|
37025
|
25195
|
51
|
5
|
55dfcf8071943ca22e462fcd79a103681f9c9090
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31272
|
2
|
1791121619
|
1791121668
|
1791078823
|
1791121668
|
|
0
|
|
0
|
Edit
Delete
|
|
37026
|
25196
|
121
|
5
|
833eba10ce54e30eeccd95ab7ff20f26fb729b7e
|
0
|
acceptance
|
1
|
name: Kernel V1.0 CI
"on":
push:
name: Kernel V1.0 CI
"on":
push:
branches: [main]
jobs:
acceptance:
name: acceptance
runs-on: ubuntu-latest
steps:
- name: Checkout fixed source
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: "0"
persist-credentials: "false"
- name: Verify host runner and locked toolchain
run: |
set -eu
echo "Node executable: $(command -v node || true)"
node --version
node -e "if (Number(process.versions.node.split('.')[0]) < 22) { console.error('Node.js >=22 is required'); process.exit(1); }"
echo "Docker executable: $(command -v docker || true)"
docker version
docker image inspect postgres:16-alpine >/dev/null
corepack --version
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Run isolated PostgreSQL acceptance
run: pnpm ci:local
env:
ERK_TEST_CONCURRENCY: "1"
permissions:
contents: read
...
|
acceptance
|
null
|
["ubuntu-latest"]
|
31273
|
2
|
1791121668
|
1791124721
|
1791080416
|
1791124721
|
|
0
|
|
0
|
Edit
Delete
|
|
37032
|
25200
|
51
|
5
|
1d335e46af39fab7287df8b066ebdb6441866ea8
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31274
|
2
|
1791124722
|
1791124773
|
1791082093
|
1791124773
|
|
0
|
|
0
|
Edit
Delete
|
|
37036
|
25202
|
51
|
5
|
c8b1849d97c16e01d0e54b6b5f0ba7d9c49670d2
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31275
|
2
|
1791124773
|
1791124817
|
1791082950
|
1791124817
|
|
0
|
|
0
|
Edit
Delete
|
|
37040
|
25204
|
51
|
5
|
6bd4254c53f9089a569f370eae1380f3d362e82b
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31276
|
2
|
1791124817
|
1791124857
|
1791085991
|
1791124857
|
|
0
|
|
0
|
Edit
Delete
|
|
37041
|
25205
|
57
|
5
|
fcf2069901b8469ddeda090ed580fe0eb0c934aa
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version-file: .node-version
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
- name: Runtime and development dependency audit
run: pnpm check:deps
permissions:
contents: read
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
31277
|
2
|
1791124858
|
1791124908
|
1791086301
|
1791124908
|
|
0
|
|
0
|
Edit
Delete
|
|
37045
|
25207
|
51
|
5
|
f5e0f5cd7013ffb3bc7f30f173fa8aab7fbe59f0
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31278
|
2
|
1791124908
|
1791124951
|
1791087416
|
1791124951
|
|
0
|
|
0
|
Edit
Delete
|
|
37049
|
25209
|
51
|
5
|
ffc82024e26210dd956dd84dfb66b6a102026bf6
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31279
|
2
|
1791124951
|
1791124992
|
1791088492
|
1791124992
|
|
0
|
|
0
|
Edit
Delete
|
|
37053
|
25211
|
51
|
5
|
2a4061e4c3ff9166f1b8d1bdd1a847749a5b7828
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31280
|
2
|
1791124992
|
1791125035
|
1791088761
|
1791125035
|
|
0
|
|
0
|
Edit
Delete
|
|
37057
|
25213
|
51
|
5
|
92a86b698b2071089cbb4e272dea99863d4f162a
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31281
|
2
|
1791125035
|
1791125078
|
1791092429
|
1791125078
|
|
0
|
|
0
|
Edit
Delete
|
|
37061
|
25215
|
51
|
5
|
bc7a44f1327b4955940074a6789cd7354d345a53
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31282
|
2
|
1791125079
|
1791125119
|
1791097228
|
1791125120
|
|
0
|
|
0
|
Edit
Delete
|
|
37065
|
25217
|
51
|
