name: CI on: pull_request: branches: [main] paths-ignore: - '*.md' - 'docs/**' - 'AUDIT-*.md' - '.claude/**' - 'LICENSE' concurrency: group: ci-${{ github.ref }} cancel-in-progress: true permissions: contents: read jobs: dotnet: name: .NET Build & Test # Fix: INF-M8 — pin to SHA for supply chain security (ci-dotnet.yaml@main) uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc with: working-directory: api solution: ProposalSystem.sln web: name: Web Frontend Check # Fix: INF-M8 — pin to SHA for supply chain security (ci-typescript-cdk.yaml@main) uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc with: working-directory: web cache-dependency-path: web/package-lock.json node-version: "24" run-cdk-synth: false run-conventions-check: false web-test: name: Web Tests runs-on: ubuntu-latest timeout-minutes: 10 defaults: run: working-directory: web steps: - uses: actions/checkout@v6 - uses: actions/setup-node@v4 with: node-version: "24" cache: npm cache-dependency-path: web/package-lock.json - run: npm ci - run: npm test python: name: Python Lint # Fix: INF-M8 — pin to SHA for supply chain security (ci-python-sam.yaml@main) uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc with: source-dirs: "lambdas/" run-sam-validate: false run-conventions-check: false python-test: name: Python Tests runs-on: ubuntu-latest timeout-minutes: 10 defaults: run: working-directory: lambdas steps: - uses: actions/checkout@v6 - uses: actions/setup-python@v5 with: python-version: "3.12" - name: Install dependencies run: | pip install -r tests/requirements-test.txt for req in $(find . -name requirements.txt -not -path './tests/*'); do pip install -r "$req" done - run: pytest tests/ -v mobile: name: Mobile Typecheck # Fix: INF-M8 — pin to SHA for supply chain security (ci-typescript-cdk.yaml@main) uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc with: working-directory: mobile cache-dependency-path: mobile/package-lock.json node-version: "24" run-cdk-synth: false run-conventions-check: false infra: name: CDK Synth # Fix: INF-M8 — pin to SHA for supply chain security (ci-typescript-cdk.yaml@main) uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@c040bfaa223ac9a671cca9047cffdac45b00f3dc with: working-directory: infra cache-dependency-path: infra/package-lock.json node-version: "24" dotnet-version: "8.0.x" dotnet-publish-project: api/src/ProposalSystem.Api/ProposalSystem.Api.csproj run-typecheck: false # Aggregator producing the org-required "ci / ci" status context. # Caller/inline jobs here have distinct names, so the org ruleset's # required check would otherwise never report on this repo. ci: name: ci / ci needs: [dotnet, web, web-test, python, python-test, mobile, infra] if: always() runs-on: ubuntu-latest steps: - name: All CI jobs passed run: | [ "${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}" = "false" ]