From 4464e76228adc04de521fc855730cb9ae032fe0b Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 24 Jun 2026 16:46:47 -0400 Subject: [PATCH] Convert CI to org reusable workflow caller Replace the inline 5-job ci.yml with a thin caller of the org reusable workflow ci-typescript-frontend.yaml. The standards gate, changed-line guard, format/lint/build, unit tests, and Playwright browser smoke now live centrally in Sea-Haven-Industries/.github and are maintained once. Renames ci.yml -> ci.yaml (kebab-case .yaml convention) and triggers on pull_request and push to main and dev, so this branch keeps CI coverage. The reusable workflow runs as a single `ci` job, so this caller emits the `ci / ci` status context. Branch-protection rulesets for main and dev must have their required checks switched from the old job names (Metadata and standards, Code quality, Build, Unit tests, Browser smoke) to `ci / ci`. --- .github/workflows/ci.yaml | 16 +++++ .github/workflows/ci.yml | 141 -------------------------------------- 2 files changed, 16 insertions(+), 141 deletions(-) create mode 100644 .github/workflows/ci.yaml delete mode 100644 .github/workflows/ci.yml diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml new file mode 100644 index 00000000..3b220720 --- /dev/null +++ b/.github/workflows/ci.yaml @@ -0,0 +1,16 @@ +name: CI + +on: + pull_request: + branches: [main, dev] + push: + branches: [main, dev] + +permissions: + contents: read + +jobs: + ci: + uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-frontend.yaml@main + with: + node-version: "24" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml deleted file mode 100644 index 89e945b1..00000000 --- a/.github/workflows/ci.yml +++ /dev/null @@ -1,141 +0,0 @@ -name: CI - -on: - push: - branches: [main, master, develop, Dev] - pull_request: - -permissions: - contents: read - -concurrency: - group: frontend-ci-${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -jobs: - standards: - name: Metadata and standards - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - - uses: actions/setup-node@v4 - with: - node-version: 24 - - - name: Verify required npm scripts - run: | - node <<'NODE' - const { readFileSync } = require("node:fs"); - const pkg = JSON.parse(readFileSync("package.json", "utf8")); - const required = ["format:check", "lint", "build", "test", "test:e2e"]; - const missing = required.filter((script) => !pkg.scripts?.[script]); - - if (missing.length > 0) { - console.error(`Missing required scripts: ${missing.join(", ")}`); - process.exit(1); - } - NODE - - - name: Guard changed lines - run: | - set -euo pipefail - - if [ "${{ github.event_name }}" = "pull_request" ]; then - BASE_REF="${{ github.event.pull_request.base.sha }}" - else - BASE_REF="${{ github.event.before }}" - fi - - if [ -z "${BASE_REF}" ] || [ "${BASE_REF}" = "0000000000000000000000000000000000000000" ]; then - BASE_REF="$(git rev-parse HEAD~1 2>/dev/null || true)" - fi - - if [ -z "${BASE_REF}" ]; then - echo "No base ref available; skipping changed-line guard." - exit 0 - fi - - ADDED_LINES="$(git diff --unified=0 "${BASE_REF}" "${GITHUB_SHA}" | grep -E '^\+' | grep -vE '^\+\+\+' || true)" - - if printf '%s\n' "${ADDED_LINES}" | grep -E 'Generated with (Claude [C]ode|[C]odex|Chat[G]PT)|--no-[v]erify|HUSKY[=]0'; then - echo "Found generated-tool footer or hook bypass wording in added lines." - exit 1 - fi - - if printf '%s\n' "${ADDED_LINES}" | grep -E 'A[K]IA[0-9A-Z]{16}|A[S]IA[0-9A-Z]{16}|AWS[_]SECRET[_]ACCESS[_]KEY|aws[_-]?secret[_-]?access[_-]?key|J[W]TAuthenticationHIGHsecuredPassword|P[a]ssword=|S[e]ndGrid.*A[p]iKey'; then - echo "Found a likely secret in added lines. Move sensitive values to the environment or secret manager." - exit 1 - fi - - code-quality: - name: Code quality - runs-on: ubuntu-latest - needs: standards - steps: - - uses: actions/checkout@v4 - - - uses: actions/setup-node@v4 - with: - node-version: 24 - cache: npm - - - run: npm ci - - - run: npm run format:check - - - run: npm run lint - - build: - name: Build - runs-on: ubuntu-latest - needs: standards - steps: - - uses: actions/checkout@v4 - - - uses: actions/setup-node@v4 - with: - node-version: 24 - cache: npm - - - run: npm ci - - - run: npm run build - - unit-tests: - name: Unit tests - runs-on: ubuntu-latest - needs: standards - steps: - - uses: actions/checkout@v4 - - - uses: actions/setup-node@v4 - with: - node-version: 24 - cache: npm - - - run: npm ci - - - run: npm test - - e2e: - name: Browser smoke - runs-on: ubuntu-latest - needs: standards - steps: - - uses: actions/checkout@v4 - - - uses: actions/setup-node@v4 - with: - node-version: 24 - cache: npm - - - run: npm ci - - - run: npx playwright install --with-deps chromium - - - run: npm run test:e2e - env: - CI: true