|
32546
|
23956
|
116
|
5
|
517414d8806adba9ad700d6508e6c563513a583e
|
0
|
Runtime image build + SBOM (+ cosign when a key is Runtime image build + SBOM (+ cosign when a key is provided)...
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
image:
name: Runtime image build + SBOM (+ cosign when a key is provided)
runs-on: ubuntu-latest
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "20"
- name: Private registry auth (temporary userconfig)
uses: ./.github/actions/private-npm
with:
token: ${{ secrets.GITEA_NPM_TOKEN }}
- name: Resolve npmrc for BuildKit secret (never printed)
run: |
cfg="${RUNNER_TEMP}/platform-npmrc-resolved"
umask 077
printf '@juhai:registry=https://gitea.g-hi.com/api/packages/luoanwu/npm/\n//gitea.g-hi.com/api/packages/luoanwu/npm/:_authToken=%s\n' "${GITEA_NPM_TOKEN}" > "${cfg}"
echo "PLATFORM_NPMRC=${cfg}" >> "${GITHUB_ENV}"
- name: Build runtime image from git archive HEAD:runtime (reports/image-digest.json)
run: node governance/build-image.mjs --context head --npmrc "${PLATFORM_NPMRC}"
- name: Install syft (pinned) and generate SPDX SBOM
run: |
curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b "${RUNNER_TEMP}/bin" v1.20.0
PATH="${RUNNER_TEMP}/bin:${PATH}" node governance/sbom.mjs
- name: Install cosign (pinned)
uses: sigstore/cosign-installer@v3
with:
cosign-release: v2.4.1
- name: Sign image when COSIGN_PRIVATE_KEY is provided (otherwise explicit skip)
run: |
if [ -n "${COSIGN_PRIVATE_KEY}" ]; then
umask 077; printf '%s' "${COSIGN_PRIVATE_KEY}" > "${RUNNER_TEMP}/cosign.key"
COSIGN_KEY="${RUNNER_TEMP}/cosign.key" node governance/sign-image.mjs
else
node governance/sign-image.mjs
fi
env:
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
- if: always()
name: Upload image evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: warn
name: platform-image-${{ env.CANDIDATE_TAG }}
path: |
reports/image-digest.json
reports/sbom.spdx.json
reports/sbom.latest.json
reports/signature.json
retention-days: "30"
timeout-minutes: "40"
permissions:
contents: read
...
|
image
|
["static"]
|
["ubuntu-latest"]
|
28196
|
4
|
1789439459
|
1789439459
|
1789439267
|
1789439459
|
|
1
|
|
0
|
Edit
Delete
|
|
32547
|
23956
|
116
|
5
|
517414d8806adba9ad700d6508e6c563513a583e
|
0
|
Release candidate verification + manifest
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
candidate:
name: Release candidate verification + manifest
runs-on: ubuntu-latest
if: always()
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "20"
- name: Download static evidence
uses: actions/download-artifact@v3
with:
name: platform-static-${{ env.CANDIDATE_TAG }}
path: candidate/static
continue-on-error: true
- name: Download runtime evidence
uses: actions/download-artifact@v3
with:
name: platform-runtime-${{ env.CANDIDATE_TAG }}
path: candidate/runtime/runtime/reports
continue-on-error: true
- name: Download identity evidence
uses: actions/download-artifact@v3
with:
name: platform-identity-${{ env.CANDIDATE_TAG }}
path: candidate/identity/identity/reports
continue-on-error: true
- name: Download port-conformance evidence
uses: actions/download-artifact@v3
with:
name: platform-port-conformance-${{ env.CANDIDATE_TAG }}
path: candidate/port-conformance/reports
continue-on-error: true
- id: verify
name: Verify candidate (per-report sourceSha / dirty / status / digest; missing → ineligible)
run: node governance/verify-candidate.mjs --candidate candidate --sha "${{ github.sha }}" --run-id "${{ github.run_id }}" --attempt "${{ github.run_attempt }}" --out reports/release-candidate.latest.json
continue-on-error: true
- name: Download image and full SBOM evidence for the same candidate
uses: actions/download-artifact@v3
with:
name: platform-image-${{ env.CANDIDATE_TAG }}
path: reports
- name: Release Manifest (known facts, status partial until all deliverables exist)
run: node governance/release-manifest.mjs
- if: always()
name: Upload candidate evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: error
name: platform-candidate-${{ env.CANDIDATE_TAG }}
path: |
reports/release-candidate.latest.json
reports/release-manifest.latest.json
retention-days: "30"
- if: always()
name: Propagate upstream results and candidate eligibility
run: |
echo "public-static=${{ needs.public-static.result }} static=${{ needs.static.result }} runtime=${{ needs.runtime.result }} identity=${{ needs.identity.result }} verify=${{ steps.verify.outcome }}"
test "${{ needs.public-static.result }}" = "success"
test "${{ needs.static.result }}" = "success"
test "${{ needs.unit.result }}" = "success"
test "${{ needs.port-conformance.result }}" = "success"
test "${{ needs.runtime.result }}" = "success"
test "${{ needs.identity.result }}" = "success"
test "${{ needs.image.result }}" = "success"
test "${{ steps.verify.outcome }}" = "success"
timeout-minutes: "10"
permissions:
contents: read
...
