mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-03 05:10:16 +03:00
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 9.0.0 to 10.0.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/setup-uv/releases">astral-sh/setup-uv's releases</a>.</em></p> <blockquote> <h2>v10.0.1 🌈 Tolerate transient manifest timeouts</h2> <h2>Changes</h2> <p>Thank you <a href="https://github.com/arguile"><code>@arguile</code></a>- for making this action more resilient.</p> <h2>🐛 Bug fixes</h2> <ul> <li>Tolerate transient manifest timeouts <a href="https://github.com/arguile"><code>@arguile</code></a>- (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1016">#1016</a>)</li> </ul> <h2>🧰 Maintenance</h2> <ul> <li>chore: update known checksums for 0.12.4 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1017">#1017</a>)</li> </ul> <h2>📚 Documentation</h2> <ul> <li>docs: update version references to v10.0.0 @<a href="https://github.com/apps/github-actions">github-actions[bot]</a> (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1014">#1014</a>)</li> </ul> <h2>v10.0.0 🌈 Disable automatic caching for sensitive events and new QOL features</h2> <h2>Changes</h2> <p>Another breaking release, directly after v9.0.0 but we think the added security justifies that.</p> <h3>Extra security by default</h3> <p>If you use the default <code>enable-cache: auto</code> this will now <strong>DISABLE THE CACHE</strong> to protect against cache poisoning for the following events:</p> <ul> <li><code>pull_request_target</code></li> <li><code>workflow_run</code></li> <li><code>release</code></li> </ul> <p>You can read the full reasoning in <a href="https://redirect.github.com/astral-sh/setup-uv/issues/984">astral-sh/setup-uv#984</a></p> <h3><code>version: latest-known</code></h3> <pre lang="yaml"><code>- name: Install the latest version of uv known to setup-uv uses: astral-sh/setup-uv@v10.0.0 with: version: "latest-known" </code></pre> <p>This will now install the latest version with a checksum that is known by this action. The <a href="https://github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts">known <code>uv</code> checksums</a> are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security.</p> <h3>Read python version from <code>.tool-versions</code></h3> <pre lang="yaml"><code>- name: Install uv based on the version defined in .tool-versions and also set python uses: astral-sh/setup-uv@v10.0.0 with: version-file: "pyproject.toml" </tr></table> </code></pre> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/setup-uv/commit/20cfd1bf945f4377ade1205e4dbc17946fc9a30d"><code>20cfd1b</code></a> chore: update known checksums for 0.12.4 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1017">#1017</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/d73a0cab66a532d7afa440d9df4a67ea9fe65a30"><code>d73a0ca</code></a> Tolerate transient manifest timeouts (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1016">#1016</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/ae3b92d1bdb308a10adfe7b8f408e5cc8c30f3f6"><code>ae3b92d</code></a> docs: update version references to v10.0.0 (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1014">#1014</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/ae62891fec2bb8e7d6c99fc78c9fec3a63790f8d"><code>ae62891</code></a> chore(deps): roll up Dependabot updates (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1013">#1013</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/f9cdb47d487aee2be8925d1e57290177ad9e1ac2"><code>f9cdb47</code></a> Reject paths in .tool-versions (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1007">#1007</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/4f6036f71cec78afb113b323f220c9185d983c12"><code>4f6036f</code></a> Require pull requests for Dependabot rollups (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1005">#1005</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/8d6402c9b71205b2d8d0b82de531d8fed8430182"><code>8d6402c</code></a> chore(deps): roll up Dependabot updates (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/1004">#1004</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/46f427bd47c794e99536b75ffaa9f27602425027"><code>46f427b</code></a> Read Python version from .tool-versions (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/996">#996</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/8ed89c51143f65ea13eaba62db51dbb8ea52d0a3"><code>8ed89c5</code></a> ci: pin Alpine container image (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/995">#995</a>)</li> <li><a href="https://github.com/astral-sh/setup-uv/commit/8473c7fea42cdfd540f4b01317a17ac5f54126ae"><code>8473c7f</code></a> chore(deps): roll up Dependabot updates (<a href="https://redirect.github.com/astral-sh/setup-uv/issues/994">#994</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/setup-uv/compare/c771a70e6277c0a99b617c7a806ffedaca235ff9...20cfd1bf945f4377ade1205e4dbc17946fc9a30d">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
221 lines
10 KiB
YAML
221 lines
10 KiB
YAML
name: Playwright E2E (live backend)