5
|
c403f278853af537c83151736686e428a13ef35a
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31283
|
2
|
1791125120
|
1791125210
|
1791097460
|
1791125210
|
|
0
|
|
0
|
Edit
Delete
|
|
37069
|
25219
|
51
|
5
|
cc720a3ed232225461ea8651defce0f7de17a7e8
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31284
|
2
|
1791125210
|
1791125240
|
1791098629
|
1791125241
|
|
0
|
|
0
|
Edit
Delete
|
|
37070
|
25220
|
51
|
5
|
8dea76f88dbc1d25b9138740a700858621193fcf
|
0
|
后端 · lint + 类型 + 无DB单测(含契约)
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
server-checks:
name: 后端 · lint + 类型 + 无DB单测(含契约)
runs-on: ubuntu-latest
env:
# 无DB单测会 import config/env(zod 启动校验,仅校验格式不连库):提供合法 DATABASE_URL/JWT_SECRET 让校验通过。
# 纯函数单测(leads.canTransition / platforms.platformConnectionTruth 等)不发查询,无需真实 DB 服务。
DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
JWT_SECRET: ci-jwt-secret-not-for-prod
USE_MOCK_ADAPTERS: 'true'
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: server/package-lock.json
node-version: "20"
- run: npm ci
- run: npx prisma generate
- run: npm run lint
- run: npm run build
- run: npm run test:unit
defaults:
run:
working-directory: server
...
|
server-checks
|
null
|
["ubuntu-latest"]
|
31285
|
2
|
1791125241
|
1791125271
|
1791117721
|
1791125271
|
|
0
|
|
0
|
Edit
Delete
|
|
37071
|
25220
|
51
|
5
|
8dea76f88dbc1d25b9138740a700858621193fcf
|
0
|
后端 · 真实DB集成测试(多租户/RBAC/并发/状态机/归因)
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
server-integration:
name: 后端 · 真实DB集成测试(多租户/RBAC/并发/状态机/归因)
runs-on: ubuntu-latest
env:
# global-setup 会用这个串跑 prisma migrate deploy + seed,再运行 vitest。
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
# CI 专用占位密钥(仅满足 env.ts 的 zod 校验,绝非生产值)。
JWT_SECRET: ci-jwt-secret-not-for-prod
JWT_REFRESH_SECRET: ci-jwt-refresh-secret-not-for-prod
# 用 Mock 适配层:CI 不打外部 LLM/平台,确定性、零外部依赖。
USE_MOCK_ADAPTERS: 'true'
NODE_ENV: test
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: server/package-lock.json
node-version: "20"
- run: npm ci
- run: npx prisma generate
- run: npm run test:integration
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong_test
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong_test" --health-interval 5s --health-timeout 5s --health-retries 20
defaults:
run:
working-directory: server
...
|
server-integration
|
null
|
["ubuntu-latest"]
|
31286
|
2
|
1791125271
|
1791125301
|
1791117721
|
1791125301
|
|
0
|
|
0
|
Edit
Delete
|
|
37072
|
25220
|
51
|
5
|
8dea76f88dbc1d25b9138740a700858621193fcf
|
0
|
前端 · 静态契约 + 屏幕治理 + lint + AOT构建
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
frontend-static:
name: 前端 · 静态契约 + 屏幕治理 + lint + AOT构建
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: 团购本地生活AI运营App/package-lock.json
node-version: "20"
- run: npm ci
- run: npm run vendor
- run: npm test
- run: npm run lint
- run: npm run build
defaults:
run:
working-directory: 团购本地生活AI运营App
...
|
frontend-static
|
null
|
["ubuntu-latest"]
|
31287
|
2
|
1791125301
|
1791125332
|
1791117721
|
1791125332
|
|
0
|
|
0
|
Edit
Delete
|
|
37073
|
25221
|
51
|
5
|
8dea76f88dbc1d25b9138740a700858621193fcf
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31288
|
2
|
1791125332
|
1791125362
|
1791117721
|
1791125362
|
|
0
|
|
0
|
Edit
Delete
|
|
36996
|
25183
|
116
|
5
|
562056b6b1d3d5f51fe0d7b5ca1d5283f487e92f
|
0
|
Unit tests without DB (modules / packages / govern Unit tests without DB (modules / packages / governance)...