|
candidate
|
["public-static","static","uni ["public-static","static","unit","port-conformance","runtime","identity","image"]...
|
["ubuntu-latest"]
|
28197
|
2
|
1789439461
|
1789440381
|
1789439267
|
1789440382
|
|
1
|
|
0
|
Edit
Delete
|
|
32548
|
23957
|
51
|
5
|
fe40791d1aec2f0e2a6fa6826d26b210add5f8bd
|
0
|
后端 · lint + 类型 + 无DB单测(含契约)
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
server-checks:
name: 后端 · lint + 类型 + 无DB单测(含契约)
runs-on: ubuntu-latest
env:
# 无DB单测会 import config/env(zod 启动校验,仅校验格式不连库):提供合法 DATABASE_URL/JWT_SECRET 让校验通过。
# 纯函数单测(leads.canTransition / platforms.platformConnectionTruth 等)不发查询,无需真实 DB 服务。
DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
JWT_SECRET: ci-jwt-secret-not-for-prod
USE_MOCK_ADAPTERS: 'true'
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: server/package-lock.json
node-version: "20"
- run: npm ci
- run: npx prisma generate
- run: npm run lint
- run: npm run build
- run: npm run test:unit
defaults:
run:
working-directory: server
...
|
server-checks
|
null
|
["ubuntu-latest"]
|
28198
|
1
|
1789440855
|
1789440927
|
1789440853
|
1789440928
|
|
0
|
|
0
|
Edit
Delete
|
|
32549
|
23957
|
51
|
5
|
fe40791d1aec2f0e2a6fa6826d26b210add5f8bd
|
0
|
后端 · 真实DB集成测试(多租户/RBAC/并发/状态机/归因)
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
server-integration:
name: 后端 · 真实DB集成测试(多租户/RBAC/并发/状态机/归因)
runs-on: ubuntu-latest
env:
# global-setup 会用这个串跑 prisma migrate deploy + seed,再运行 vitest。
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
# CI 专用占位密钥(仅满足 env.ts 的 zod 校验,绝非生产值)。
JWT_SECRET: ci-jwt-secret-not-for-prod
JWT_REFRESH_SECRET: ci-jwt-refresh-secret-not-for-prod
# 用 Mock 适配层:CI 不打外部 LLM/平台,确定性、零外部依赖。
USE_MOCK_ADAPTERS: 'true'
NODE_ENV: test
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: server/package-lock.json
node-version: "20"
- run: npm ci
- run: npx prisma generate
- run: npm run test:integration
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong_test
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong_test" --health-interval 5s --health-timeout 5s --health-retries 20
defaults:
run:
working-directory: server
...
|
server-integration
|
null
|
["ubuntu-latest"]
|
28199
|
2
|
1789440928
|
1789440968
|
1789440853
|
1789440969
|
|
0
|
|
0
|
Edit
Delete
|
|
32550
|
23957
|
51
|
5
|
fe40791d1aec2f0e2a6fa6826d26b210add5f8bd
|
0
|
前端 · 静态契约 + 屏幕治理 + lint + AOT构建
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
frontend-static:
name: 前端 · 静态契约 + 屏幕治理 + lint + AOT构建
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: 团购本地生活AI运营App/package-lock.json
node-version: "20"
- run: npm ci
- run: npm run vendor
- run: npm test
- run: npm run lint
- run: npm run build
defaults:
run:
working-directory: 团购本地生活AI运营App
...
