Skip to content

Merge pull request #80 from SecureToolsProject/test/sprint-16c-v2.1-r… #63

Merge pull request #80 from SecureToolsProject/test/sprint-16c-v2.1-r…

Merge pull request #80 from SecureToolsProject/test/sprint-16c-v2.1-r… #63

Workflow file for this run

name: CI
on:
pull_request:
push:
branches:
- main
- v2
- v2.1
permissions:
contents: read
jobs:
validate:
name: Validate static tools
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Check out repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Enforce pull request branch policy
if: github.event_name == 'pull_request'
shell: bash
env:
BASE_REF: ${{ github.base_ref }}
HEAD_REF: ${{ github.head_ref }}
run: |
if [[ "$BASE_REF" == "v2.1" ]]; then
if [[ "$HEAD_REF" =~ ^(feat|fix|test|chore)/.+$ ]]; then
exit 0
fi
echo "::error::Pull requests into v2.1 must come from feat/*, fix/*, test/*, or chore/* branches."
exit 1
fi
if [[ "$BASE_REF" == "main" ]]; then
if [[ "$HEAD_REF" == "v2.1" || "$HEAD_REF" =~ ^hotfix/.+$ ]]; then
exit 0
fi
echo "::error::Only v2.1 release promotion or an explicit hotfix/* branch may target main."
exit 1
fi
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: 24
- name: Check changed files for whitespace errors
shell: bash
env:
BASE_SHA: ${{ github.event.pull_request.base.sha || github.event.before }}
HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: |
if [[ "$BASE_SHA" =~ ^0+$ ]]; then
git show --check --format= "$HEAD_SHA"
else
git diff --check "$BASE_SHA...$HEAD_SHA"
fi
- name: Install pinned OCR build inputs
run: npm ci --ignore-scripts
- name: Verify prepared production OCR assets
run: npm run build
- name: Run static tool validation
run: npm test
- name: Run real local OCR smoke test
run: node tests/ocr-smoke.test.mjs