Commit Graph
9 Commits
Author SHA1 Message Date
Eduard Gert 4779d75306 Move every GitHub Action off the retired Node 20 runtime (#995)
GitHub Actions runners no longer ship Node 20 for JavaScript actions, and the
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION opt-out is gone, so any action whose
own action.yml declares `runs.using: node20` (or older) now fails to start.
Each target tag below was verified by reading its action.yml runtime directly,
not inferred from the version number.

  actions/checkout          v3, v4, v6 -> v7
  actions/setup-node        v4         -> v7
  actions/cache             v4         -> v6
  actions/setup-go          v5, v6     -> v7
  docker/metadata-action    v5         -> v6
  docker/login-action       v3         -> v4
  docker/build-push-action  v6         -> v7

booxmedialtd/ws-action-parse-semver is knowingly left alone. It declares node12
at v1, its newest tag v1.4.7 and master are node16, and the repo has not been
touched since 2023, so there is no version to move to. Replacing it is a real
change, not a version bump: it validates through node-semver and fails the job
on a non-semver tag, and the obvious substitutes are weaker. A plain shell
capture accepts the dispatch input's own placeholder default of refs/tags/vX.Y.Z,
and netbirdio/shared-actions/actions/parse-semver falls back to 0.0.0 rather
than failing. Either would let the job run on past the bad version, 404 the
openapi.yml download, and push a commit deleting all 36 generated API pages,
because the curl has no --fail and the Go expander ignores read and parse
errors. That swap needs those guards and its own PR.

Breaking changes across every major crossed were checked against the actual
workflow lines and none apply: setup-node v5/v6 auto-caching needs a
packageManager field package.json does not have (and every call site already
passes cache: 'npm'); setup-node v7 drops a NODE_AUTH_TOKEN export nothing
here uses, as no step sets registry-url; cache v5/v6 and checkout v5 raise the
runner floor, and every job runs on ubuntu-latest or macos-latest; checkout v6
relocates persisted credentials, which generate_api_pages already proves
harmless by pushing over HTTPS on v6 today; checkout v7 blocks fork PR heads
under pull_request_target and workflow_run, neither of which is a trigger in
this repo; metadata-action v6 changes '#' handling in list inputs, and the one
input is a bare image name; build-push-action v7 removes DOCKER_BUILD_NO_SUMMARY
and DOCKER_BUILD_EXPORT_RETENTION_DAYS, neither set anywhere; setup-go v6
reworks toolchain selection, and the only Go dependency here declares go 1.18
against an installed 1.21.

The two pull_request-triggered checkouts that run PR-authored code and never
touch a remote — pr-build and codespell — also stop persisting a token into
the workspace. build_n_push keeps its credentials: the same checkout feeds the
promote step's `git ls-remote origin`, so hardening it needs a job split.

setup-node's node-version stays at 20. That is a real concern separately, since
Node 20 is EOL, but docker/Dockerfile is FROM node:20-slim and build_n_push
builds the Next standalone bundle on the runner and copies it into that image,
so build-time and runtime Node have to move together and be proven by a real
build. It belongs in its own PR.
2026-09-24 14:50:53 +02:00
Jack CarterandBrandon Hopkins 2a02ce7edd ci: harden the build and API-pages workflows (#843)
* ci: serialise image builds and stop the API-pages workflow clobbering the lockfile

build_n_push: add a per-ref concurrency group so two quick merges to main can't race the :main tag (last push wins regardless of commit order, and the server auto-pulls :main); add permissions: contents: read; validate .dockerignore and package.json changes in the PR path filter.

generate_api_pages: pin Node 20 and switch npm install -> npm ci so the run can never rewrite the now-tracked package-lock.json with a divergent macOS-resolved tree; stage only src/pages/ipa/resources instead of git add -A; drop --force from the push — a force-push from this workflow would silently rewrite main and destroy any PR merged since its checkout.