|
frontend-static
|
null
|
["ubuntu-latest"]
|
28200
|
1
|
1789440969
|
1789440997
|
1789440853
|
1789440998
|
|
0
|
|
0
|
Edit
Delete
|
|
32551
|
23958
|
72
|
5
|
ec9e07de44a5619a8a6b5648f00f5ea7f7dcafcf
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
28201
|
1
|
1789440998
|
1789441171
|
1789440856
|
1789441171
|
|
0
|
|
0
|
Edit
Delete
|
|
32552
|
23958
|
72
|
5
|
ec9e07de44a5619a8a6b5648f00f5ea7f7dcafcf
|
0
|
Runtime and UI acceptance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
runtime-acceptance:
name: Runtime and UI acceptance
runs-on: ubuntu-latest
env:
DATABASE_URL: postgresql://postgres:postgres@127.0.0.1:5432/juhai_quotation_ci?schema=public
REDIS_URL: redis://127.0.0.1:6379
# 桶名须 juhai-quotation* 前缀(preflight 基座守卫,G15 同型)。
S3_ENDPOINT: http://127.0.0.1:9000
S3_BUCKET: juhai-quotation-ci
S3_ACCESS_KEY_ID: ci-access-key
S3_SECRET_ACCESS_KEY: ci-secret-key
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Start object storage (MinIO)
run: |
docker run -d --name minio -p 9000:9000 \
-e MINIO_ROOT_USER=ci-access-key \
-e MINIO_ROOT_PASSWORD=ci-secret-key \
minio/minio:latest server /data
for _ in $(seq 1 30); do
if curl -sf http://127.0.0.1:9000/minio/health/live >/dev/null; then
echo "MinIO is live."
exit 0
fi
sleep 2
done
echo "MinIO did not become live within 60s" >&2
docker logs minio >&2
exit 1
- name: Run real DB and Redis acceptance
run: pnpm check:runtime
- name: Install Playwright browser
run: pnpm --filter web exec playwright install --with-deps chromium
- name: Run UI acceptance
run: pnpm check:ui
- if: failure()
name: Upload acceptance evidence
uses: actions/upload-artifact@v4
with:
if-no-files-found: warn
name: acceptance-evidence
path: |
reports/*.latest.json
apps/web/e2e-results.json
apps/web/test-results/**
retention-days: "7"
services:
postgres:
image: postgres:16
env:
POSTGRES_DB: juhai_quotation_ci
POSTGRES_PASSWORD: postgres
POSTGRES_USER: postgres
ports:
- 5432:5432
options: --health-cmd "pg_isready -U postgres -d juhai_quotation_ci" --health-interval 5s --health-timeout 5s --health-retries 20
redis:
image: redis:7
ports:
- 6379:6379
options: --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
runtime-acceptance
|
["static-governance"]
|
["ubuntu-latest"]
|
28208
|
2
|
1789441286
|
1789441317
|
1789440856
|
1789441317
|
|
1
|
|
0
|
Edit
Delete
|
|
32553
|
23959
|
81
|
5
|
2085f1a31a52687344dd74911761be941a185b3c
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
steps:
- name: Checkout service system
uses: actions/checkout@v4
with:
path: service-system
- name: Checkout locked Digital Employee OS baseline
uses: actions/checkout@v4
with:
path: digital-employee-os
ref: 89b2adeeda1017b1ac4f66fb1ff5f89e0a21fcef
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.DIGITAL_EMPLOYEE_OS_READ_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build locked Digital Employee OS compatibility packages
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" install --frozen-lockfile
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/skill-runtime build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/tool-runtime build
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: service-system
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
28202
|
2
|
1789441171
|
1789441179
|
1789440859
|
1789441179
|
|
0
|
|
0
|
Edit
Delete
|
|
32555
|
23960
|
83
|
5
|
a0ebf7769727344892ab96c1240bd809b5791430
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
name: Configure read-only platform package authentication
run: node scripts/configure-platform-npm.mjs
env:
PLATFORM_NPM_TOKEN: ${{ secrets.PLATFORM_NPM_TOKEN }}
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
28203
|
2
|
1789441179
|
1789441204
|
1789440861
|
1789441205
|
|
0
|
|
0
|
Edit
Delete
|
|
32557
|
23961
|
83
|
5
|
a0ebf7769727344892ab96c1240bd809b5791430
|
0
|
@juhai/* exact pin + contracts fixtures
|
1
|
name: Platform governance (consumer)
"on": name: Platform governance (consumer)
"on":
pull_request:
push:
branches: [main]
jobs:
pins:
name: '@juhai/* exact pin + contracts fixtures'
runs-on: ubuntu-latest
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
name: Configure read-only platform package authentication
run: node scripts/configure-platform-npm.mjs
env:
PLATFORM_NPM_TOKEN: ${{ secrets.PLATFORM_NPM_TOKEN }}
- name: Install (frozen lockfile)
run: pnpm install --frozen-lockfile --ignore-scripts
- name: check:pins(必需检查)
run: pnpm exec juhai-governance check:pins --require @juhai/contracts --require @juhai/governance
- name: check:fixtures(必需检查)
run: pnpm exec juhai-governance check:fixtures --suite governance/fixtures/contracts.suite.json
- if: always()
name: Upload governance reports
uses: actions/upload-artifact@v3
with:
if-no-files-found: ignore
name: governance-${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
path: reports/*.latest.json
timeout-minutes: "15"
permissions:
contents: read
...
