feat(admin): FuzzySearch artist lookup client, endpoint, and key setting (SONA-156) #488
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| # The canonical template deliberately skips deploy.yml (no Cloudflare account), | |
| # so its check/test/build never ran anywhere. This runs them ON the canonical | |
| # repo. Forks already run the same steps inside deploy.yml, so this job is gated | |
| # to the canonical repo to avoid duplicating that work on every fork. | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| jobs: | |
| check: | |
| runs-on: ubuntu-latest | |
| if: github.repository == 'sona-fast/sona' | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 24 # match deploy.yml | |
| cache: npm | |
| # Fails if the lockfile resolves a guarded package (FLOORS in | |
| # scripts/check-lockfile-security-lib.mjs) below its security | |
| # floor — npm before 8.3 ignores the "pkg@<range>" override | |
| # keys, so an old-npm lockfile regen would revert them silently. Reads | |
| # package-lock.json only (no dependencies), so it runs BEFORE `npm ci`: | |
| # after it, a downgraded package's install scripts have already run. | |
| - run: npm run check:lockfile-security | |
| - run: npm ci | |
| - run: npm run check | |
| - run: npm test | |
| - run: npm run build | |
| # Fails if a client chunk carries most of the message catalog — a | |
| # computed-key lookup into the paraglide namespace re-pinning it | |
| # (SONA-169). Needs the build output above. | |
| - run: npm run check:catalog-pinning | |
| # Integration test for the local-dev self-bootstrap (#137): needs real wrangler | |
| # + a local D1 (miniflare), so it's out of the fast unit suite and run here. | |
| # Gated to the canonical repo like `check`/`e2e`; forks skip it (their deploy.yml | |
| # already runs check/test/build). | |
| integration: | |
| runs-on: ubuntu-latest | |
| if: github.repository == 'sona-fast/sona' | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 24 # match deploy.yml | |
| cache: npm | |
| # Same pre-`npm ci` security floor guard as the `check` job (see there). | |
| - run: npm run check:lockfile-security | |
| - run: npm ci | |
| - run: npm run test:integration | |
| # Browser E2E (playwright). Separate from the unit suite so `npm test` stays | |
| # fast; gated to the canonical repo like `check`, and skipped on forks (their | |
| # deploy.yml already runs check/test/build). | |
| e2e: | |
| runs-on: ubuntu-latest | |
| if: github.repository == 'sona-fast/sona' | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 24 # match deploy.yml | |
| cache: npm | |
| # Same pre-`npm ci` security floor guard as the `check` job (see there). | |
| - run: npm run check:lockfile-security | |
| - run: npm ci | |
| - name: Cache Playwright browsers | |
| uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| with: | |
| path: ~/.cache/ms-playwright | |
| key: playwright-${{ runner.os }}-${{ hashFiles('package-lock.json') }} | |
| - run: npx playwright install --with-deps chromium | |
| - run: npm run test:e2e |