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
unit:
name: Unit tests without DB (modules / packages / governance)
runs-on: ubuntu-latest
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
cache: pnpm
cache-dependency-path: runtime/pnpm-lock.yaml
node-version: "20"
- name: Private registry auth (temporary userconfig)
uses: ./.github/actions/private-npm
with:
token: ${{ secrets.GITEA_NPM_TOKEN }}
- name: Install runtime workspace (frozen lockfile)
run: pnpm --dir runtime install --frozen-lockfile
- name: Generate clients for authority module unit imports (no database)
run: pnpm --dir runtime prisma:generate
- name: Module / package unit tests
run: pnpm --dir runtime exec turbo run test --filter='./modules/*' --filter='./packages/*' --filter='./clients/*' --force
- name: Governance package tests
run: pnpm governance:test
timeout-minutes: "20"
permissions:
contents: read
...
|
unit
|
["static"]
|
["ubuntu-latest"]
|
31289
|
4
|
1791125362
|
1791125362
|
1791075771
|
1791125363
|
|
1
|
|
0
|
Edit
Delete
|
|
36997
|
25183
|
116
|
5
|
562056b6b1d3d5f51fe0d7b5ca1d5283f487e92f
|
0
|
Port conformance (kernel / modules / clients)
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
port-conformance:
name: Port conformance (kernel / modules / clients)
runs-on: ubuntu-latest
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
cache: pnpm
cache-dependency-path: runtime/pnpm-lock.yaml
node-version: "20"
- name: Private registry auth (temporary userconfig)
uses: ./.github/actions/private-npm
with:
token: ${{ secrets.GITEA_NPM_TOKEN }}
- name: Install runtime workspace (frozen lockfile)
run: pnpm --dir runtime install --frozen-lockfile
- name: Run port conformance with complete suite coverage
run: pnpm check:port-conformance
- if: always()
name: Upload port conformance evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: error
name: platform-port-conformance-${{ env.CANDIDATE_TAG }}
path: reports/port-conformance.latest.json
retention-days: "30"
timeout-minutes: "20"
permissions:
contents: read
...
|
port-conformance
|
["static"]
|
["ubuntu-latest"]
|
31290
|
4
|
1791125364
|
1791125364
|
1791075771
|
1791125365
|
|
1
|
|
0
|
Edit
Delete
|
|
36998
|
25183
|
116
|
5
|
562056b6b1d3d5f51fe0d7b5ca1d5283f487e92f
|
0
|
Runtime and UI acceptance (real PostgreSQL + Redis Runtime and UI acceptance (real PostgreSQL + Redis)...