|
pins
|
null
|
["ubuntu-latest"]
|
28204
|
1
|
1789441205
|
1789441222
|
1789440861
|
1789441222
|
|
0
|
|
0
|
Edit
Delete
|
|
32558
|
23961
|
83
|
5
|
a0ebf7769727344892ab96c1240bd809b5791430
|
0
|
Platform consumer gate
|
1
|
name: Platform governance (consumer)
"on": name: Platform governance (consumer)
"on":
pull_request:
push:
branches: [main]
jobs:
required:
name: Platform consumer gate
runs-on: ubuntu-latest
if: always()
steps:
- name: Require completed pins and fixture checks
run: test "$PINS_RESULT" = success
env:
PINS_RESULT: ${{ needs.pins.result }}
timeout-minutes: "2"
permissions:
contents: read
...
|
required
|
["pins"]
|
["ubuntu-latest"]
|
28209
|
1
|
1789441317
|
1789441317
|
1789440861
|
1789441317
|
|
1
|
|
0
|
Edit
Delete
|
|
32559
|
23962
|
82
|
5
|
ab2e7f155b4fbe2e9bebc1ac4887247efc0e97c7
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
28205
|
2
|
1789441222
|
1789441251
|
1789440864
|
1789441251
|
|
0
|
|
0
|
Edit
Delete
|
|
32561
|
23963
|
84
|
5
|
558e30bac2666ebe08fed4d2649e433638ead6c6
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
28206
|
2
|
1789441251
|
1789441278
|
1789440865
|
1789441278
|
|
0
|
|
0
|
Edit
Delete
|
|
32563
|
23964
|
80
|
5
|
bda8349f3440331dc74da6a4a41880607201d63d
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
DIGITAL_EMPLOYEE_OS_SHA: 5cb2f1cc2f9953d47fa0bcfac541400d01603f78
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout device cloud with history
uses: actions/checkout@v4
with:
fetch-depth: "0"
path: device-cloud
- name: Checkout pinned Digital Employee OS
uses: actions/checkout@v4
with:
fetch-depth: "1"
path: digital-employee-os
ref: ${{ env.DIGITAL_EMPLOYEE_OS_SHA }}
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.OS_REPO_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install device-cloud dependencies
run: pnpm install --frozen-lockfile
- name: Install pinned OS dependencies
run: pnpm install --frozen-lockfile
working-directory: digital-employee-os
- name: Build OS contracts and generate device-cloud Prisma clients
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: device-cloud
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
28207
|
2
|
1789441278
|
1789441286
|
1789440869
|
1789441286
|
|
0
|
|
0
|
Edit
Delete
|
|
32565
|
23965
|
116
|
5
|
02587c52835c0d763ab44c302cb862b5cb1a0125
|
0
|
Public static checks (no private packages)
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
public-static:
name: Public static checks (no private packages)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "20"
- name: Install contracts dependencies (public npm only, frozen lockfile; CT-1 build / validators / generated-types check)
run: pnpm --dir contracts install --frozen-lockfile
- name: Governance checks (no private packages; contracts deps from public npm)
run: |
pnpm check:module-imports
pnpm check:catalog
pnpm check:migration-decs
pnpm check:caddy
pnpm test
pnpm contracts:check:local
- name: Pack publishable packages (contracts + governance; no publish)
run: |
rm -rf dist-artifacts
pnpm --dir contracts build
pnpm --dir governance pack --pack-destination ../dist-artifacts
pnpm --dir contracts pack --pack-destination ../dist-artifacts
ls -la dist-artifacts
- if: always()
name: Upload package tarballs
uses: actions/upload-artifact@v3
with:
if-no-files-found: error
name: platform-packages-${{ env.CANDIDATE_TAG }}
path: dist-artifacts/*.tgz
retention-days: "30"
- if: always()
name: Upload public static evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: warn
name: platform-public-static-${{ env.CANDIDATE_TAG }}
path: reports/*.latest.json
retention-days: "30"
timeout-minutes: "15"
permissions:
contents: read
...
