Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 31 additions & 16 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
name: CI

on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:

defaults:
run:
working-directory: anythingmcp

jobs:
backend:
name: Backend (lint, test, build)
name: Backend (lint, typecheck, test, build)
runs-on: ubuntu-latest

services:
Expand All @@ -29,8 +29,10 @@ jobs:

env:
DATABASE_URL: postgresql://amcp:testpassword@localhost:5432/anythingmcp_test
JWT_SECRET: ci-test-jwt-secret-at-least-32-chars
ENCRYPTION_KEY: ci-test-encryption-key-32-chars!
# CI-only secrets — long enough to pass our boot validation, never used
# outside the test database.
JWT_SECRET: ci-test-jwt-secret-at-least-32-chars-aaaaaa
ENCRYPTION_KEY: ci-test-encryption-key-32-chars-aaaaaaaa

steps:
- uses: actions/checkout@v4
Expand All @@ -39,29 +41,36 @@ jobs:
with:
node-version: 22
cache: npm
cache-dependency-path: anythingmcp/package-lock.json

- name: Install dependencies
run: npm ci

- name: Generate Prisma client
run: npx prisma generate
working-directory: anythingmcp/packages/backend
working-directory: packages/backend

- name: Run Prisma migrations
run: npx prisma migrate deploy
working-directory: anythingmcp/packages/backend
working-directory: packages/backend

- name: Lint
run: npm run lint
working-directory: packages/backend

- name: Type-check
run: npx tsc --noEmit -p tsconfig.json
working-directory: packages/backend

- name: Run tests
run: npm test
working-directory: anythingmcp/packages/backend
working-directory: packages/backend

- name: Build backend
run: npm run build
working-directory: anythingmcp/packages/backend
working-directory: packages/backend

frontend:
name: Frontend (build)
name: Frontend (lint, typecheck, build)
runs-on: ubuntu-latest

steps:
Expand All @@ -71,14 +80,21 @@ jobs:
with:
node-version: 22
cache: npm
cache-dependency-path: anythingmcp/package-lock.json

- name: Install dependencies
run: npm ci

- name: Lint
run: npm run lint
working-directory: packages/frontend

- name: Type-check
run: npx tsc --noEmit -p tsconfig.json
working-directory: packages/frontend

- name: Build frontend
run: npm run build
working-directory: anythingmcp/packages/frontend
working-directory: packages/frontend
env:
NEXT_PUBLIC_API_URL: http://localhost:4000

Expand All @@ -93,4 +109,3 @@ jobs:

- name: Build unified image
run: docker build -t anythingmcp:ci .
working-directory: anythingmcp
41 changes: 41 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
name: CodeQL

on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
# Weekly Monday 06:00 UTC, in case dependencies introduce new advisories.
- cron: '0 6 * * 1'

jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [javascript-typescript]

steps:
- uses: actions/checkout@v4

- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
queries: security-and-quality

- name: Autobuild
uses: github/codeql-action/autobuild@v3

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
category: "/language:${{ matrix.language }}"
77 changes: 77 additions & 0 deletions .github/workflows/trivy.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
name: Trivy

on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
# Daily — new CVEs land in the Trivy DB constantly.
- cron: '0 5 * * *'

jobs:
filesystem:
name: Filesystem scan
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write

steps:
- uses: actions/checkout@v4

- name: Run Trivy filesystem scan
uses: aquasecurity/trivy-action@master
with:
scan-type: fs
scan-ref: .
format: sarif
output: trivy-fs.sarif
ignore-unfixed: true
severity: CRITICAL,HIGH
# Lockfiles + Dockerfile + IaC. Skips secrets to avoid false positives
# on test fixtures; we already enforce required-secret validation at
# boot.
scanners: vuln,misconfig
skip-dirs: node_modules,.next,dist
env:
TRIVY_DISABLE_VEX_NOTICE: "true"

- name: Upload Trivy SARIF
if: always()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: trivy-fs.sarif
category: trivy-fs

image:
name: Docker image scan
runs-on: ubuntu-latest
if: github.event_name != 'pull_request'
permissions:
contents: read
security-events: write

steps:
- uses: actions/checkout@v4

- name: Build image
run: docker build -t anythingmcp:scan .

- name: Run Trivy image scan
uses: aquasecurity/trivy-action@master
with:
image-ref: anythingmcp:scan
format: sarif
output: trivy-image.sarif
ignore-unfixed: true
severity: CRITICAL,HIGH
env:
TRIVY_DISABLE_VEX_NOTICE: "true"

- name: Upload Trivy image SARIF
if: always()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: trivy-image.sarif
category: trivy-image
Loading
Loading