mirror of
https://github.com/getpaseo/paseo.git
synced 2026-07-29 12:01:31 +00:00
* perf(ci): skip unaffected test jobs Keep required checks present as skipped jobs and run the full matrix whenever change detection cannot produce a trustworthy result. * fix(ci): harden change-based job gating Include shared build inputs in packaged desktop smoke selection and pin the path filter action that controls job execution. * fix(ci): run CLI checks for Nix packaging changes The CLI supervision regression suite reads the Nix package definition directly, so include that external dependency in its path filter. * fix(ci): track external test inputs Select server and CLI suites when their narrowly scoped cross-package fixtures and source assertions change. * fix(ci): track server test CLI imports Run server tests for CLI source changes because the Hub relationship harness executes the CLI command graph directly. * fix(ci): pin gating checkout action Keep every third-party action that controls change detection pinned to a verified commit SHA.
515 lines
16 KiB
YAML
515 lines
16 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
branches: [main]
|
|
merge_group:
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: ci-${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
|
|
|
|
env:
|
|
# CI does not use the CUDA execution provider, and the onnxruntime-node
|
|
# postinstall download from NuGet is large enough to make npm ci flaky.
|
|
ONNXRUNTIME_NODE_INSTALL: skip
|
|
|
|
jobs:
|
|
changes:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
pull-requests: read
|
|
outputs:
|
|
quality: ${{ steps.filter.outputs.shared != 'false' || steps.filter.outputs.quality != 'false' }}
|
|
server: ${{ steps.filter.outputs.shared != 'false' || steps.filter.outputs.server != 'false' }}
|
|
desktop: ${{ steps.filter.outputs.shared != 'false' || steps.filter.outputs.desktop != 'false' }}
|
|
desktop_package: ${{ steps.filter.outputs.shared != 'false' || steps.filter.outputs.desktop_package != 'false' }}
|
|
app: ${{ steps.filter.outputs.shared != 'false' || steps.filter.outputs.app != 'false' }}
|
|
sdk: ${{ steps.filter.outputs.shared != 'false' || steps.filter.outputs.sdk != 'false' }}
|
|
playwright: ${{ steps.filter.outputs.shared != 'false' || steps.filter.outputs.playwright != 'false' }}
|
|
relay: ${{ steps.filter.outputs.shared != 'false' || steps.filter.outputs.relay != 'false' }}
|
|
cli: ${{ steps.filter.outputs.shared != 'false' || steps.filter.outputs.cli != 'false' }}
|
|
steps:
|
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Detect affected CI jobs
|
|
id: filter
|
|
uses: dorny/paths-filter@d1c1ffe0248fe513906c8e24db8ea791d46f8590 # v3.0.3
|
|
with:
|
|
filters: |
|
|
shared:
|
|
- '.github/workflows/ci.yml'
|
|
- '.github/actions/**'
|
|
- '.mise.toml'
|
|
- '.tool-versions'
|
|
- 'package.json'
|
|
- 'package-lock.json'
|
|
- 'patches/**'
|
|
- 'scripts/**'
|
|
- 'tsconfig.json'
|
|
- 'tsconfig.base.json'
|
|
- 'vitest.config.ts'
|
|
quality:
|
|
- 'packages/**'
|
|
- '*.cjs'
|
|
- '*.js'
|
|
- '*.json'
|
|
- '*.mjs'
|
|
- '*.ts'
|
|
server:
|
|
- 'packages/app/e2e/fixtures/recording.*'
|
|
- 'packages/client/**'
|
|
- 'packages/cli/src/**'
|
|
- 'packages/highlight/**'
|
|
- 'packages/protocol/**'
|
|
- 'packages/relay/**'
|
|
- 'packages/server/**'
|
|
desktop:
|
|
- 'packages/app/**'
|
|
- 'packages/cli/**'
|
|
- 'packages/client/**'
|
|
- 'packages/desktop/**'
|
|
- 'packages/expo-two-way-audio/**'
|
|
- 'packages/highlight/**'
|
|
- 'packages/protocol/**'