|
public-static
|
null
|
["ubuntu-latest"]
|
28210
|
2
|
1789444584
|
1789444675
|
1789444583
|
1789444675
|
|
0
|
|
0
|
Edit
Delete
|
|
32566
|
23965
|
116
|
5
|
02587c52835c0d763ab44c302cb862b5cb1a0125
|
0
|
Static governance (repo root, private packages)
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
static:
name: Static governance (repo root, private packages)
runs-on: ubuntu-latest
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
cache: pnpm
cache-dependency-path: runtime/pnpm-lock.yaml
node-version: "20"
- name: Private registry auth (temporary userconfig)
uses: ./.github/actions/private-npm
with:
token: ${{ secrets.GITEA_NPM_TOKEN }}
- name: Install runtime workspace (frozen lockfile)
run: pnpm --dir runtime install --frozen-lockfile
- name: Install contracts dependencies (public npm only, frozen lockfile; CT-1 build / validators / generated-types check)
run: pnpm --dir contracts install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm --dir runtime prisma:generate
- name: Build runtime modules (fixture suites evaluate migrated rules from dist)
run: pnpm runtime:build:modules
- name: Repo-root governance gate
run: pnpm check
- name: Source tree must stay clean apart from latest reports (no tracked .npmrc mutation)
run: |
git status --porcelain | grep -vE '\.latest\.json$' && { echo "::error::静态门禁修改了报告以外的跟踪文件"; exit 1; } || echo "clean apart from latest reports"
- if: always()
name: Upload static evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: warn
name: platform-static-${{ env.CANDIDATE_TAG }}
path: |
reports/*.latest.json
runtime/reports/*.latest.json
!runtime/reports/runtime-acceptance.latest.json
!runtime/reports/conformance-differential.latest.json
!runtime/reports/ui-acceptance.latest.json
retention-days: "30"
timeout-minutes: "30"
permissions:
contents: read
...
|
static
|
null
|
["ubuntu-latest"]
|
28211
|
6
|
1789444675
|
0
|
1789444583
|
1789444675
|
|
0
|
|
0
|
Edit
Delete
|
|
30138
|
22805
|
6
|
5
|
a46d1a8248b62d039fbdf3815bc192399beb6ce5
|
0
|
Frontend Type Check
|
2
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
env:
NODE_OPTIONS: --max-old-space-size=8192
NODE_VERSION: "20"
jobs:
frontend-typecheck:
name: Frontend Type Check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
with:
cache: pnpm
node-version: ${{ env.NODE_VERSION }}
- run: pnpm install --frozen-lockfile
- name: Build shared package
run: pnpm -C shared run build
- name: 前端类型检查(vue-tsc --noEmit)
run: pnpm --filter ./frontend run type-check
...
|
frontend-typecheck
|
null
|
["ubuntu-latest"]
|
26306
|
2
|
1778722289
|
1778722380
|
1778721836
|
1778722380
|
|
0
|
|
0
|
Edit
Delete
|
|
30139
|
22805
|
6
|
5
|
a46d1a8248b62d039fbdf3815bc192399beb6ce5
|
0
|
Lint & Type Check
|
2
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
env:
NODE_OPTIONS: --max-old-space-size=8192
NODE_VERSION: "20"
jobs:
lint-and-typecheck:
name: Lint & Type Check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
with:
cache: pnpm
node-version: ${{ env.NODE_VERSION }}
- run: pnpm install --frozen-lockfile
- name: Generate Prisma Client
run: pnpm -C backend exec prisma generate
- name: Build shared package
run: pnpm -C shared run build
- name: Backend type check
run: pnpm -C backend run type-check
- name: Lint
run: pnpm -C backend run lint
...