|
|
|
|
# Reusable workflow called from build.yml. Live-backend Playwright suite —
|
|
# boots Spring Boot and runs auth + real tool round-trips against the live
|
|
# server.
|
|
on:
|
|
workflow_call:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
playwright-e2e-live:
|
|
environment:
|
|
name: ci-unsigned
|
|
deployment: false
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
|
|
with:
|
|
egress-policy: audit
|
|
- name: Checkout repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Restore cache Gradle User Home
|
|
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
|
with:
|
|
path: |
|
|
~/.gradle/caches
|
|
~/.gradle/wrapper
|
|
key: gradle-v1-${{ runner.os }}-${{ runner.arch }}-jdk-25-${{ hashFiles('gradle/wrapper/gradle-wrapper.properties', 'gradle/libs.versions.toml', 'buildSrc/**', 'settings.gradle', 'build.gradle', 'app/**/build.gradle', 'gradle/**/*.gradle') }}
|
|
|
|
- name: Set up JDK 25
|
|
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
|
|
with:
|
|
java-version: "25"
|
|
distribution: "temurin"
|
|
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
cache-dependency-path: frontend/package-lock.json
|
|
- name: Install Task
|
|
uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2.1.0
|
|
- name: Install Playwright (chromium only)
|
|
run: task e2e:install -- chromium
|
|
- name: Build frontend (production bundle for vite preview)
|
|
env:
|
|
VITE_BUILD_FOR_PREVIEW: "1"
|
|
run: task frontend:build
|
|
- name: Run live E2E tests (chromium) with coverage
|
|
id: live-tests
|
|
env:
|
|
# Attaches the JaCoCo agent to the bootRun JVM (see
|
|
# .taskfiles/e2e.yml live:backend). The .exec gets flushed on
|
|
# graceful shutdown when the runner traps EXIT/INT/TERM, so the
|
|
# report step below sees a populated file.
|
|
COVERAGE: "1"
|
|
# Tells the Playwright fixture (test-base.ts) to capture per-test
|
|
# V8 JS coverage. Raw dumps land under
|
|
# .test-state/playwright/coverage-pw/ for the post-process step
|
|
# to aggregate. Chromium-only - other engines silently skip.
|
|
PW_COVERAGE: "1"
|
|
PLAYWRIGHT_JSON_OUTPUT_FILE: ${{ github.workspace }}/frontend/playwright-report/results.json
|
|
# Internal mirror, as in backend-build.yml. Empty on Dependabot and
|
|
# fork PRs, where the build falls back to Maven Central.
|
|
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
|
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
|
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
|
run: task e2e:live
|
|
- name: Flag flaky tests
|
|
# Runs regardless of the test outcome: a flaky test (passed on retry)
|
|
# leaves the step green, so this is the only place it surfaces. Emits
|
|
# ::warning:: annotations + a job summary; never fails the job.
|
|
if: always()
|
|
working-directory: frontend
|
|
run: npx tsx editor/scripts/report-flaky-tests.mts "$PLAYWRIGHT_JSON_OUTPUT_FILE"
|
|
env:
|
|
PLAYWRIGHT_JSON_OUTPUT_FILE: ${{ github.workspace }}/frontend/playwright-report/results.json
|
|
- name: Generate JaCoCo report from e2e:live .exec
|
|
if: always()
|
|
id: live-coverage
|
|
env:
|
|
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
|
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
|
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
|
# `if: always()` so even a failed test run still produces a
|
|
# report from whatever flows did exercise the backend before
|
|
# the failure. The task itself tolerates a missing .exec
|
|
# (jacoco emits an empty report rather than crashing) but we
|
|
# guard with `test -s` to keep the job log clean.
|
|
run: |
|
|
if [ -s .test-state/playwright/jacoco.exec ]; then
|
|
./gradlew jacocoReportFromExec \
|
|
-PexecFile=.test-state/playwright/jacoco.exec \
|
|
-PreportDir=build/reports/jacoco/e2e-live \
|
|
-PnoSpotless
|
|
echo "report=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "::warning::No e2e:live .exec found at .test-state/playwright/jacoco.exec; skipping report"
|
|
echo "report=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
- name: Install uv
|
|
if: always()
|
|
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
|
|
with:
|
|
enable-cache: true
|
|
cache-dependency-glob: |
|
|
engine/pyproject.toml
|
|
engine/uv.lock
|
|
- name: e2e:live coverage step summary
|
|
if: always() && steps.live-coverage.outputs.report == 'true'
|
|
run: |
|
|
uv run --project engine --locked --group tools python scripts/coverage-summary.py \
|
|
--title "Playwright (live backend) JaCoCo coverage" \
|
|
--jacoco "e2e-live=build/reports/jacoco/e2e-live/jacocoTestReport.xml" \
|
|
--github-step-summary
|
|
- name: Upload e2e:live JaCoCo report
|
|
if: always() && steps.live-coverage.outputs.report == 'true'
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: jacoco-e2e-live-${{ github.run_id }}
