Skip to content

feat(admin): FuzzySearch artist lookup client, endpoint, and key setting (SONA-156) #488

feat(admin): FuzzySearch artist lookup client, endpoint, and key setting (SONA-156)

feat(admin): FuzzySearch artist lookup client, endpoint, and key setting (SONA-156) #488

Workflow file for this run

name: CI
# The canonical template deliberately skips deploy.yml (no Cloudflare account),
# so its check/test/build never ran anywhere. This runs them ON the canonical
# repo. Forks already run the same steps inside deploy.yml, so this job is gated
# to the canonical repo to avoid duplicating that work on every fork.
on:
push:
branches: [main]
pull_request:
jobs:
check:
runs-on: ubuntu-latest
if: github.repository == 'sona-fast/sona'
permissions:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24 # match deploy.yml
cache: npm
# Fails if the lockfile resolves a guarded package (FLOORS in
# scripts/check-lockfile-security-lib.mjs) below its security
# floor — npm before 8.3 ignores the "pkg@<range>" override
# keys, so an old-npm lockfile regen would revert them silently. Reads
# package-lock.json only (no dependencies), so it runs BEFORE `npm ci`:
# after it, a downgraded package's install scripts have already run.
- run: npm run check:lockfile-security
- run: npm ci
- run: npm run check
- run: npm test
- run: npm run build
# Fails if a client chunk carries most of the message catalog — a
# computed-key lookup into the paraglide namespace re-pinning it
# (SONA-169). Needs the build output above.
- run: npm run check:catalog-pinning
# Integration test for the local-dev self-bootstrap (#137): needs real wrangler
# + a local D1 (miniflare), so it's out of the fast unit suite and run here.
# Gated to the canonical repo like `check`/`e2e`; forks skip it (their deploy.yml
# already runs check/test/build).
integration:
runs-on: ubuntu-latest
if: github.repository == 'sona-fast/sona'
permissions:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24 # match deploy.yml
cache: npm
# Same pre-`npm ci` security floor guard as the `check` job (see there).
- run: npm run check:lockfile-security
- run: npm ci
- run: npm run test:integration
# Browser E2E (playwright). Separate from the unit suite so `npm test` stays
# fast; gated to the canonical repo like `check`, and skipped on forks (their
# deploy.yml already runs check/test/build).
e2e:
runs-on: ubuntu-latest
if: github.repository == 'sona-fast/sona'
permissions:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24 # match deploy.yml
cache: npm
# Same pre-`npm ci` security floor guard as the `check` job (see there).
- run: npm run check:lockfile-security
- run: npm ci
- name: Cache Playwright browsers
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ~/.cache/ms-playwright
key: playwright-${{ runner.os }}-${{ hashFiles('package-lock.json') }}
- run: npx playwright install --with-deps chromium
- run: npm run test:e2e