* chore: warn when per-page dates are skipped; drop dead per-file git lookup

buildGitDateMap now logs a warning when it emits no dates (git missing or shallow clone) instead of silently blanking every page's Updated line and the sitemap lastmod entries; document the squash-merge assumption behind the --name-only walk. Remove the unused getGitLastModified. Note in CLAUDE.md that npm run start warns under output: 'standalone'. Gen output verified byte-identical.

* ci: self-heal the API-pages push when main moves mid-run

Rebase the single generated-files commit onto the moved branch before pushing, so a PR merged during the multi-minute run no longer rejects the push (the failure --force was presumably papering over). A genuine conflict — a concurrent edit of the generated files themselves — still fails the run loudly with main untouched. Also serialise dispatches with a concurrency group: run history shows several same-day dispatches, and overlapping runs regenerate the same files.

Sandbox-tested against a bare repo: plain push rejected on race; rebase+push lands with both commits intact; true conflict exits 1 leaving the branch tip untouched.

* ci: sync to branch tip before regenerating API pages

A run queued behind another checks out the commit pinned at its dispatch time; regenerating against that stale base means the pre-push rebase replays a snapshot diff, and a file the newer spec removed can silently survive from the prior run. Fetch + reset to the branch tip before generating so the diff is computed against reality. Also note the latest-dispatched-vs-newest-tag caveat on the concurrency comment.

Sandbox-proven: with the old order a removed-in-newer-spec file survives the rebase replay; with sync-first it is gone.

* Prevent stale workflows from overwriting newer published content

* Coderabbit Fix

---------

Co-authored-by: Brandon Hopkins <brandon@techhut.tv>
2026-07-22 17:06:58 +02:00
Jack Carter 76845ec77f perf: build docs on the CI runner with a warm .next cache (#840)
Move `npm run build` out of the Docker image onto the runner, where actions/cache persists .next/cache across runs (the in-Docker build discarded it every time). The image now just packages the prebuilt .next and serves it with `next start`; runtime and the DocSearch entrypoint injection are unchanged.

Also: checkout full history (fetch-depth: 0) so per-page dates are correct, guard buildGitDateMap against shallow clones (correct-or-absent, never wrong), modernise the Docker actions (build-push-action v6, provenance: false), and add a path-filtered pull_request trigger so pipeline changes are validated before merge.

Smoke-tested via isolated build + docker run: serves /, /introduction, /api, sitemap, static assets (200); DocSearch placeholder injection intact.
2026-07-09 14:13:30 +02:00
Maycon Santos 17fb9602d3 Update docker creds (#239) 2024-09-30 20:07:10 +02:00
Maycon Santos af5479f041 Update build_n_push.yml with workflow_dispatch 2023-08-14 12:02:38 +02:00
pascal-fischer d18f5c076f Decouple api generation flow from docker build (#62)
* decouple api generation from docker build

* add different PAT
2023-06-12 14:47:20 +02:00
pascal-fischerandGitHub Actions f33b4df3dd Add workflow for api gen and refactor genration script (#60)
* update gitignore

* add first version of api generation flow

* try to run flow

* testing flow

* update gen flow

* switch flow to macOS

* fix

* add npm install

* test workflow

* Update API pages

* test workflow with current main

* refactor parser

* merge examples and schema functions

* merge examples and schema functions

* merge parameters as well

* revert template to single class component

* update account

* finalizing

* update with the newest version of openapi

* full flow

* update

* add docker command

* split flow in two jobs

* remove testing trigger

---------

Co-authored-by: GitHub Actions <no-reply@github.com>
2023-06-05 09:35:54 +02:00
mlsmaycon f5146c7455 Run ci/cd on PRs 2022-06-20 19:12:43 +02:00
mlsmaycon 98751bc1f4 Move the documentation repository to a public repo
Added a LICENSE and documentation on how to contribute

Updated CI/CD to use the root level code
2022-06-20 19:05:25 +02:00