mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-02 21:03:34 +03:00
# Description of Changes This change adds cleanup steps to GitHub Actions workflows that create temporary files or sensitive build resources. Changes include: - Removing temporary backend helper files, logs, and PID files. - Cleaning up database migration temporary directories after failure logs are uploaded. - Removing locally generated deployment files and Storybook archives. - Deleting temporary signing certificates, MSI extraction directories, and Apple signing keychains. - Ensuring cleanup runs even when earlier workflow steps fail. The cleanup reduces temporary data retention on runners and ensures sensitive signing material is removed after builds. No functional application code was changed. --- ## Checklist ### General - [ ] I have read the [Contribution Guidelines](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/CONTRIBUTING.md) - [ ] I have read the [Stirling-PDF Developer Guide](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/DeveloperGuide.md) (if applicable) - [ ] I have read the [How to add new languages to Stirling-PDF](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/devGuide/HowToAddNewLanguage.md) (if applicable) - [ ] I have performed a self-review of my own code - [ ] My changes generate no new warnings ### Documentation - [ ] I have updated relevant docs on [Stirling-PDF's doc repo](https://github.com/Stirling-Tools/Stirling-Tools.github.io/blob/main/docs/) (if functionality has heavily changed) - [ ] I have read the section [Add New Translation Tags](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/devGuide/HowToAddNewLanguage.md#add-new-translation-tags) (for new translation tags only) ### Translations (if applicable) - [ ] I ran [`scripts/counter_translation.py`](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/docs/counter_translation.md) ### UI Changes (if applicable) - [ ] Screenshots or videos demonstrating the UI changes are attached (e.g., as comments or direct attachments in the PR) ### Testing (if applicable) - [ ] I have run `task check` to verify linters, typechecks, and tests pass - [ ] I have tested my changes locally. Refer to the [Testing Guide](https://github.com/Stirling-Tools/Stirling-PDF/blob/main/DeveloperGuide.md#7-testing) for more details.
89 lines
3.2 KiB
YAML
89 lines
3.2 KiB
YAML
name: DB migration smoke test
|
|
|
|
# Boots the current Stirling-PDF JAR against H2 fixtures captured from past
|
|
# releases (v2.0.0 / v2.5.0 / v2.10.0) and verifies admin login still works.
|
|
# Catches schema changes that would break existing user databases under
|
|
# Hibernate's `ddl-auto=update` upgrade path.
|
|
|
|
on:
|
|
workflow_call:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
migration-test:
|
|
environment:
|
|
name: ci-unsigned
|
|
deployment: false
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Checkout repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Restore cache Gradle User Home
|
|
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
|
with:
|
|
path: |
|
|
~/.gradle/caches
|
|
~/.gradle/wrapper
|
|
key: gradle-v1-${{ runner.os }}-${{ runner.arch }}-jdk-25-${{ hashFiles('gradle/wrapper/gradle-wrapper.properties', 'gradle/libs.versions.toml', 'buildSrc/**', 'settings.gradle', 'build.gradle', 'app/**/build.gradle', 'gradle/**/*.gradle') }}
|
|
|
|
- name: Set up JDK 25
|
|
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5.7.0
|
|
with:
|
|
java-version: 25
|
|
distribution: temurin
|
|
|
|
# Keep the normal formatting path here so this smoke test exercises the
|
|
# same Gradle configuration as the backend build.
|
|
- name: Build Stirling-PDF JAR
|
|
env:
|
|
MAVEN_USER: ${{ secrets.MAVEN_USER }}
|
|
MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }}
|
|
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
|
|
run: ./gradlew :stirling-pdf:bootJar -PnoSpotless --no-daemon
|
|
|
|
- name: Locate built JAR
|
|
id: jar
|
|
run: |
|
|
jar=$(find app/core/build/libs -maxdepth 1 -name 'Stirling-PDF*.jar' -o -name 'stirling-pdf*.jar' 2>/dev/null \
|
|
| grep -vE '(-plain|-sources)\.jar$' | head -n 1)
|
|
if [[ -z "$jar" ]]; then
|
|
echo "::error::No JAR under app/core/build/libs"
|
|
ls -lah app/core/build/libs || true
|
|
exit 1
|
|
fi
|
|
# Absolute path - the migration script pushd's into a temp workdir
|
|
# before invoking java, which would dangle a relative path.
|
|
jar=$(realpath "$jar")
|
|
echo "path=$jar" >> "$GITHUB_OUTPUT"
|
|
echo "Built JAR: $jar"
|
|
|
|
- name: Run migration smoke test
|
|
env:
|
|
STIRLING_JAR: ${{ steps.jar.outputs.path }}
|
|
run: bash scripts/db-migration/run-migration-test.sh
|
|
|
|
- name: Upload app logs on failure
|
|
if: failure()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: db-migration-app-logs
|
|
# Path matches the preserved workdir in run-migration-test.sh -
|
|
# only failing fixtures leave a directory behind.
|
|
path: /tmp/stirling-migration-failed-*/app.log
|
|
retention-days: 7
|
|
if-no-files-found: warn
|
|
|
|
- name: Cleanup temporary files
|
|
if: always()
|
|
run: rm -rf /tmp/stirling-migration-failed-*
|
|
continue-on-error: true
|