Harden internal-JWT minting, pin RS256, dedupe key-ring rejection (#53) #109
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build | |
| on: | |
| workflow_dispatch: | |
| push: | |
| branches: [ main, release/v** ] | |
| pull_request: | |
| branches: [ main ] | |
| # Dependabot PRs run with a read-only GITHUB_TOKEN by default. The | |
| # EnricoMi/publish-unit-test-result-action step calls POST /check-runs | |
| # (needs `checks: write`) and may comment on PRs (`pull-requests: write`). | |
| # Without this explicit block, the action 403s on every dependabot PR | |
| # even when the build + tests themselves are green. Matches the same | |
| # block in xavierjohn/Trellis's build.yml. | |
| permissions: | |
| contents: read | |
| checks: write | |
| pull-requests: write | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v7 | |
| with: | |
| fetch-depth: 0 # needed for nbgv | |
| - name: Setup .NET | |
| uses: actions/setup-dotnet@v5 | |
| with: | |
| global-json-file: global.json | |
| - name: Cache NuGet packages | |
| uses: actions/cache@v6 | |
| with: | |
| path: ~/.nuget/packages | |
| key: ${{ runner.os }}-nuget-${{ hashFiles('**/*.csproj', '**/Directory.Packages.props') }} | |
| restore-keys: | | |
| ${{ runner.os }}-nuget- | |
| - name: Setup versioning | |
| run: | | |
| dotnet tool install --global nbgv | |
| nbgv cloud | |
| - name: Restore dependencies | |
| run: dotnet restore Trellis.Microservices.slnx | |
| - name: Build | |
| run: dotnet build Trellis.Microservices.slnx --no-restore -c Release | |
| - name: Test with Coverage | |
| # --coverage: Native MTP coverage (requires Microsoft.Testing.Extensions.CodeCoverage) | |
| # --report-trx: Native MTP TRX generation (requires Microsoft.Testing.Extensions.TrxReport) | |
| # MTP writes TRX to TestResults/ relative to each test project directory; | |
| # coverage path is set explicitly via --coverage-output. | |
| run: | | |
| dotnet test Trellis.Microservices.slnx --no-build -c Release \ | |
| --coverage --coverage-output-format cobertura --coverage-output coverage.cobertura.xml \ | |
| --report-trx | |
| - name: Publish Test Results | |
| uses: EnricoMi/publish-unit-test-result-action@v2 | |
| if: always() | |
| with: | |
| files: | | |
| **/TestResults/**/*.trx | |
| - name: Upload Coverage to Codecov | |
| uses: codecov/codecov-action@v7 | |
| if: always() | |
| with: | |
| # MTP writes coverage relative to each test project; search recursively | |
| files: ./**/*.cobertura.xml | |
| token: ${{ secrets.CODECOV_TOKEN }} | |
| fail_ci_if_error: false | |
| - name: Doc-lint API reference | |
| shell: pwsh | |
| run: pwsh docs/lint-api-reference.ps1 | |
| - name: Pack | |
| if: ${{ success() && !github.base_ref }} | |
| run: dotnet pack Trellis.Microservices.slnx --no-build --verbosity normal -c Release -o artifacts/ | |
| - name: Upload artifacts | |
| uses: actions/upload-artifact@v7 | |
| if: ${{ success() && !github.base_ref }} | |
| with: | |
| name: artifact | |
| path: artifacts/ |