Skip to content

ci(frontend): Fold build, lint and test into one entry point #83

ci(frontend): Fold build, lint and test into one entry point

ci(frontend): Fold build, lint and test into one entry point #83

name: PR Quality Gate
on:
pull_request:
push:
branches: [main]
concurrency:
group: quality-gate-${{ github.ref }}
cancel-in-progress: true
# Deny-all by default; this workflow only ever reads the checked-out code. No
# job here writes packages, contents, or any other scope, so a malicious PR or a
# compromised build dependency has no privileged token to exfiltrate.
permissions: {}
env:
CARGO_TERM_COLOR: always
jobs:
backend:
name: Backend (fmt, clippy, tests)
runs-on: ubuntu-latest
# The debug target root is shared only with other debug CI builds. It is
# deliberately disjoint from release and profiling artifacts.
env:
CARGO_TARGET_DIR: target/ci-debug
permissions:
contents: read
steps:
- uses: actions/checkout@v4
with:
submodules: recursive
- name: Install Rust toolchain
run: rustup show
# Cache only dependency artifacts and use a typed target root. PRs may
# restore the default branch's cache but only a push of trusted main code
# may save it, so no PR can poison a cache consumed by trusted CI.
- name: Cache Rust debug dependencies
uses: Swatinem/rust-cache@v2
with:
prefix-key: v1-serval-rust
shared-key: ci-debug
workspaces: . -> target/ci-debug
cache-bin: false
cache-workspace-crates: false
save-if: ${{ github.event_name == 'push' && github.ref == 'refs/heads/main' }}
- name: Format
run: cargo fmt --all -- --check
- name: Clippy
run: cargo clippy --all-features -- -D warnings -A clippy::too_many_arguments
env:
SERVAL_SKIP_FRONTEND_BUILD: "1"
- name: Unit tests
run: cargo test
env:
SERVAL_SKIP_FRONTEND_BUILD: "1"
frontend:
name: Frontend (build, lint, test)
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v4
with:
submodules: recursive
- uses: ./.github/actions/frontend