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
runtime:
name: Runtime and UI acceptance (real PostgreSQL + Redis)
runs-on: ubuntu-latest
env:
# 库名前缀由 runtime/package.json name 派生(G15 基座守卫:enterprise_platform*)
DATABASE_URL: postgresql://postgres:postgres@127.0.0.1:5432/enterprise_platform_ci?schema=public
REDIS_URL: redis://127.0.0.1:6379
KAFKA_BROKERS: 127.0.0.1:59092
MAINLINE_CHAOS_CONTAINER: enterprise-platform-ms23-ci-redpanda-1
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
cache: pnpm
cache-dependency-path: runtime/pnpm-lock.yaml
node-version: "20"
- name: Private registry auth (temporary userconfig)
uses: ./.github/actions/private-npm
with:
token: ${{ secrets.GITEA_NPM_TOKEN }}
- name: Install runtime workspace (frozen lockfile)
run: pnpm --dir runtime install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm --dir runtime prisma:generate
- name: Build persistence modules and prepare isolated ordinary-role databases
run: |
pnpm runtime:build:modules
pnpm mainline:prepare
pnpm identity:prepare
- name: Policy activation concurrency and lease fencing (isolated PostgreSQL with RLS)
run: pnpm check:policy-governance
- name: Real file and notification execution slices (S3, ClamAV, durable receiver receipts)
run: pnpm check:execution-slices
env:
EXECUTION_CLAMAV_PORT: "3310"
- name: Start isolated Redpanda and provision registered topics
run: |
docker compose -p enterprise-platform-ms23-ci -f stack/compose.yaml -f stack/overlays/test.yaml up -d --wait --no-deps redpanda
bash stack/provision/redpanda-topics.sh --apply
- name: Real DB and Redis acceptance (deploy → RLS roles → differential → tests incl. 7 profile boots)
run: pnpm runtime:check:runtime
- name: Persistent mainline, audit tamper, revocation SLA and real broker failure
run: pnpm mainline:check
- name: Identity signing against isolated OpenBao Transit
run: pnpm identity:check:transit
- name: Install Playwright browser
run: pnpm --dir runtime --filter web exec playwright install --with-deps chromium
- name: Workbench browser regressions (intercepted read APIs)
run: pnpm check:workbench-ui
- name: UI acceptance (NestJS / Fastify x WS / SSE)
run: pnpm runtime:check:ui
env:
UI_MATRIX: "1"
- name: Identity module browser acceptance (login / MFA / consent / sessions)
run: pnpm identity:check:module-ui
- name: MCP controlled writes (isolated IdP, Owner receipt, retry and revocation)
run: pnpm check:mcp-writes
- if: always()
name: Upload runtime and UI evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: warn
name: platform-runtime-${{ env.CANDIDATE_TAG }}
path: |
runtime/reports/runtime-acceptance.latest.json
runtime/reports/conformance-differential.latest.json
runtime/reports/ui-acceptance.latest.json
reports/workbench-ui.latest.json
reports/identity-ui.latest.json
reports/mcp-writes.latest.json
reports/mainline-acceptance.latest.json
reports/revocation-sla.latest.json
reports/policy-governance.latest.json
reports/execution-slices.latest.json
reports/identity-transit.latest.json
reports/scope-http.latest.json
reports/scope-fact-sla.latest.json
reports/machine-revocation-sla.latest.json
reports/credential-m1-sla.latest.json
retention-days: "30"
- if: always()
name: Stop isolated acceptance broker
run: docker compose -p enterprise-platform-ms23-ci -f stack/compose.yaml -f stack/overlays/test.yaml down
timeout-minutes: "50"
services:
clamav:
image: clamav/clamav-debian@sha256:be3cb41d9833ce9ffb98f3d3e1483c35c0d87060c2bda3624d75fd28bbf0b3bd
ports:
- 3310:3310
options: --health-cmd "clamdcheck.sh" --health-start-period 120s --health-interval 10s --health-timeout 5s --health-retries 24
postgres:
image: postgres:16
env:
POSTGRES_DB: enterprise_platform_ci
POSTGRES_PASSWORD: postgres
POSTGRES_USER: postgres
ports:
- 5432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_platform_ci" --health-interval 5s --health-timeout 5s --health-retries 20
redis:
image: redis:7
ports:
- 6379:6379
options: --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 5s --health-retries 20
permissions:
contents: read
...
|
runtime
|
["static"]
|
["ubuntu-latest"]
|
31291
|
4
|
1791125366
|
1791125366
|
1791075771
|
1791125367
|
|
1
|
|
0
|
Edit
Delete
|
|
36999
|
25183
|
116
|
5
|
562056b6b1d3d5f51fe0d7b5ca1d5283f487e92f
|
0
|
M1 identity transitional workspace (IdP static → E M1 identity transitional workspace (IdP static → E2 → governance)...
