mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-03 05:10:16 +03:00
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.20.0 to 2.21.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/step-security/harden-runner/releases">step-security/harden-runner's releases</a>.</em></p> <blockquote> <h2>v2.21.0</h2> <h2>What's Changed</h2> <ul> <li>Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries.</li> <li>Improved Support for AWS CodeBuild GitHub Actions Runners.</li> <li>Bug fixes.</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.20.1...v2.21.0">https://github.com/step-security/harden-runner/compare/v2.20.1...v2.21.0</a></p> <h2>v2.20.1</h2> <h2>What's Changed</h2> <ul> <li>AWS CodeBuild-hosted runner support</li> <li>Implicitly allow single-labeled (internal) domains in block-mode</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1">https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/step-security/harden-runner/commit/05e31511f85b41b11d1cf0ef85d0992719546e2c"><code>05e3151</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/684">#684</a> from step-security/rc-42</li> <li><a href="https://github.com/step-security/harden-runner/commit/0f37afa338f57c61ee3dfc274daca8834963d83e"><code>0f37afa</code></a> fix: ignore denied-endpoints on non-enterprise tier</li> <li><a href="https://github.com/step-security/harden-runner/commit/93b58ee491c5b6cf3a5324966fca2908f8d447f3"><code>93b58ee</code></a> fix: resolve cache host read-first and never downgrade egress policy</li> <li><a href="https://github.com/step-security/harden-runner/commit/e7399dd3e93d6c159d314af54b4704bc48abf6bc"><code>e7399dd</code></a> fix: align deny-list mode detection with agent and log when both endpoint inp...</li> <li><a href="https://github.com/step-security/harden-runner/commit/c16689f716a10cdfd9cfe22e63938b8c6c0657de"><code>c16689f</code></a> test: add denied_endpoints to Configuration fixtures and cover deny-list merge</li> <li><a href="https://github.com/step-security/harden-runner/commit/40b99cf0c7161e4dcdc6c5508927188b65028df9"><code>40b99cf</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/682">#682</a> from rohan-stepsecurity/rp/feat/codebuild-self-v2</li> <li><a href="https://github.com/step-security/harden-runner/commit/fedec027a205365a7d64001a81931e4c36a1af6e"><code>fedec02</code></a> Merge branch 'rc-42' into rp/feat/codebuild-self-v2</li> <li><a href="https://github.com/step-security/harden-runner/commit/5361fb178b926b2be6df52e11ee257823821567b"><code>5361fb1</code></a> feat: add build artifacts</li> <li><a href="https://github.com/step-security/harden-runner/commit/286474fffe0b8fe7c9db855f132d04a9b48ab564"><code>286474f</code></a> feat: Support Bravo agent install on CodeBuild runners</li> <li><a href="https://github.com/step-security/harden-runner/commit/051ec05283d064bd82f41279db4f70f0717bf778"><code>051ec05</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/683">#683</a> from h0x0er/jatin/deny-list</li> <li>Additional commits viewable in <a href="https://github.com/step-security/harden-runner/compare/v2.20.0...05e31511f85b41b11d1cf0ef85d0992719546e2c">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
221 lines
10 KiB
YAML
221 lines
10 KiB
YAML
name: Playwright E2E (live backend)
