name: CI on: push: branches: [main] pull_request: branches: [main] merge_group: workflow_dispatch: concurrency: group: ci-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} env: # CI does not use the CUDA execution provider, and the onnxruntime-node # postinstall download from NuGet is large enough to make npm ci flaky. ONNXRUNTIME_NODE_INSTALL: skip jobs: format: runs-on: ubuntu-latest env: # This job never executes Electron. Skipping the hosted binary avoids # unrelated npm ci failures when Electron's CDN returns 504. ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies run: node scripts/npm-retry.mjs ci - name: Check formatting run: npx oxfmt --check . lint: runs-on: ubuntu-latest env: ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies run: node scripts/npm-retry.mjs ci - name: Lint lockfile run: npx --yes lockfile-lint --path package-lock.json --type npm --allowed-hosts npm --validate-https --validate-integrity - name: Verify dependency signatures run: npm audit signatures - name: Lint run: npm run lint typecheck: runs-on: ubuntu-latest env: ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies run: node scripts/npm-retry.mjs ci - name: Build server stack run: npm run build:server - name: Typecheck all packages run: npm run typecheck - name: Verify public package contents run: | npm pack --dry-run --ignore-scripts --workspace=@getpaseo/protocol npm pack --dry-run --ignore-scripts --workspace=@getpaseo/client npm pack --dry-run --ignore-scripts --workspace=@getpaseo/server npm run verify:package --workspace=@getpaseo/migrate server-tests: strategy: fail-fast: false matrix: os: [ubuntu-latest, windows-latest] runs-on: ${{ matrix.os }} name: server-tests (${{ matrix.os }}) env: ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 with: fetch-depth: 0 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Fetch origin/main (worktree tests) run: git fetch --no-tags origin main:refs/remotes/origin/main - name: Install dependencies run: node scripts/npm-retry.mjs ci - name: Install agent CLIs for provider tests run: node scripts/npm-retry.mjs install -g @anthropic-ai/claude-code opencode-ai - name: Build server dependencies run: npm run build:server-deps - name: Run server tests run: npm run test --workspace=@getpaseo/server env: CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }} OPENROUTER_API_KEY: ${{ secrets.OPENROUTER_API_KEY }} desktop-tests: strategy: fail-fast: false matrix: os: [ubuntu-latest, windows-latest] runs-on: ${{ matrix.os }} timeout-minutes: 30 permissions: contents: read pull-requests: read steps: - uses: actions/checkout@v4 - name: Detect desktop changes if: matrix.os == 'ubuntu-latest' id: desktop_changes uses: dorny/paths-filter@v3 with: filters: | desktop: - 'packages/desktop/**' - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies with retry run: node scripts/npm-retry.mjs ci - name: Build server stack run: npm run build:server - name: Run desktop tests run: npm run test --workspace=@getpaseo/desktop - name: Build app dependencies for desktop E2E if: matrix.os == 'ubuntu-latest' run: npm run build:app-deps - name: Install virtual display if: matrix.os == 'ubuntu-latest' run: sudo apt-get update && sudo apt-get install -y xvfb xauth - name: Run real Electron browser tab bridge E2E if: matrix.os == 'ubuntu-latest' run: npm run test:e2e:browser-tab-bridge --workspace=@getpaseo/desktop env: PASEO_TAB_BRIDGE_E2E_ARTIFACT_DIR: ${{ runner.temp }}/browser-tab-bridge-e2e - name: Upload browser tab bridge diagnostics uses: actions/upload-artifact@v4 if: failure() && matrix.os == 'ubuntu-latest' with: name: browser-tab-bridge-e2e path: ${{ runner.temp }}/browser-tab-bridge-e2e if-no-files-found: ignore retention-days: 7 - name: Build and smoke unpacked desktop app if: matrix.os == 'ubuntu-latest' && steps.desktop_changes.outputs.desktop == 'true' run: npm run build:desktop -- --publish never --linux --x64 --dir env: EP_GH_IGNORE_TIME: true PASEO_DESKTOP_SMOKE: "1" PASEO_DESKTOP_SMOKE_ARTIFACT_DIR: ${{ runner.temp }}/desktop-smoke - name: Upload packaged smoke diagnostics if: failure() && matrix.os == 'ubuntu-latest' && steps.desktop_changes.outputs.desktop == 'true' uses: actions/upload-artifact@v4 with: name: desktop-packaged-smoke-linux-x64 path: ${{ runner.temp }}/desktop-smoke if-no-files-found: ignore retention-days: 7 migration-electron: runs-on: macos-latest timeout-minutes: 30 steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies with retry run: node scripts/npm-retry.mjs ci - name: Build app and server dependencies run: | npm run build:app-deps npm run build:server - name: Build migrator and Desktop main run: | npm run build --workspace=@getpaseo/migrate npm run build:main --workspace=@getpaseo/desktop - name: Run product migration behavior run: npm run test:migration-electron --workspace=@getpaseo/desktop - name: Upload migration behavior diagnostics if: failure() uses: actions/upload-artifact@v4 with: name: migration-electron-macos path: | packages/app/test-results/ packages/app/playwright-report/ retention-days: 7 app-tests: runs-on: ubuntu-latest env: ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies with retry run: node scripts/npm-retry.mjs ci - name: Install Playwright browsers timeout-minutes: 10 run: npx playwright install chromium - name: Build app dependencies run: npm run build:app-deps - name: Run app unit tests run: npm run test --workspace=@getpaseo/app sdk-tests: runs-on: ubuntu-latest env: ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies run: node scripts/npm-retry.mjs ci - name: Build client dependencies run: npm run build:client - name: Run protocol tests run: npm run test --workspace=@getpaseo/protocol - name: Run client tests run: npm run test --workspace=@getpaseo/client - name: Run migrator tests run: npm run test --workspace=@getpaseo/migrate - name: Typecheck client examples run: npm run typecheck:examples --workspace=@getpaseo/client migrator-node18: runs-on: ubuntu-latest env: ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "18" cache: "npm" - name: Install dependencies run: node scripts/npm-retry.mjs ci - name: Build published migrator run: | npm run build:server-deps npm run build --workspace=@getpaseo/migrate - name: Exercise the published CLI on Node 18 run: node packages/migrate/dist/cli.js conductor --database packages/migrate/fixtures/conductor/conductor.db --dry-run - name: Verify published package contents run: npm run verify:package --workspace=@getpaseo/migrate playwright: strategy: fail-fast: false matrix: include: - { label: "shard 1/4", shard: 1, desktop: false } - { label: "shard 2/4", shard: 2, desktop: false } - { label: "shard 3/4", shard: 3, desktop: false } - { label: "shard 4/4", shard: 4, desktop: false } - { label: "desktop overlay", shard: "desktop", desktop: true } name: playwright (${{ matrix.label }}) runs-on: ubuntu-latest env: ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies with retry run: node scripts/npm-retry.mjs ci - name: Install Playwright browsers timeout-minutes: 10 run: npx playwright install chromium - name: Build app dependencies run: npm run build:app-deps - name: Build server stack run: npm run build:server - name: Install agent CLIs for provider tests if: ${{ !matrix.desktop }} run: node scripts/npm-retry.mjs install -g @anthropic-ai/claude-code @openai/codex@0.105.0 opencode-ai - name: Run Playwright E2E tests if: ${{ !matrix.desktop }} run: npm run test:e2e --workspace=@getpaseo/app -- --shard=${{ matrix.shard }}/4 env: OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }} - name: Run desktop-overlay Playwright tests if: ${{ matrix.desktop }} run: npm run test:e2e:desktop --workspace=@getpaseo/app - name: Upload test artifacts uses: actions/upload-artifact@v4 if: failure() with: name: playwright-results-${{ matrix.shard }} path: | packages/app/test-results/ packages/app/playwright-report/ retention-days: 7 relay-tests: runs-on: ubuntu-latest env: ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies run: node scripts/npm-retry.mjs ci - name: Build relay run: npm run build:relay - name: Run relay tests run: npm run test --workspace=@getpaseo/relay cli-tests: strategy: fail-fast: false matrix: shard: [1, 2, 3] runs-on: ubuntu-latest name: cli-tests (shard ${{ matrix.shard }}/3) env: ELECTRON_SKIP_BINARY_DOWNLOAD: "1" steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: "22" cache: "npm" - name: Install dependencies run: node scripts/npm-retry.mjs ci - name: Install agent CLIs for provider tests run: node scripts/npm-retry.mjs install -g @anthropic-ai/claude-code @openai/codex@0.105.0 opencode-ai - name: Run CLI tests run: npm run test --workspace=@getpaseo/cli env: PASEO_LOCAL_SPEECH_AUTO_DOWNLOAD: "0" PASEO_DICTATION_ENABLED: "0" PASEO_VOICE_MODE_ENABLED: "0" PASEO_CLI_TEST_SHARD: ${{ matrix.shard }} PASEO_CLI_TEST_SHARD_TOTAL: "3"