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
identity:
name: M1 identity transitional workspace (IdP static → E2 → governance)
runs-on: ubuntu-latest
env:
# 库名前缀由 identity/package.json name 派生(enterprise_idp*);Redis 必须 db 0(老框架 C22)
DATABASE_URL: postgresql://postgres:postgres@127.0.0.1:5432/enterprise_idp_ci?schema=public
REDIS_URL: redis://127.0.0.1:6379/0
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
cache: pnpm
cache-dependency-path: identity/pnpm-lock.yaml
node-version: "20"
- name: Private registry auth (temporary userconfig; identity 目前无私包依赖,保持同一配置步骤以便后续 pin)
uses: ./.github/actions/private-npm
with:
token: ${{ secrets.GITEA_NPM_TOKEN }}
- name: Install identity workspace (frozen lockfile)
run: pnpm --dir identity install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm --dir identity prisma:generate
- name: IdP static sub-checks (independent of runtime / UI reports)
run: pnpm identity:check:static
- name: IdP real DB acceptance (255 tests, serialized)
run: pnpm identity:check:runtime
- name: Install Playwright browser
run: pnpm --dir identity --filter web exec playwright install --with-deps chromium
- name: IdP UI acceptance (12 cases)
run: pnpm identity:check:ui
- name: IdP final governance aggregation (same checkout, fresh runtime / UI reports)
run: pnpm identity:check:governance
- if: always()
name: Upload identity evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: warn
name: platform-identity-${{ env.CANDIDATE_TAG }}
path: identity/reports/*.latest.json
retention-days: "30"
timeout-minutes: "50"
services:
postgres:
image: postgres:16
env:
POSTGRES_DB: enterprise_idp_ci
POSTGRES_PASSWORD: postgres
POSTGRES_USER: postgres
ports:
- 5432:5432
options: --health-cmd "pg_isready -U postgres -d enterprise_idp_ci" --health-interval 5s --health-timeout 5s --health-retries 20
redis:
image: redis:7
ports:
- 6379:6379
options: --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 5s --health-retries 20
permissions:
contents: read
...
|
identity
|
["static"]
|
["ubuntu-latest"]
|
31292
|
4
|
1791125368
|
1791125368
|
1791075771
|
1791125369
|
|
1
|
|
0
|
Edit
Delete
|
|
37000
|
25183
|
116
|
5
|
562056b6b1d3d5f51fe0d7b5ca1d5283f487e92f
|
0
|
Runtime image build + SBOM (+ cosign when a key is Runtime image build + SBOM (+ cosign when a key is provided)...
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
image:
name: Runtime image build + SBOM (+ cosign when a key is provided)
runs-on: ubuntu-latest
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "20"
- name: Private registry auth (temporary userconfig)
uses: ./.github/actions/private-npm
with:
token: ${{ secrets.GITEA_NPM_TOKEN }}
- name: Resolve npmrc for BuildKit secret (never printed)
run: |
cfg="${RUNNER_TEMP}/platform-npmrc-resolved"
umask 077
printf '@juhai:registry=https://gitea.g-hi.com/api/packages/luoanwu/npm/\n//gitea.g-hi.com/api/packages/luoanwu/npm/:_authToken=%s\n' "${GITEA_NPM_TOKEN}" > "${cfg}"
echo "PLATFORM_NPMRC=${cfg}" >> "${GITHUB_ENV}"
- name: Build runtime image from git archive HEAD:runtime (reports/image-digest.json)
run: node governance/build-image.mjs --context head --npmrc "${PLATFORM_NPMRC}"
- name: Install syft (pinned) and generate SPDX SBOM
run: |
curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sh -s -- -b "${RUNNER_TEMP}/bin" v1.20.0
PATH="${RUNNER_TEMP}/bin:${PATH}" node governance/sbom.mjs
- name: Install cosign (pinned)
uses: sigstore/cosign-installer@v3
with:
cosign-release: v2.4.1
- name: Sign image when COSIGN_PRIVATE_KEY is provided (otherwise explicit skip)
run: |
if [ -n "${COSIGN_PRIVATE_KEY}" ]; then
umask 077; printf '%s' "${COSIGN_PRIVATE_KEY}" > "${RUNNER_TEMP}/cosign.key"
COSIGN_KEY="${RUNNER_TEMP}/cosign.key" node governance/sign-image.mjs
else
node governance/sign-image.mjs
fi
env:
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
- if: always()
name: Upload image evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: warn
name: platform-image-${{ env.CANDIDATE_TAG }}
path: |
reports/image-digest.json
reports/sbom.spdx.json
reports/sbom.latest.json
reports/signature.json
retention-days: "30"
timeout-minutes: "40"
permissions:
contents: read
...
