mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-03 05:10:16 +03:00
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.20.0 to 2.21.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/step-security/harden-runner/releases">step-security/harden-runner's releases</a>.</em></p> <blockquote> <h2>v2.21.0</h2> <h2>What's Changed</h2> <ul> <li>Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries.</li> <li>Improved Support for AWS CodeBuild GitHub Actions Runners.</li> <li>Bug fixes.</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.20.1...v2.21.0">https://github.com/step-security/harden-runner/compare/v2.20.1...v2.21.0</a></p> <h2>v2.20.1</h2> <h2>What's Changed</h2> <ul> <li>AWS CodeBuild-hosted runner support</li> <li>Implicitly allow single-labeled (internal) domains in block-mode</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1">https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/step-security/harden-runner/commit/05e31511f85b41b11d1cf0ef85d0992719546e2c"><code>05e3151</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/684">#684</a> from step-security/rc-42</li> <li><a href="https://github.com/step-security/harden-runner/commit/0f37afa338f57c61ee3dfc274daca8834963d83e"><code>0f37afa</code></a> fix: ignore denied-endpoints on non-enterprise tier</li> <li><a href="https://github.com/step-security/harden-runner/commit/93b58ee491c5b6cf3a5324966fca2908f8d447f3"><code>93b58ee</code></a> fix: resolve cache host read-first and never downgrade egress policy</li> <li><a href="https://github.com/step-security/harden-runner/commit/e7399dd3e93d6c159d314af54b4704bc48abf6bc"><code>e7399dd</code></a> fix: align deny-list mode detection with agent and log when both endpoint inp...</li> <li><a href="https://github.com/step-security/harden-runner/commit/c16689f716a10cdfd9cfe22e63938b8c6c0657de"><code>c16689f</code></a> test: add denied_endpoints to Configuration fixtures and cover deny-list merge</li> <li><a href="https://github.com/step-security/harden-runner/commit/40b99cf0c7161e4dcdc6c5508927188b65028df9"><code>40b99cf</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/682">#682</a> from rohan-stepsecurity/rp/feat/codebuild-self-v2</li> <li><a href="https://github.com/step-security/harden-runner/commit/fedec027a205365a7d64001a81931e4c36a1af6e"><code>fedec02</code></a> Merge branch 'rc-42' into rp/feat/codebuild-self-v2</li> <li><a href="https://github.com/step-security/harden-runner/commit/5361fb178b926b2be6df52e11ee257823821567b"><code>5361fb1</code></a> feat: add build artifacts</li> <li><a href="https://github.com/step-security/harden-runner/commit/286474fffe0b8fe7c9db855f132d04a9b48ab564"><code>286474f</code></a> feat: Support Bravo agent install on CodeBuild runners</li> <li><a href="https://github.com/step-security/harden-runner/commit/051ec05283d064bd82f41279db4f70f0717bf778"><code>051ec05</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/683">#683</a> from h0x0er/jatin/deny-list</li> <li>Additional commits viewable in <a href="https://github.com/step-security/harden-runner/compare/v2.20.0...05e31511f85b41b11d1cf0ef85d0992719546e2c">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
198 lines
6.9 KiB
YAML
198 lines
6.9 KiB
YAML
name: Nightly E2E Tests
|
|
|
|
on:
|
|
schedule:
|
|
- cron: "0 2 * * *" # 2 AM UTC every night
|
|
workflow_dispatch:
|
|
pull_request:
|
|
paths:
|
|
- .github/workflows/nightly.yml
|
|
- testing/cucumber/**
|
|
- docker/embedded/compose/test_cicd.yml
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
playwright-all-browsers:
|
|
name: Playwright (chromium + firefox + webkit)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Harden the runner (Audit all outbound calls)
|
|
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Checkout repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
cache-dependency-path: frontend/package-lock.json
|
|
|
|
- name: Install Task
|
|
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
|
|
- name: Install all Playwright browsers
|
|
run: task e2e:install
|
|
|
|
- name: Build frontend (production bundle for vite preview)
|
|
env:
|
|
VITE_BUILD_FOR_PREVIEW: "1"
|
|
run: task frontend:build
|
|
|
|
- name: Run E2E tests (all browsers)
|
|
run: task e2e:cross-browser
|
|
|
|
- name: Upload Playwright report
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: playwright-report-nightly-${{ github.run_id }}
