name: CI on: pull_request: branches: [main] paths-ignore: - '*.md' - 'docs/**' - 'AUDIT-*.md' - '.claude/**' - 'LICENSE' merge_group: concurrency: group: ci-${{ github.ref }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} permissions: contents: read jobs: dotnet: name: .NET Build & Test uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8 with: working-directory: api solution: ProposalSystem.sln web: name: Web Frontend Check # Phase 5: full frontend pipeline — format:check, build (tsc -b included), # vitest, Playwright chromium smoke. Replaces the old typecheck-only job # plus the standalone Web Tests job. No lint script yet (run-lint: false). uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8 with: working-directory: web cache-dependency-path: web/package-lock.json node-version: "24" run-lint: false required-scripts: "format:check,build,test,test:e2e" python: name: Python Lint uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8 with: source-dirs: "lambdas/" run-sam-validate: false run-conventions-check: false python-test: name: Python Tests runs-on: ubuntu-latest timeout-minutes: 10 defaults: run: working-directory: lambdas steps: - uses: actions/checkout@v7.0.1 - uses: actions/setup-python@v7 with: python-version: "3.12" - name: Install dependencies run: | pip install -r tests/requirements-test.txt for req in $(find . -name requirements.txt -not -path './tests/*'); do pip install -r "$req" done - run: pytest tests/ -v mobile: name: Mobile Typecheck uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8 with: working-directory: mobile cache-dependency-path: mobile/package-lock.json node-version: "24" run-cdk-synth: false run-conventions-check: false infra: name: CDK Synth uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@af0f002e14a08cdbfd879c1183bfe7eb2604bce9 # v1.0.8 with: working-directory: infra cache-dependency-path: infra/package-lock.json node-version: "24" dotnet-version: "8.0.x" dotnet-publish-project: api/src/ProposalSystem.Api/ProposalSystem.Api.csproj run-typecheck: false # Aggregator producing the org-required "ci / ci" status context. # Caller/inline jobs here have distinct names, so the org ruleset's # required check would otherwise never report on this repo. ci: name: ci / ci needs: [dotnet, web, python, python-test, mobile, infra] if: always() runs-on: ubuntu-latest steps: - name: All CI jobs passed run: | [ "${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}" = "false" ]