|
|
|
|
# Reusable workflow called from build.yml. Live-backend Playwright suite —
|
|
# boots Spring Boot and runs auth + real tool round-trips against the live
|
|
# server.
|
|
on:
|
|
workflow_call:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
playwright-e2e-live:
|
|
environment:
|
|
name: ci-unsigned
|
|
deployment: false
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
|
|
with:
|
|
egress-policy: audit
|
|
- name: Checkout repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Restore cache Gradle User Home
|
|
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
|
with:
|
|
path: |
|
|
~/.gradle/caches
|
|
~/.gradle/wrapper
|
|
key: gradle-v1-${{ runner.os }}-${{ runner.arch }}-jdk-25-${{ hashFiles('gradle/wrapper/gradle-wrapper.properties', 'gradle/libs.versions.toml', 'buildSrc/**', 'settings.gradle', 'build.gradle', 'app/**/build.gradle', 'gradle/**/*.gradle') }}
|
|
|
|
- name: Set up JDK 25
|
|
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
|
|
with:
|
|
java-version: "25"
|
|
distribution: "temurin"
|
|
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
cache-dependency-path: frontend/package-lock.json
|
|
- name: Install Task
|
|
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
|
|
- name: Install Playwright (chromium only)
|
|
run: task e2e:install -- chromium
|
|
- name: Build frontend (production bundle for vite preview)
|
|
env:
|
|
VITE_BUILD_FOR_PREVIEW: "1"
|
|
run: task frontend:build
|
|
- name: Run live E2E tests (chromium) with coverage
|
|
id: live-tests
|
|
env:
|
|
# Attaches the JaCoCo agent to the bootRun JVM (see
|
|
# .taskfiles/e2e.yml live:backend). The .exec gets flushed on
|
|
# graceful shutdown when the runner traps EXIT/INT/TERM, so the
|
|
# report step below sees a populated file.
|
|
COVERAGE: "1"
|
|
# Tells the Playwright fixture (test-base.ts) to capture per-test
|
|
# V8 JS coverage. Raw dumps land under
|
|
# .test-state/playwright/coverage-pw/ for the post-process step
|
|
# to aggregate. Chromium-only - other engines silently skip.
|
|
PW_COVERAGE: "1"
|
|
PLAYWRIGHT_JSON_OUTPUT_FILE: ${{ github.workspace }}/frontend/playwright-report/results.json
|
|
# Internal mirror, as in backend-build.yml. Empty on Dependabot and
|
|
# fork PRs, where the build falls back to Maven Central.
|
|
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
|
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
|
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
|
run: task e2e:live
|
|
- name: Flag flaky tests
|
|
# Runs regardless of the test outcome: a flaky test (passed on retry)
|
|
# leaves the step green, so this is the only place it surfaces. Emits
|
|
# ::warning:: annotations + a job summary; never fails the job.
|
|
if: always()
|
|
working-directory: frontend
|
|
run: npx tsx editor/scripts/report-flaky-tests.mts "$PLAYWRIGHT_JSON_OUTPUT_FILE"
|
|
env:
|
|
PLAYWRIGHT_JSON_OUTPUT_FILE: ${{ github.workspace }}/frontend/playwright-report/results.json
|
|
- name: Generate JaCoCo report from e2e:live .exec
|
|
if: always()
|
|
id: live-coverage
|
|
env:
|
|
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
|
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
|
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
|
# `if: always()` so even a failed test run still produces a
|
|
# report from whatever flows did exercise the backend before
|
|
# the failure. The task itself tolerates a missing .exec
|
|
# (jacoco emits an empty report rather than crashing) but we
|
|
# guard with `test -s` to keep the job log clean.
|
|
run: |
|
|
if [ -s .test-state/playwright/jacoco.exec ]; then
|
|
./gradlew jacocoReportFromExec \
|
|
-PexecFile=.test-state/playwright/jacoco.exec \
|
|
-PreportDir=build/reports/jacoco/e2e-live \
|
|
-PnoSpotless
|
|
echo "report=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "::warning::No e2e:live .exec found at .test-state/playwright/jacoco.exec; skipping report"
|
|
echo "report=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
- name: Install uv
|
|
if: always()
|
|
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
|
with:
|
|
enable-cache: true
|
|
cache-dependency-glob: |
|
|
engine/pyproject.toml
|
|
engine/uv.lock
|
|
- name: e2e:live coverage step summary
|
|
if: always() && steps.live-coverage.outputs.report == 'true'
|
|
run: |
|
|
uv run --project engine --locked --group tools python scripts/coverage-summary.py \
|
|
--title "Playwright (live backend) JaCoCo coverage" \
|
|
--jacoco "e2e-live=build/reports/jacoco/e2e-live/jacocoTestReport.xml" \
|
|
--github-step-summary
|
|
- name: Upload e2e:live JaCoCo report
|
|
if: always() && steps.live-coverage.outputs.report == 'true'
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: jacoco-e2e-live-${{ github.run_id }}
