Cap prose at a reading measure, assign typefaces by role, write the g… #13
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy Pages | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| pages: write | |
| id-token: write | |
| concurrency: | |
| group: pages | |
| cancel-in-progress: false | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| # No version pin here. pnpm/action-setup reads packageManager from | |
| # package.json, and giving it both is a hard error. | |
| - uses: pnpm/action-setup@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22 | |
| cache: pnpm | |
| - name: Install | |
| run: pnpm install --no-frozen-lockfile | |
| # Runs the full pipeline over committed fixtures and writes one JSON file | |
| # per (passport, role). Each file contains ONLY the fields that role may | |
| # see, so the disclosure boundary is provable by inspecting the deployed | |
| # site rather than merely asserted in prose. | |
| - name: Generate per-role fixture payloads | |
| run: pnpm fixtures | |
| - name: Build static site | |
| run: pnpm build:web | |
| env: | |
| NEXT_PUBLIC_BASE_PATH: /DPA | |
| - uses: actions/configure-pages@v5 | |
| - uses: actions/upload-pages-artifact@v3 | |
| with: | |
| path: apps/web/out | |
| deploy: | |
| needs: build | |
| runs-on: ubuntu-latest | |
| environment: | |
| name: github-pages | |
| url: ${{ steps.deployment.outputs.page_url }} | |
| steps: | |
| - id: deployment | |
| uses: actions/deploy-pages@v4 |