|
|
path: build/reports/jacoco/e2e-live/
|
|
retention-days: 7
|
|
|
|
- name: Upload raw e2e:live .exec for aggregate merge
|
|
# Picked up by the coverage-aggregate workflow via the
|
|
# `jacoco-exec-*` artifact name pattern.
|
|
if: always() && steps.live-coverage.outputs.report == 'true'
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: jacoco-exec-e2e-live
|
|
path: .test-state/playwright/jacoco.exec
|
|
retention-days: 7
|
|
if-no-files-found: warn
|
|
|
|
- name: Aggregate Playwright frontend (V8) coverage
|
|
# Rolls per-test V8 dumps from the test-base fixture into one
|
|
# vitest-shaped coverage-summary.json. Tolerates a missing dump
|
|
# dir (firefox/webkit runs, or a failure before any test got
|
|
# far enough to dump).
|
|
if: always()
|
|
id: pw-frontend-coverage
|
|
run: |
|
|
if [ -d .test-state/playwright/coverage-pw ] && \
|
|
find .test-state/playwright/coverage-pw -name '*.json' -type f | grep -q .; then
|
|
uv run --project engine --locked --group tools python scripts/playwright-coverage-summary.py \
|
|
.test-state/playwright/coverage-pw \
|
|
--out .test-state/playwright/coverage-pw-summary/coverage-summary.json
|
|
echo "summary=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "::notice::No Playwright frontend coverage dumps found (chromium-only feature)"
|
|
echo "summary=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- name: Playwright frontend coverage step summary
|
|
if: always() && steps.pw-frontend-coverage.outputs.summary == 'true'
|
|
run: |
|
|
uv run --project engine --locked --group tools python scripts/coverage-summary.py \
|
|
--title "Playwright (live) frontend coverage" \
|
|
--vitest .test-state/playwright/coverage-pw-summary/coverage-summary.json \
|
|
--github-step-summary
|
|
|
|
- name: Upload Playwright frontend coverage
|
|
# Bundle both the aggregated summary and the raw V8 dumps so
|
|
# someone debugging "why is this function showing as covered"
|
|
# can trace it back to the source dump.
|
|
if: always() && steps.pw-frontend-coverage.outputs.summary == 'true'
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: playwright-frontend-coverage
|
|
path: |
|
|
.test-state/playwright/coverage-pw-summary/
|
|
.test-state/playwright/coverage-pw/
|
|
retention-days: 7
|
|
|
|
- name: Print backend log on failure
|
|
if: failure() && steps.live-tests.conclusion == 'failure'
|
|
run: |
|
|
echo "::group::Spring Boot backend log (last 500 lines)"
|
|
tail -500 .test-state/playwright/backend.log || echo "no backend log found"
|
|
echo "::endgroup::"
|
|
- name: Upload backend log
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: backend-log-live-${{ github.run_id }}
|
|
path: .test-state/playwright/backend.log
|
|
retention-days: 7
|
|
- name: List Playwright output locations (debug)
|
|
if: always()
|
|
run: |
|
|
echo "::group::Playwright output dirs"
|
|
# Playwright anchors its default outputDir + HTML report to the
|
|
# nearest package.json, which is frontend/ (frontend/editor has
|
|
# none), so artifacts land under frontend/, not frontend/editor/.
|
|
ls -la frontend/playwright-report 2>/dev/null \
|
|
|| echo "no playwright-report at frontend/"
|
|
ls -la frontend/test-results 2>/dev/null \
|
|
|| echo "no test-results at frontend/"
|
|
find . -name node_modules -prune -o -name 'trace.zip' -print 2>/dev/null || true
|
|
echo "::endgroup::"
|
|
- name: Upload Playwright report + traces
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: playwright-report-live-${{ github.run_id }}
|
|
# test-results/ holds the per-test trace.zip (with browser console
|
|
# logs) + screenshots/video; playwright-report/ is the HTML report.
|
|
# Both live under frontend/ (Playwright anchors them to the nearest
|
|
# package.json, which is frontend/; frontend/editor has none).
|
|
path: |
|
|
frontend/playwright-report/
|
|
frontend/test-results/
|
|
retention-days: 7
|
|
if-no-files-found: warn
|