chore: establish v2.1 development safety gate #58
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| push: | |
| branches: | |
| - main | |
| - v2 | |
| - v2.1 | |
| permissions: | |
| contents: read | |
| jobs: | |
| validate: | |
| name: Validate static tools | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Enforce pull request branch policy | |
| if: github.event_name == 'pull_request' | |
| shell: bash | |
| env: | |
| BASE_REF: ${{ github.base_ref }} | |
| HEAD_REF: ${{ github.head_ref }} | |
| run: | | |
| if [[ "$BASE_REF" == "v2.1" ]]; then | |
| if [[ "$HEAD_REF" =~ ^(feat|fix|test|chore)/.+$ ]]; then | |
| exit 0 | |
| fi | |
| echo "::error::Pull requests into v2.1 must come from feat/*, fix/*, test/*, or chore/* branches." | |
| exit 1 | |
| fi | |
| if [[ "$BASE_REF" == "main" ]]; then | |
| if [[ "$HEAD_REF" == "v2.1" || "$HEAD_REF" =~ ^hotfix/.+$ ]]; then | |
| exit 0 | |
| fi | |
| echo "::error::Only v2.1 release promotion or an explicit hotfix/* branch may target main." | |
| exit 1 | |
| fi | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: 24 | |
| - name: Check changed files for whitespace errors | |
| shell: bash | |
| env: | |
| BASE_SHA: ${{ github.event.pull_request.base.sha || github.event.before }} | |
| HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }} | |
| run: | | |
| if [[ "$BASE_SHA" =~ ^0+$ ]]; then | |
| git show --check --format= "$HEAD_SHA" | |
| else | |
| git diff --check "$BASE_SHA...$HEAD_SHA" | |
| fi | |
| - name: Install pinned OCR build inputs | |
| run: npm ci --ignore-scripts | |
| - name: Verify prepared production OCR assets | |
| run: npm run build | |
| - name: Run static tool validation | |
| run: npm test | |
| - name: Run real local OCR smoke test | |
| run: node tests/ocr-smoke.test.mjs |