diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 8c247d5..de5c36b 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -18,14 +18,28 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 with: fetch-depth: 0 + - name: Determine validation scope + id: scope + shell: bash + run: | + base_sha="${{ gitea.event.pull_request.base.sha }}" + if git diff --quiet "$base_sha...HEAD" -- . ':(exclude).gitea/workflows/**'; then + echo "full=false" >> "$GITEA_OUTPUT" + echo "Workflow-only change: the protected lightweight gate is sufficient." + else + echo "full=true" >> "$GITEA_OUTPUT" + echo "Product or test change: running the complete acceptance gate." + fi - name: Secret scan uses: trufflesecurity/trufflehog@b9dd330365132cd2d01dd5dc8a857a056a2544e1 # v3.79.0 with: path: ./ extra_args: --only-verified - name: Backend tests in isolated PostgreSQL stack + if: steps.scope.outputs.full == 'true' run: sh scripts/run-isolated-tests.sh - name: Backend static and contract checks + if: steps.scope.outputs.full == 'true' run: | docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml run --build --rm api ruff check app tests docker compose -p mobilityops-ci -f compose.yaml -f compose.test.yaml run --rm api mypy app @@ -33,14 +47,17 @@ jobs: -v "$PWD:/repo:ro" api python /repo/scripts/check-contracts.py python scripts/check-source-budgets.py - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 + if: steps.scope.outputs.full == 'true' with: node-version: 22 cache: npm cache-dependency-path: frontend/package-lock.json - name: Install frontend dependencies once + if: steps.scope.outputs.full == 'true' working-directory: frontend run: npm ci --no-audit --no-fund - name: Frontend lint, build, budget and dependency audit + if: steps.scope.outputs.full == 'true' working-directory: frontend run: | npm run lint @@ -48,6 +65,7 @@ jobs: npm run budget npm audit --audit-level=high - name: Start the demo stack + if: steps.scope.outputs.full == 'true' run: | cp .env.example .env # Acceptance tests intentionally reset their isolated demo dataset per scenario. @@ -61,9 +79,11 @@ jobs: curl -fsS http://web/health/ready docker compose -p mobilityops-e2e exec -T api python -m app.cli seed --reset - name: Install acceptance browsers + if: steps.scope.outputs.full == 'true' working-directory: frontend run: npx playwright install --with-deps chromium - name: Run browser acceptance and live smoke suites + if: steps.scope.outputs.full == 'true' working-directory: frontend env: MOBILITYOPS_PUBLIC_URL: http://web @@ -72,9 +92,10 @@ jobs: npx playwright test --grep-invert "visual hierarchy" npx playwright test --config=playwright.live.config.ts --project=chromium - name: Run concurrent persisted-read smoke + if: steps.scope.outputs.full == 'true' run: python scripts/run-readonly-load-smoke.py --base-url http://web - name: Upload Playwright report - if: failure() + if: failure() && steps.scope.outputs.full == 'true' uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3; Gitea-compatible artifact protocol with: name: playwright-report @@ -83,10 +104,10 @@ jobs: frontend/playwright-live-report if-no-files-found: ignore - name: Stack logs on failure - if: failure() + if: failure() && steps.scope.outputs.full == 'true' run: docker compose -p mobilityops-e2e logs --tail=200 api web - name: Remove CI stacks - if: always() + if: always() && steps.scope.outputs.full == 'true' run: | docker network disconnect mobilityops-e2e_mobilityops "$HOSTNAME" 2>/dev/null || true docker compose -p mobilityops-e2e down -v --remove-orphans