Skip to content

Cap prose at a reading measure, assign typefaces by role, write the g… #13

Cap prose at a reading measure, assign typefaces by role, write the g…

Cap prose at a reading measure, assign typefaces by role, write the g… #13

Workflow file for this run

name: Deploy Pages
on:
push:
branches: [main]
workflow_dispatch:
permissions:
contents: read
pages: write
id-token: write
concurrency:
group: pages
cancel-in-progress: false
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# No version pin here. pnpm/action-setup reads packageManager from
# package.json, and giving it both is a hard error.
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
with:
node-version: 22
cache: pnpm
- name: Install
run: pnpm install --no-frozen-lockfile
# Runs the full pipeline over committed fixtures and writes one JSON file
# per (passport, role). Each file contains ONLY the fields that role may
# see, so the disclosure boundary is provable by inspecting the deployed
# site rather than merely asserted in prose.
- name: Generate per-role fixture payloads
run: pnpm fixtures
- name: Build static site
run: pnpm build:web
env:
NEXT_PUBLIC_BASE_PATH: /DPA
- uses: actions/configure-pages@v5
- uses: actions/upload-pages-artifact@v3
with:
path: apps/web/out
deploy:
needs: build
runs-on: ubuntu-latest
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- id: deployment
uses: actions/deploy-pages@v4