|
|
path: build/reports/jacoco/e2e-live/
|
|
retention-days: 7
|
|
|
|
- name: Upload raw e2e:live .exec for aggregate merge
|
|
# Picked up by the coverage-aggregate workflow via the
|
|
# `jacoco-exec-*` artifact name pattern.
|
|
if: always() && steps.live-coverage.outputs.report == 'true'
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: jacoco-exec-e2e-live
|
|
path: .test-state/playwright/jacoco.exec
|
|
retention-days: 7
|
|
if-no-files-found: warn
|
|
|
|
- name: Aggregate Playwright frontend (V8) coverage
|
|
# Rolls per-test V8 dumps from the test-base fixture into one
|
|
# vitest-shaped coverage-summary.json. Tolerates a missing dump
|
|
# dir (firefox/webkit runs, or a failure before any test got
|
|
# far enough to dump).
|
|
if: always()
|
|
id: pw-frontend-coverage
|
|
run: |
|
|
if [ -d .test-state/playwright/coverage-pw ] && \
|
|
find .test-state/playwright/coverage-pw -name '*.json' -type f | grep -q .; then
|
|
uv run --project engine --locked --group tools python scripts/playwright-coverage-summary.py \
|
|
.test-state/playwright/coverage-pw \
|
|
--out .test-state/playwright/coverage-pw-summary/coverage-summary.json
|
|
echo "summary=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "::notice::No Playwright frontend coverage dumps found (chromium-only feature)"
|
|
echo "summary=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- name: Playwright frontend coverage step summary
|
|
if: always() && steps.pw-frontend-coverage.outputs.summary == 'true'
|
|
run: |
|
|
uv run --project engine --locked --group tools python scripts/coverage-summary.py \
|
|
--title "Playwright (live) frontend coverage" \
|
|
--vitest .test-state/playwright/coverage-pw-summary/coverage-summary.json \
|
|
--github-step-summary
|
|
|
|
- name: Upload Playwright frontend coverage
|
|
# Bundle both the aggregated summary and the raw V8 dumps so
|
|
# someone debugging "why is this function showing as covered"
|
|
# can trace it back to the source dump.
|
|
if: always() && steps.pw-frontend-coverage.outputs.summary == 'true'
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: playwright-frontend-coverage
|
|
path: |
|
|
.test-state/playwright/coverage-pw-summary/
|
|
.test-state/playwright/coverage-pw/
|
|
retention-days: 7
|
|
|
|
- name: Print backend log on failure
|
|
if: failure() && steps.live-tests.conclusion == 'failure'
|
|
run: |
|
|
echo "::group::Spring Boot backend log (last 500 lines)"
|
|
tail -500 .test-state/playwright/backend.log || echo "no backend log found"
|
|
echo "::endgroup::"
|
|
- name: Upload backend log
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: backend-log-live-${{ github.run_id }}
|
|
path: .test-state/playwright/backend.log
|
|
retention-days: 7
|
|
- name: List Playwright output locations (debug)
|
|
if: always()
|
|
run: |
|
|
echo "::group::Playwright output dirs"
|
|
# Playwright anchors its default outputDir + HTML report to the
|
|
# nearest package.json, which is frontend/ (frontend/editor has
|
|
# none), so artifacts land under frontend/, not frontend/editor/.
|
|
ls -la frontend/playwright-report 2>/dev/null \
|
|
|| echo "no playwright-report at frontend/"
|
|
ls -la frontend/test-results 2>/dev/null \
|
|
|| echo "no test-results at frontend/"
|
|
find . -name node_modules -prune -o -name 'trace.zip' -print 2>/dev/null || true
|
|
echo "::endgroup::"
|
|
- name: Upload Playwright report + traces
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: playwright-report-live-${{ github.run_id }}
|
|
# test-results/ holds the per-test trace.zip (with browser console
|
|
# logs) + screenshots/video; playwright-report/ is the HTML report.
|
|
# Both live under frontend/ (Playwright anchors them to the nearest
|
|
# package.json, which is frontend/; frontend/editor has none).
|
|
path: |
|
|
frontend/playwright-report/
|
|
frontend/test-results/
|
|
retention-days: 7
|
|
if-no-files-found: warn
|