|
|
- 'packages/relay/**'
|
|
- 'packages/server/**'
|
|
desktop_package:
|
|
- '.github/workflows/ci.yml'
|
|
- 'packages/desktop/**'
|
|
app:
|
|
- 'packages/app/**'
|
|
- 'packages/client/**'
|
|
- 'packages/expo-two-way-audio/**'
|
|
- 'packages/highlight/**'
|
|
- 'packages/protocol/**'
|
|
- 'packages/relay/**'
|
|
sdk:
|
|
- 'packages/client/**'
|
|
- 'packages/protocol/**'
|
|
- 'packages/relay/**'
|
|
playwright:
|
|
- 'packages/app/**'
|
|
- 'packages/client/**'
|
|
- 'packages/expo-two-way-audio/**'
|
|
- 'packages/highlight/**'
|
|
- 'packages/protocol/**'
|
|
- 'packages/relay/**'
|
|
- 'packages/server/**'
|
|
relay:
|
|
- 'packages/relay/**'
|
|
cli:
|
|
- 'nix/**'
|
|
- 'packages/app/e2e/global-setup.ts'
|
|
- 'packages/cli/**'
|
|
- 'packages/client/**'
|
|
- 'packages/desktop/src/daemon/runtime-paths.ts'
|
|
- 'packages/highlight/**'
|
|
- 'packages/protocol/**'
|
|
- 'packages/relay/**'
|
|
- 'packages/server/**'
|
|
|
|
format:
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
# This job never executes Electron. Skipping the hosted binary avoids
|
|
# unrelated npm ci failures when Electron's CDN returns 504.
|
|
ELECTRON_SKIP_BINARY_DOWNLOAD: "1"
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Install dependencies
|
|
run: node scripts/npm-retry.mjs ci
|
|
|
|
- name: Check formatting
|
|
run: npx oxfmt --check .
|
|
|
|
lint:
|
|
needs: changes
|
|
if: >-
|
|
${{ always() &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.quality != 'false') }}
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
ELECTRON_SKIP_BINARY_DOWNLOAD: "1"
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Install dependencies
|
|
run: node scripts/npm-retry.mjs ci
|
|
|
|
- name: Lint lockfile
|
|
run: npx --yes lockfile-lint --path package-lock.json --type npm --allowed-hosts npm --validate-https --validate-integrity
|
|
|
|
- name: Verify dependency signatures
|
|
run: npm audit signatures
|
|
|
|
- name: Lint
|
|
run: npm run lint
|
|
|
|
typecheck:
|
|
needs: changes
|
|
if: >-
|
|
${{ always() &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.quality != 'false') }}
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
ELECTRON_SKIP_BINARY_DOWNLOAD: "1"
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Install dependencies
|
|
run: node scripts/npm-retry.mjs ci
|
|
- name: Build server stack
|
|
run: npm run build:server
|
|
|
|
- name: Typecheck all packages
|
|
run: npm run typecheck
|
|
|
|
- name: Verify public package contents
|
|
run: |
|
|
npm pack --dry-run --ignore-scripts --workspace=@getpaseo/protocol
|
|
npm pack --dry-run --ignore-scripts --workspace=@getpaseo/client
|
|
npm pack --dry-run --ignore-scripts --workspace=@getpaseo/server
|
|
|
|
server-tests:
|
|
needs: changes
|
|
if: >-
|
|
${{ always() &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.server != 'false') }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
os: [ubuntu-latest, windows-latest]
|
|
runs-on: ${{ matrix.os }}
|
|
name: server-tests (${{ matrix.os }})
|
|
env:
|
|
ELECTRON_SKIP_BINARY_DOWNLOAD: "1"
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Fetch origin/main (worktree tests)
|
|
run: git fetch --no-tags origin main:refs/remotes/origin/main
|
|
|
|
- name: Install dependencies
|
|
run: node scripts/npm-retry.mjs ci
|
|
- name: Install agent CLIs for provider tests
|
|
run: node scripts/npm-retry.mjs install -g @anthropic-ai/claude-code opencode-ai
|
|
|
|
- name: Build server dependencies
|
|
run: npm run build:server-deps
