Skip to content

refactor(client): adopt Redux Toolkit slices for state layer (#43) (#… #108

refactor(client): adopt Redux Toolkit slices for state layer (#43) (#…

refactor(client): adopt Redux Toolkit slices for state layer (#43) (#… #108

Workflow file for this run

name: E2E Security Regression Suite
on:
push:
branches: ['master']
pull_request:
branches: ['master']
workflow_dispatch:
permissions:
contents: read
jobs:
http-suite:
name: E2E over HTTP (containment, sanitisation, CORS, limits, legit flows)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Node.js
uses: actions/setup-node@v4
with:
# Match the runtime the shipped container image uses, so the gate
# exercises the same Node major as a deployed instance.
node-version: '22'
cache: npm
- name: Install dependencies
run: npm ci
# The compiled client bundle is no longer committed (issue #42), so build
# it before running the suite — the security-headers test reads
# src/public/index.html for its CSP inline-script assertions.
- name: Build the dashboard client
run: cd src/client && npm install && npm run build
# Serialised: several files spawn their own real instance and the suites
# share the on-disk storage root, so running them in parallel makes the
# directory snapshots race and the instances contend for the same port.
# `npm test` is `node --test-concurrency=1 --test "test/**/*.test.js"`, so
# it keeps that serialisation while also gating the unit-level regression
# guards that naming the e2e files individually left unable to fail a PR.
# The container image assertion is part of the glob but skips itself here:
# its runtime half is guarded on TAS_IMAGE, which only the job below sets.
- name: Run the full test suite
run: npm test
dependency-audit:
name: Production dependency advisories (high/critical gate)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: '22'
cache: npm
- name: Install dependencies
run: npm ci
# Issue #71: `npm audit` never ran in CI, so a new high/critical advisory
# in the production manifest shipped silently. The gate fails on any
# unlisted high/critical advisory and on stale allowlist entries; every
# exception lives in .github/audit-allowlist.json with a written reason
# naming the issue that owns its fix.
- name: Gate on production dependency advisories
run: node scripts/audit-gate.js
container:
name: Container image runs as non-root
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Build the TaS container image
run: docker build -t montimage/tas:e2e .
# Issue #45: the composition is a shipped artifact — validate its
# schema, variable interpolation and health-check wiring on every PR.
- name: Validate the service composition
run: docker compose config -q
- name: Assert the built image runs as a non-root user
run: node --test test/e2e/container-nonroot.test.js
env:
TAS_IMAGE: montimage/tas:e2e
lint:
name: Lint (eslint)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: '22'
cache: npm
- name: Install dependencies
run: npm ci
# Issue #24: the suite gate exercised behaviour, but nothing ran static
# analysis on a pull request. A dedicated job rather than a step of the
# suite job, so lint reports independently of the database-backed suites.
- name: Run eslint
run: npm run lint