|
lint-and-typecheck
|
null
|
["ubuntu-latest"]
|
26307
|
2
|
1778722380
|
1778722471
|
1778721836
|
1778722471
|
|
0
|
|
0
|
Edit
Delete
|
|
30717
|
23342
|
6
|
5
|
a5c6ac6d84d0c6aef2a832c4d0dbdffefe4d9eb3
|
0
|
Frontend Type Check
|
2
|
name: Gitea CI
"on":
push:
bra name: Gitea CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
env:
NODE_OPTIONS: --max-old-space-size=8192
NODE_VERSION: "20"
jobs:
frontend-typecheck:
name: Frontend Type Check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
with:
cache: pnpm
node-version: ${{ env.NODE_VERSION }}
- run: pnpm install --frozen-lockfile
- name: Build shared package
run: pnpm -C shared run build
- name: 前端类型检查(vue-tsc --noEmit)
run: pnpm --filter ./frontend run type-check
...
|
frontend-typecheck
|
null
|
["ubuntu-latest"]
|
26893
|
2
|
1778889923
|
1778890014
|
1778885718
|
1778890014
|
|
0
|
|
0
|
Edit
Delete
|
|
30718
|
23342
|
6
|
5
|
a5c6ac6d84d0c6aef2a832c4d0dbdffefe4d9eb3
|
0
|
Lint & Type Check
|
2
|
name: Gitea CI
"on":
push:
bra name: Gitea CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
env:
NODE_OPTIONS: --max-old-space-size=8192
NODE_VERSION: "20"
jobs:
lint-and-typecheck:
name: Lint & Type Check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
with:
cache: pnpm
node-version: ${{ env.NODE_VERSION }}
- run: pnpm install --frozen-lockfile
- name: Generate Prisma Client
run: pnpm -C backend exec prisma generate
- name: Build shared package
run: pnpm -C shared run build
- name: Backend type check
run: pnpm -C backend run type-check
- name: Lint
run: pnpm -C backend run lint
...
|
lint-and-typecheck
|
null
|
["ubuntu-latest"]
|
26894
|
2
|
1778890014
|
1778890044
|
1778885718
|
1778890044
|
|
0
|
|
0
|
Edit
Delete
|
|
32076
|
23883
|
83
|
5
|
df46b98835ff77c7f4675e043d0869799fbb8d08
|
0
|
@juhai/* exact pin + contracts fixtures
|
2
|
name: Platform governance (consumer)
"on": name: Platform governance (consumer)
"on":
pull_request:
push:
branches: [main]
jobs:
pins:
name: '@juhai/* exact pin + contracts fixtures'
runs-on: ubuntu-latest
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
name: Configure read-only platform package authentication
run: node scripts/configure-platform-npm.mjs
env:
PLATFORM_NPM_TOKEN: ${{ secrets.PLATFORM_NPM_TOKEN }}
- name: Install (frozen lockfile)
run: pnpm install --frozen-lockfile --ignore-scripts
- name: check:pins(必需检查)
run: pnpm exec juhai-governance check:pins --require @juhai/contracts
- if: ${{ hashFiles('governance/fixtures/*.suite.json') != '' }}
name: check:fixtures(可选)
run: pnpm exec juhai-governance check:fixtures --suite governance/fixtures/contracts.suite.json
- if: always()
name: Upload governance reports
uses: actions/upload-artifact@v3
with:
if-no-files-found: ignore
name: governance-${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
path: reports/*.latest.json
timeout-minutes: "15"
permissions:
contents: read
...
|
pins
|
null
|
["ubuntu-latest"]
|
27821
|
1
|
1789203799
|
1789203818
|
1789203232
|
1789203818
|
|
0
|
|
0
|
Edit
Delete
|
|
32077
|
23883
|
83
|
5
|
df46b98835ff77c7f4675e043d0869799fbb8d08
|
0
|
Platform consumer gate
|
2
|
name: Platform governance (consumer)
"on": name: Platform governance (consumer)
"on":
pull_request:
push:
branches: [main]
jobs:
required:
name: Platform consumer gate
runs-on: ubuntu-latest
if: always()
steps:
- name: Require completed pins and fixture checks
run: test "$PINS_RESULT" = success
env:
PINS_RESULT: ${{ needs.pins.result }}
timeout-minutes: "2"
permissions:
contents: read
...
|
required
|
["pins"]
|
["ubuntu-latest"]
|
27822
|
1
|
1789203821
|
1789203821
|
1789203232
|
1789203821
|
|
1
|
|
0
|
Edit
Delete
|