|
|
path: frontend/playwright-report/
|
|
retention-days: 14
|
|
|
|
# Whole-suite accessibility sweep. Pull requests only scan the stories they
|
|
# touch (frontend-a11y.yml) because a full pass takes ~30 minutes; this covers
|
|
# everything else, so a violation introduced by a change somewhere other than
|
|
# the story itself — a shared component, a theme token — still surfaces within
|
|
# a day.
|
|
a11y-all-stories:
|
|
name: a11y (every story)
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
theme: [light, dark]
|
|
runs-on: ubuntu-latest
|
|
# One full sweep (~30 minutes of browser time).
|
|
timeout-minutes: 60
|
|
steps:
|
|
- name: Harden the runner (Audit all outbound calls)
|
|
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Checkout repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
cache-dependency-path: frontend/package-lock.json
|
|
|
|
- name: Install Task
|
|
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
|
|
|
|
- name: a11y gate (every story, ${{ matrix.theme }})
|
|
run: task frontend:storybook:a11y:${{ matrix.theme }}
|
|
|
|
- name: Upload scan reports
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: a11y-scan-nightly-${{ matrix.theme }}-${{ github.run_id }}
|
|
path: frontend/.a11y-scan/
|
|
retention-days: 14
|
|
if-no-files-found: ignore
|
|
# The reports live in a dot-directory, which upload-artifact treats as
|
|
# hidden and silently skips by default.
|
|
include-hidden-files: true
|
|
|
|
# Builds all desktop platforms on a schedule so the Rust dependency cache is
|
|
# written on main, where PR and merge-queue tauri builds can restore it.
|
|
#
|
|
# The only job here still pinned to schedule/main: it primes a cache rather than
|
|
# testing anything, and Actions scopes a cache written on a PR branch to that PR
|
|
# alone, so a PR run costs three platform builds and produces nothing reusable.
|
|
warm-tauri-cache:
|
|
name: Warm Tauri Rust cache
|
|
if: github.event_name == 'schedule' || github.ref == 'refs/heads/main'
|
|
permissions:
|
|
contents: read
|
|
pull-requests: write
|
|
uses: ./.github/workflows/tauri-build.yml
|
|
with:
|
|
platform: all
|
|
sign: false
|
|
secrets: inherit
|
|
|
|
# Runs the @nightly tag (conversion scenarios) plus a 10-shard concurrency run
|
|
# of every other feature.
|
|
cucumber-nightly:
|
|
environment:
|
|
name: ci-unsigned
|
|
deployment: false
|
|
name: Cucumber (nightly scenarios + full concurrency)
|
|
runs-on: ubuntu-latest
|
|
# Fork pull requests get no MAVEN_* secrets, so the image build cannot work.
|
|
if: >-
|
|
github.event_name != 'pull_request' ||
|
|
github.event.pull_request.head.repo.full_name == github.repository
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Harden the runner (Audit all outbound calls)
|
|
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Checkout repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Set up JDK 25
|
|
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
|
|
with:
|
|
java-version: "25"
|
|
distribution: "temurin"
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
|
with:
|
|
enable-cache: true
|
|
cache-dependency-glob: |
|
|
engine/pyproject.toml
|
|
engine/uv.lock
|
|
|
|
- name: Install Task
|
|
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
|
|
|
|
- name: Start the fat image with login and storage enabled
|
|
run: docker compose -f docker/embedded/compose/test_cicd.yml up -d --build
|
|
env:
|
|
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
|
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
|
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
|
|
|
- name: Wait for the server
|
|
# Throwaway key from test_cicd.yml; out of the header literal for gitleaks.
|
|
env:
|
|
TEST_API_KEY: "123456789"
|
|
run: |
|
|
curl --retry 90 --retry-delay 3 --retry-connrefused --retry-all-errors \
|
|
-sf -H "X-API-KEY: $TEST_API_KEY" http://localhost:8080/api/v1/info/status
|
|
|
|
# Heavy LibreOffice/Calibre/Ghostscript conversions, excluded from the PR run.
|
|
# Both tasks install the behave deps themselves, so there is no separate uv sync step.
|
|
- name: Run @nightly scenarios
|
|
run: task cucumber:nightly
|
|
|
|
# Genuinely different payloads contending on one backend.
|
|
- name: Sharded concurrency validation
|
|
run: task cucumber:parallel SHARDS=10
|
|
|
|
- name: Container logs on failure
|
|
if: failure()
|
|
run: docker compose -f docker/embedded/compose/test_cicd.yml logs --tail 400
|
|
|
|
- name: Tear down
|
|
if: always()
|
|
run: docker compose -f docker/embedded/compose/test_cicd.yml down -v
|