|
|
|
|
- name: Run server tests
|
|
run: npm run test --workspace=@getpaseo/server
|
|
env:
|
|
CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
|
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
|
|
OPENROUTER_API_KEY: ${{ secrets.OPENROUTER_API_KEY }}
|
|
|
|
desktop-tests:
|
|
needs: changes
|
|
if: >-
|
|
${{ always() &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.desktop != 'false') }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
os: [ubuntu-latest, windows-latest]
|
|
runs-on: ${{ matrix.os }}
|
|
timeout-minutes: 30
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Install dependencies with retry
|
|
run: node scripts/npm-retry.mjs ci
|
|
- name: Build server stack
|
|
run: npm run build:server
|
|
|
|
- name: Run desktop tests
|
|
run: npm run test --workspace=@getpaseo/desktop
|
|
|
|
- name: Build app dependencies for desktop E2E
|
|
if: matrix.os == 'ubuntu-latest'
|
|
run: npm run build:app-deps
|
|
|
|
- name: Install virtual display
|
|
if: matrix.os == 'ubuntu-latest'
|
|
run: sudo apt-get update && sudo apt-get install -y xvfb xauth
|
|
|
|
- name: Run real Electron browser tab bridge E2E
|
|
if: matrix.os == 'ubuntu-latest'
|
|
run: npm run test:e2e:browser-tab-bridge --workspace=@getpaseo/desktop
|
|
env:
|
|
PASEO_TAB_BRIDGE_E2E_ARTIFACT_DIR: ${{ runner.temp }}/browser-tab-bridge-e2e
|
|
|
|
- name: Upload browser tab bridge diagnostics
|
|
uses: actions/upload-artifact@v4
|
|
if: failure() && matrix.os == 'ubuntu-latest'
|
|
with:
|
|
name: browser-tab-bridge-e2e
|
|
path: ${{ runner.temp }}/browser-tab-bridge-e2e
|
|
if-no-files-found: ignore
|
|
retention-days: 7
|
|
|
|
- name: Build and smoke unpacked desktop app
|
|
if: >-
|
|
matrix.os == 'ubuntu-latest' &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.desktop_package != 'false')
|
|
run: npm run build:desktop -- --publish never --linux --x64 --dir
|
|
env:
|
|
EP_GH_IGNORE_TIME: true
|
|
PASEO_DESKTOP_SMOKE: "1"
|
|
PASEO_DESKTOP_SMOKE_ARTIFACT_DIR: ${{ runner.temp }}/desktop-smoke
|
|
|
|
- name: Upload packaged smoke diagnostics
|
|
if: >-
|
|
failure() && matrix.os == 'ubuntu-latest' &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.desktop_package != 'false')
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: desktop-packaged-smoke-linux-x64
|
|
path: ${{ runner.temp }}/desktop-smoke
|
|
if-no-files-found: ignore
|
|
retention-days: 7
|
|
|
|
app-tests:
|
|
needs: changes
|
|
if: >-
|
|
${{ always() &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.app != 'false') }}
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
ELECTRON_SKIP_BINARY_DOWNLOAD: "1"
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Install dependencies with retry
|
|
run: node scripts/npm-retry.mjs ci
|
|
- name: Install Playwright browsers
|
|
timeout-minutes: 10
|
|
run: npx playwright install chromium
|
|
|
|
- name: Build app dependencies
|
|
run: npm run build:app-deps
|
|
|
|
- name: Run app unit tests
|
|
run: npm run test --workspace=@getpaseo/app
|
|
|
|
sdk-tests:
|
|
needs: changes
|
|
if: >-
|
|
${{ always() &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.sdk != 'false') }}
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
ELECTRON_SKIP_BINARY_DOWNLOAD: "1"
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Install dependencies
|
|
run: node scripts/npm-retry.mjs ci
|
|
- name: Build client dependencies
|
|
run: npm run build:client
|
|
|
|
- name: Run protocol tests
|
|
run: npm run test --workspace=@getpaseo/protocol
|
