name: Frontend lint, type-check, and build # Reusable workflow called from build.yml when frontend / testing sources # change. Runs `task frontend:check:all` and uploads the # coverage + dist artifacts for downstream jobs. on: workflow_call: permissions: contents: read pull-requests: write jobs: frontend-validation: runs-on: ubuntu-latest steps: - name: Harden Runner uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0 with: egress-policy: audit - name: Checkout repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Set up Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "22" cache: "npm" cache-dependency-path: frontend/package-lock.json - name: Install Task uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0 - name: Quality-check frontend id: frontend-check run: task frontend:check:all continue-on-error: true - name: Comment on frontend check failure # Only post a comment on PRs. github-script's PR helpers need an # issue/PR number, which doesn't exist on merge_group runs. if: steps.frontend-check.outcome == 'failure' && github.event_name == 'pull_request' continue-on-error: true uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const marker = ''; const body = [ marker, '### Frontend Check Failed', '', 'There are issues with your frontend code that will need to be fixed before they can be merged in.', '', 'Run `task frontend:fix` to auto-fix what can be fixed automatically, then run `task frontend:check:all` to see what still needs fixing manually.', ].join('\n'); const { data: comments } = await github.rest.issues.listComments({ owner: context.repo.owner, repo: context.repo.repo, issue_number: context.issue.number, }); const existing = comments.find(c => c.body.includes(marker)); if (existing) { await github.rest.issues.updateComment({ owner: context.repo.owner, repo: context.repo.repo, comment_id: existing.id, body, }); } else { await github.rest.issues.createComment({ owner: context.repo.owner, repo: context.repo.repo, issue_number: context.issue.number, body, }); } - name: Fail if frontend check failed if: steps.frontend-check.outcome == 'failure' run: | echo "============================================" echo " Frontend Check Failed" echo "============================================" echo "" echo "There are issues with your frontend code that" echo "will need to be fixed before they can be merged in." echo "" echo "Run 'task frontend:fix' to auto-fix what can be" echo "fixed automatically, then run 'task frontend:check:all'" echo "to see what still needs fixing manually." echo "============================================" exit 1 - name: Remove frontend check comment on success if: steps.frontend-check.outcome == 'success' && github.event_name == 'pull_request' continue-on-error: true uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: script: | const marker = ''; const { data: comments } = await github.rest.issues.listComments({ owner: context.repo.owner, repo: context.repo.repo, issue_number: context.issue.number, }); const existing = comments.find(c => c.body.includes(marker)); if (existing) { await github.rest.issues.deleteComment({ owner: context.repo.owner, repo: context.repo.repo, comment_id: existing.id, }); } - name: Install uv if: always() uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 with: enable-cache: true cache-dependency-glob: | engine/pyproject.toml engine/uv.lock - name: Vitest coverage step summary if: always() run: | uv run --project engine --locked --group tools python scripts/coverage-summary.py \ --title "Frontend Vitest coverage" \ --vitest frontend/editor/coverage/coverage-summary.json \ --github-step-summary - name: Upload vitest coverage report if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-coverage path: frontend/editor/coverage/ retention-days: 7 if-no-files-found: warn - name: Upload frontend build artifacts uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-build path: frontend/editor/dist/ retention-days: 3