chore: update codeyam state #163
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| # Supersede in-flight runs for the same ref — codeyam state commits often land | |
| # in quick succession and only the latest one needs a verdict. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| # Least privilege: nothing here writes to the repo. The repo-wide default is | |
| # `write`, which this overrides. release.yml declares its own contents:write. | |
| permissions: | |
| contents: read | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| # Runs take ~1 min; the GitHub default cap is 360, so a hung job would sit | |
| # burning runner minutes for six hours. | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version: 22 | |
| cache: npm | |
| - run: npm ci | |
| # Production deps only — those are the ones that end up in the packaged | |
| # extension. The dev toolchain carries known advisories whose fixes are | |
| # major bumps (vite, vitest); Dependabot surfaces those as reviewable PRs | |
| # instead of wedging every unrelated CI run red. | |
| - run: npm audit --omit=dev --audit-level=high | |
| - run: npm run lint | |
| - run: npm test | |
| - run: npm run build | |
| # Guards a real regression: an earlier package shipped internal URLs and | |
| # scenario mock data. See store/UPLOAD-GUIDE.md. Release runs this too, | |
| # but catching it on the PR beats catching it at the tag. | |
| - name: Verify no codeyam artifacts or internal URLs in build | |
| run: | | |
| if grep -rlE "codeyam|s2/favicons|notion\.so|fonts\.googleapis" build; then | |
| echo "::error::build/ contains codeyam artifacts or internal URLs" | |
| exit 1 | |
| fi | |
| # Separate job so it runs alongside `build` rather than lengthening it. | |
| # Complements `npm audit`, which only sees production deps at high+: this | |
| # inspects what the diff actually introduces, dev deps included. Free on | |
| # public repos. | |
| dependency-review: | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/dependency-review-action@v5 | |
| with: | |
| fail-on-severity: high |