Repository navigation
Merge pull request #621 from brazilian-utils/hyan/eloquent-hamilton-1… #1056
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Check | |
| on: | |
| pull_request: | |
| types: [opened, synchronize, reopened, ready_for_review] | |
| push: | |
| branches: [main] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | |
| # A newer push to a pull request supersedes its run; a push to main always finishes, so the | |
| # badges never show a cancelled run as failing. | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| permissions: | |
| contents: read | |
| jobs: | |
| check: | |
| name: Check | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Setup | |
| uses: ./.github/actions/setup | |
| - name: Run checks | |
| run: vp check | |
| - name: Check commit messages | |
| if: ${{ github.event_name == 'pull_request' }} | |
| run: npx commitlint --from "${{ github.event.pull_request.base.sha }}" --to HEAD --verbose | |
| - name: Check the package has no runtime dependencies | |
| run: npm run check:dependencies | |
| - name: Check the lockfile | |
| run: npm run check:lockfile | |
| - name: Check for duplicated code | |
| run: npm run check:duplication | |
| - name: Check for unused files, exports and dependencies | |
| run: npm run check:unused | |
| - name: Validate the public API | |
| run: npm run check:api | |
| - name: Check llms.txt/llms-full.txt build from the docs | |
| run: npm run build:llms | |
| - name: Check the JSR exports are up to date | |
| run: npm run build:jsr && git diff --exit-code -- jsr.json | |
| - name: Build the documentation site | |
| # The site is generated at deploy time (the Docs workflow), so nothing here can be stale; | |
| # this only has to fail when a generator does. | |
| run: npm run build:docs | |
| - name: Check the VEX statements against the suppressed advisories | |
| run: npm run check:vex | |
| - name: Audit dependencies | |
| run: npx --yes audit-ci@7.1.0 --high --allowlist GHSA-jmr9-qjv8-65gv GHSA-7pqw-9j4j-h8q3 |