refactor(client): adopt Redux Toolkit slices for state layer (#43) (#… #108
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: E2E Security Regression Suite | |
| on: | |
| push: | |
| branches: ['master'] | |
| pull_request: | |
| branches: ['master'] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| http-suite: | |
| name: E2E over HTTP (containment, sanitisation, CORS, limits, legit flows) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| # Match the runtime the shipped container image uses, so the gate | |
| # exercises the same Node major as a deployed instance. | |
| node-version: '22' | |
| cache: npm | |
| - name: Install dependencies | |
| run: npm ci | |
| # The compiled client bundle is no longer committed (issue #42), so build | |
| # it before running the suite — the security-headers test reads | |
| # src/public/index.html for its CSP inline-script assertions. | |
| - name: Build the dashboard client | |
| run: cd src/client && npm install && npm run build | |
| # Serialised: several files spawn their own real instance and the suites | |
| # share the on-disk storage root, so running them in parallel makes the | |
| # directory snapshots race and the instances contend for the same port. | |
| # `npm test` is `node --test-concurrency=1 --test "test/**/*.test.js"`, so | |
| # it keeps that serialisation while also gating the unit-level regression | |
| # guards that naming the e2e files individually left unable to fail a PR. | |
| # The container image assertion is part of the glob but skips itself here: | |
| # its runtime half is guarded on TAS_IMAGE, which only the job below sets. | |
| - name: Run the full test suite | |
| run: npm test | |
| dependency-audit: | |
| name: Production dependency advisories (high/critical gate) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '22' | |
| cache: npm | |
| - name: Install dependencies | |
| run: npm ci | |
| # Issue #71: `npm audit` never ran in CI, so a new high/critical advisory | |
| # in the production manifest shipped silently. The gate fails on any | |
| # unlisted high/critical advisory and on stale allowlist entries; every | |
| # exception lives in .github/audit-allowlist.json with a written reason | |
| # naming the issue that owns its fix. | |
| - name: Gate on production dependency advisories | |
| run: node scripts/audit-gate.js | |
| container: | |
| name: Container image runs as non-root | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Build the TaS container image | |
| run: docker build -t montimage/tas:e2e . | |
| # Issue #45: the composition is a shipped artifact — validate its | |
| # schema, variable interpolation and health-check wiring on every PR. | |
| - name: Validate the service composition | |
| run: docker compose config -q | |
| - name: Assert the built image runs as a non-root user | |
| run: node --test test/e2e/container-nonroot.test.js | |
| env: | |
| TAS_IMAGE: montimage/tas:e2e | |
| lint: | |
| name: Lint (eslint) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@v4 | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '22' | |
| cache: npm | |
| - name: Install dependencies | |
| run: npm ci | |
| # Issue #24: the suite gate exercised behaviour, but nothing ran static | |
| # analysis on a pull request. A dedicated job rather than a step of the | |
| # suite job, so lint reports independently of the database-backed suites. | |
| - name: Run eslint | |
| run: npm run lint |