|
image
|
["static"]
|
["ubuntu-latest"]
|
31293
|
4
|
1791125370
|
1791125370
|
1791075771
|
1791125371
|
|
1
|
|
0
|
Edit
Delete
|
|
37001
|
25183
|
116
|
5
|
562056b6b1d3d5f51fe0d7b5ca1d5283f487e92f
|
0
|
Release candidate verification + manifest
|
1
|
name: Platform
"on":
pull_request:
name: Platform
"on":
pull_request:
push:
branches: [main]
workflow_dispatch:
env:
CANDIDATE_TAG: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
GOV_REPORT_RUNNER: gitea-actions
PNPM_VERSION: 9.15.9
jobs:
candidate:
name: Release candidate verification + manifest
runs-on: ubuntu-latest
if: always()
steps:
- uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@${PNPM_VERSION} --activate
- uses: actions/setup-node@v4
with:
node-version: "20"
- name: Download static evidence
uses: actions/download-artifact@v3
with:
name: platform-static-${{ env.CANDIDATE_TAG }}
path: candidate/static
continue-on-error: true
- name: Download runtime evidence
uses: actions/download-artifact@v3
with:
name: platform-runtime-${{ env.CANDIDATE_TAG }}
path: candidate/runtime/runtime/reports
continue-on-error: true
- name: Download identity evidence
uses: actions/download-artifact@v3
with:
name: platform-identity-${{ env.CANDIDATE_TAG }}
path: candidate/identity/identity/reports
continue-on-error: true
- name: Download port-conformance evidence
uses: actions/download-artifact@v3
with:
name: platform-port-conformance-${{ env.CANDIDATE_TAG }}
path: candidate/port-conformance/reports
continue-on-error: true
- id: verify
name: Verify candidate (per-report sourceSha / dirty / status / digest; missing → ineligible)
run: node governance/verify-candidate.mjs --candidate candidate --sha "${{ github.sha }}" --run-id "${{ github.run_id }}" --attempt "${{ github.run_attempt }}" --out reports/release-candidate.latest.json
continue-on-error: true
- name: Download image and full SBOM evidence for the same candidate
uses: actions/download-artifact@v3
with:
name: platform-image-${{ env.CANDIDATE_TAG }}
path: reports
- name: Release Manifest (known facts, status partial until all deliverables exist)
run: node governance/release-manifest.mjs
- if: always()
name: Upload candidate evidence
uses: actions/upload-artifact@v3
with:
if-no-files-found: error
name: platform-candidate-${{ env.CANDIDATE_TAG }}
path: |
reports/release-candidate.latest.json
reports/release-manifest.latest.json
retention-days: "30"
- if: always()
name: Propagate upstream results and candidate eligibility
run: |
echo "public-static=${{ needs.public-static.result }} static=${{ needs.static.result }} runtime=${{ needs.runtime.result }} identity=${{ needs.identity.result }} verify=${{ steps.verify.outcome }}"
test "${{ needs.public-static.result }}" = "success"
test "${{ needs.static.result }}" = "success"
test "${{ needs.unit.result }}" = "success"
test "${{ needs.port-conformance.result }}" = "success"
test "${{ needs.runtime.result }}" = "success"
test "${{ needs.identity.result }}" = "success"
test "${{ needs.image.result }}" = "success"
test "${{ steps.verify.outcome }}" = "success"
timeout-minutes: "10"
permissions:
contents: read
...
