency-tree validation (a genuine
|
|
# incompatibility, not an npm quirk) -- so it can only be fixed by an
|
|
# eslint-plugin-jsx-a11y release bumping its own minimatch. `--omit=dev`
|
|
# still audits runtime `dependencies` at high severity, so a real
|
|
# production vulnerability still fails this step.
|
|
- name: Audit
|
|
run: npm audit --omit=dev --audit-level=high
|
|
working-directory: frontend
|