|
|
|
- name: Run client tests
|
|
run: npm run test --workspace=@getpaseo/client
|
|
|
|
- name: Typecheck client examples
|
|
run: npm run typecheck:examples --workspace=@getpaseo/client
|
|
|
|
playwright:
|
|
needs: changes
|
|
if: >-
|
|
${{ always() &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.playwright != 'false') }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- { label: "shard 1/4", shard: 1, desktop: false }
|
|
- { label: "shard 2/4", shard: 2, desktop: false }
|
|
- { label: "shard 3/4", shard: 3, desktop: false }
|
|
- { label: "shard 4/4", shard: 4, desktop: false }
|
|
- { label: "desktop overlay", shard: "desktop", desktop: true }
|
|
name: playwright (${{ matrix.label }})
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
ELECTRON_SKIP_BINARY_DOWNLOAD: "1"
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Install dependencies with retry
|
|
run: node scripts/npm-retry.mjs ci
|
|
- name: Install Playwright browsers
|
|
timeout-minutes: 10
|
|
run: npx playwright install chromium
|
|
|
|
- name: Build app dependencies
|
|
run: npm run build:app-deps
|
|
|
|
- name: Build server stack
|
|
run: npm run build:server
|
|
|
|
- name: Install agent CLIs for provider tests
|
|
if: ${{ !matrix.desktop }}
|
|
run: node scripts/npm-retry.mjs install -g @anthropic-ai/claude-code @openai/codex@0.105.0 opencode-ai
|
|
|
|
- name: Run Playwright E2E tests
|
|
if: ${{ !matrix.desktop }}
|
|
run: npm run test:e2e --workspace=@getpaseo/app -- --shard=${{ matrix.shard }}/4
|
|
env:
|
|
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
|
|
|
|
- name: Run desktop-overlay Playwright tests
|
|
if: ${{ matrix.desktop }}
|
|
run: npm run test:e2e:desktop --workspace=@getpaseo/app
|
|
|
|
- name: Upload test artifacts
|
|
uses: actions/upload-artifact@v4
|
|
if: failure()
|
|
with:
|
|
name: playwright-results-${{ matrix.shard }}
|
|
path: |
|
|
packages/app/test-results/
|
|
packages/app/playwright-report/
|
|
retention-days: 7
|
|
|
|
relay-tests:
|
|
needs: changes
|
|
if: >-
|
|
${{ always() &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.relay != 'false') }}
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
ELECTRON_SKIP_BINARY_DOWNLOAD: "1"
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Install dependencies
|
|
run: node scripts/npm-retry.mjs ci
|
|
|
|
- name: Build relay
|
|
run: npm run build:relay
|
|
|
|
- name: Run relay tests
|
|
run: npm run test --workspace=@getpaseo/relay
|
|
|
|
cli-tests:
|
|
needs: changes
|
|
if: >-
|
|
${{ always() &&
|
|
(github.event_name == 'workflow_dispatch' ||
|
|
needs.changes.result != 'success' ||
|
|
needs.changes.outputs.cli != 'false') }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
shard: [1, 2, 3]
|
|
runs-on: ubuntu-latest
|
|
name: cli-tests (shard ${{ matrix.shard }}/3)
|
|
env:
|
|
ELECTRON_SKIP_BINARY_DOWNLOAD: "1"
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "22"
|
|
cache: "npm"
|
|
|
|
- name: Install dependencies
|
|
run: node scripts/npm-retry.mjs ci
|
|
|
|
- name: Build server stack
|
|
run: npm run build:server
|
|
|
|
- name: Install agent CLIs for provider tests
|
|
run: node scripts/npm-retry.mjs install -g @anthropic-ai/claude-code @openai/codex@0.105.0 opencode-ai
|
|
|
|
- name: Run CLI tests
|
|
run: npm run test --workspace=@getpaseo/cli
|
|
env:
|
|
PASEO_LOCAL_SPEECH_AUTO_DOWNLOAD: "0"
|
|
PASEO_DICTATION_ENABLED: "0"
|
|
PASEO_VOICE_MODE_ENABLED: "0"
|
|
PASEO_CLI_TEST_SHARD: ${{ matrix.shard }}
|
|
PASEO_CLI_TEST_SHARD_TOTAL: "3"
|