name: Backend CI on: pull_request: # The merge queue builds main plus the queued pull requests on a temporary # branch and only counts checks that ran on the merge_group event. merge_group: push: branches: [main] permissions: contents: read concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} jobs: build-and-test: name: Build and test runs-on: ubuntu-latest timeout-minutes: 20 steps: - name: Checkout uses: actions/checkout@v7 - name: Set up .NET uses: actions/setup-dotnet@v6 with: dotnet-version: "8.0.x" - name: Cache NuGet packages uses: actions/cache@v4 with: path: ~/.nuget/packages key: nuget-${{ runner.os }}-${{ hashFiles('**/*.csproj', '**/*.props') }} restore-keys: | nuget-${{ runner.os }}- - name: Restore run: dotnet restore SeaHavenIndustries.sln - name: Build run: dotnet build SeaHavenIndustries.sln --no-restore --configuration Release - name: Test run: dotnet test SeaHavenIndustries.sln --no-build --configuration Release architecture: name: architecture runs-on: ubuntu-latest timeout-minutes: 20 steps: - name: Checkout uses: actions/checkout@v7 with: fetch-depth: 0 - name: Set up .NET uses: actions/setup-dotnet@v6 with: dotnet-version: "8.0.x" - name: Cache NuGet packages uses: actions/cache@v4 with: path: ~/.nuget/packages key: nuget-${{ runner.os }}-${{ hashFiles('**/*.csproj', '**/*.props') }} restore-keys: | nuget-${{ runner.os }}- - name: Set up Terraform uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1 with: terraform_version: "1.9.8" terraform_wrapper: false - name: Repository quality gate shell: bash env: GOVERNANCE_SKIP_BUILD_TEST: "1" # A merge group carries its own base and head; github.event.before is # empty on that event. BASE_REF: ${{ github.event.pull_request.base.sha || github.event.merge_group.base_sha || github.event.before }} HEAD_REF: ${{ github.event.pull_request.head.sha || github.event.merge_group.head_sha || github.sha }} run: bash scripts/governance-check.sh review: name: review if: github.event_name != 'push' uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@4a6cbfd362140a68810f0f46d338026863b8e827 # v1.0.10 ci-complete: name: ci-complete if: always() needs: [build-and-test, architecture, review] runs-on: ubuntu-latest steps: - name: All required jobs passed shell: bash env: BUILD: ${{ needs.build-and-test.result }} ARCH: ${{ needs.architecture.result }} REVIEW: ${{ needs.review.result }} run: | set -euo pipefail if [[ "${BUILD}" != "success" || "${ARCH}" != "success" ]]; then echo "Build and test or architecture did not succeed: build=${BUILD} architecture=${ARCH}" exit 1 fi # review is skipped on push to main; it must succeed on pull_request # and merge_group. if [[ "${REVIEW}" != "success" && "${REVIEW}" != "skipped" ]]; then echo "review did not succeed: ${REVIEW}" exit 1 fi