As libreshop/cms adopted: a test job pipes the source into the image's base (the Dockerfile's first FROM, node:22-slim) and runs npm test there without network. The image build needs it and runs for pull requests (build only) and v* tags (published if PUBLISH_ENABLED). main no longer publishes :main and :sha-* images; mp pins the shop image by version tag. Refs libretech/mp#71
45 lines
1.7 KiB
YAML
45 lines
1.7 KiB
YAML
name: build
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
tags: ["v*"]
|
|
pull_request:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
test:
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: git.librete.ch/public/runner-image:v0.2.0@sha256:f60c587d3c0b0aac04a572db5349e27672bf76baec2ce547a3dcc28cebcf1b7e
|
|
timeout-minutes: 10
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
# The tests need no dependencies. They run in the image's base (Dockerfile FROM), so on the runtime's Node,
|
|
# without network. The source is piped in because the job container's paths do not exist on the Docker host.
|
|
- name: npm test, on the Node of the image
|
|
run: |
|
|
base=$(sed -n 's/^FROM \([^ ]*\).*/\1/p' Dockerfile | head -1)
|
|
tar -c --exclude=.git . | docker run -i --rm --network none -e npm_config_update_notifier=false "$base" \
|
|
sh -c 'mkdir /w && cd /w && tar -x && npm test'
|
|
|
|
# The image is built to check a pull request, and built and published only for a release tag.
|
|
# Nothing pulls per-commit images, so main no longer publishes :main and :sha-* images.
|
|
build:
|
|
needs: test
|
|
if: github.event_name == 'pull_request' || startsWith(github.ref, 'refs/tags/v')
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: git.librete.ch/public/runner-image:v0.2.0@sha256:f60c587d3c0b0aac04a572db5349e27672bf76baec2ce547a3dcc28cebcf1b7e
|
|
timeout-minutes: 20
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: https://git.librete.ch/public/actions/.gitea/actions/docker-build@main
|
|
with:
|
|
registry: ${{ secrets.REGISTRY }}
|
|
registry_user: ${{ secrets.REGISTRY_USER }}
|
|
registry_pass: ${{ secrets.REGISTRY_PASS }}
|
|
publish: ${{ startsWith(github.ref, 'refs/tags/v') && vars.PUBLISH_ENABLED == 'true' }}
|