open-swe/.github/workflows/ci.yml
seahaven-openswe[bot] 8d89f5c4c2
chore(deps): bump vite-tsconfig-paths to ^6.1.1 and jsdom to ^29.1.1 (#123)
* chore(deps): bump vite-tsconfig-paths to ^6.1.1 and jsdom to ^29.1.1

Reconcile two Dependabot PRs (#107, #108) into one branch with a
single bun install so package.json and bun.lock stay consistent.

vite-tsconfig-paths: ^5.1.4 -> ^6.1.1 (dependencies)
jsdom: ^27.4.0 -> ^29.1.1 (devDependencies)

* Add --frozen-lockfile to CI Checks

Normal bun install treats bun.lock as updatable. If package.json requests a requirement bun.lock doesn't satisfy, bun quietly rewrites the lock and moves on. The committed lock is never updated.

* chore: Add trailing newline on new last run

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-03 14:05:51 -04:00

124 lines
No EOL
3.9 KiB
YAML

name: CI
permissions:
contents: read
on:
push:
# dev as well as main so every dev HEAD carries the full CI signal that
# the dev->main promotion gate (check-dev-green.sh) reads. PR checks alone are
# not enough: an admin-merge can land a red PR onto dev.
branches: ["main", "dev"]
pull_request:
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
- name: Install dependencies
run: uv sync --locked --extra dev
- name: Run lint
run: make lint
format:
name: Format check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
- name: Install dependencies
run: uv sync --locked --extra dev
- name: Run format check
run: make format-check
unit-tests:
name: Unit tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
- name: Install dependencies
run: uv sync --locked --extra dev
- name: Run unit tests
run: make test
e2e:
name: Playwright E2E
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
- uses: actions/setup-node@v6
with:
node-version: "24"
- uses: oven-sh/setup-bun@v2
- name: Install Python deps (langgraph dev runtime)
run: uv sync --locked
- name: Install Playwright + Chromium
working-directory: tests/e2e
run: |
npm ci
npx playwright install --with-deps chromium
# Playwright's webServer boots `langgraph dev`; globalSetup builds the real
# ui/ SPA. The fake LLM/GitHub/Slack boundaries need no secrets.
- name: Run E2E
working-directory: tests/e2e
# Playwright's globalSetup runs the real `bun run build`, whose vite bundle
# exceeds Node's default ~2 GB heap.
# The runner has ~16 GB, so lift the heap cap.
env:
NODE_OPTIONS: "--max-old-space-size=8192"
run: npx playwright test
- name: Upload Playwright report
if: ${{ !cancelled() }}
uses: actions/upload-artifact@v7
with:
name: playwright-report
path: |
tests/e2e/playwright-report
tests/e2e/test-results
retention-days: 7
docker-build:
name: Docker build smoke
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v7
# Smoke-build the sandbox image so a bad Dockerfile pin (e.g. an
# apt "nodejs=${NODEJS_VERSION}" that no longer resolves) fails a check
# instead of only surfacing at sandbox-provision time. No push, no
# registry credentials: this only proves the image builds.
- name: Build sandbox image (no push)
run: docker build --pull -t open-swe-sandbox:ci .
triage-ledger:
name: Triage ledger up to date
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
# docs/upstream-sync/triage.md is GENERATED from triage.jsonl. Fail if a
# ledger edit forgot to regenerate it (`make triage-render`). Stdlib-only
# Python, so no uv sync / deps needed.
- name: triage.md is up to date with triage.jsonl
run: make triage-check
ui-lockfile:
name: ui bun.lock in sync
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: oven-sh/setup-bun@v2
- name: ui/package.json and ui/bun.lock agree
working-directory: ui
run: bun install --frozen-lockfile