|
candidate
|
["public-static","static","uni ["public-static","static","unit","port-conformance","runtime","identity","image"]...
|
["ubuntu-latest"]
|
31294
|
2
|
1791125372
|
1791125445
|
1791075771
|
1791125445
|
|
1
|
|
0
|
Edit
Delete
|
|
37074
|
25222
|
51
|
5
|
5cff46dfd5d7f08cd2767aa030e973b3cb2cebd5
|
0
|
后端 · lint + 类型 + 无DB单测(含契约)
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
server-checks:
name: 后端 · lint + 类型 + 无DB单测(含契约)
runs-on: ubuntu-latest
env:
# 无DB单测会 import config/env(zod 启动校验,仅校验格式不连库):提供合法 DATABASE_URL/JWT_SECRET 让校验通过。
# 纯函数单测(leads.canTransition / platforms.platformConnectionTruth 等)不发查询,无需真实 DB 服务。
DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
JWT_SECRET: ci-jwt-secret-not-for-prod
USE_MOCK_ADAPTERS: 'true'
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: server/package-lock.json
node-version: "20"
- run: npm ci
- run: npx prisma generate
- run: npm run lint
- run: npm run build
- run: npm run test:unit
defaults:
run:
working-directory: server
...
|
server-checks
|
null
|
["ubuntu-latest"]
|
31295
|
2
|
1791160349
|
1791160439
|
1791160347
|
1791160439
|
|
0
|
|
0
|
Edit
Delete
|
|
37075
|
25222
|
51
|
5
|
5cff46dfd5d7f08cd2767aa030e973b3cb2cebd5
|
0
|
后端 · 真实DB集成测试(多租户/RBAC/并发/状态机/归因)
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
server-integration:
name: 后端 · 真实DB集成测试(多租户/RBAC/并发/状态机/归因)
runs-on: ubuntu-latest
env:
# global-setup 会用这个串跑 prisma migrate deploy + seed,再运行 vitest。
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
# CI 专用占位密钥(仅满足 env.ts 的 zod 校验,绝非生产值)。
JWT_SECRET: ci-jwt-secret-not-for-prod
JWT_REFRESH_SECRET: ci-jwt-refresh-secret-not-for-prod
# 用 Mock 适配层:CI 不打外部 LLM/平台,确定性、零外部依赖。
USE_MOCK_ADAPTERS: 'true'
NODE_ENV: test
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: server/package-lock.json
node-version: "20"
- run: npm ci
- run: npx prisma generate
- run: npm run test:integration
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong_test
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong_test" --health-interval 5s --health-timeout 5s --health-retries 20
defaults:
run:
working-directory: server
...
|
server-integration
|
null
|
["ubuntu-latest"]
|
31296
|
2
|
1791160439
|
1791160470
|
1791160347
|
1791160470
|
|
0
|
|
0
|
Edit
Delete
|
|
37076
|
25222
|
51
|
5
|
5cff46dfd5d7f08cd2767aa030e973b3cb2cebd5
|
0
|
前端 · 静态契约 + 屏幕治理 + lint + AOT构建
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
frontend-static:
name: 前端 · 静态契约 + 屏幕治理 + lint + AOT构建
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: 团购本地生活AI运营App/package-lock.json
node-version: "20"
- run: npm ci
- run: npm run vendor
- run: npm test
- run: npm run lint
- run: npm run build
defaults:
run:
working-directory: 团购本地生活AI运营App
...
|
frontend-static
|
null
|
["ubuntu-latest"]
|
31297
|
2
|
1791160470
|
1791160763
|
1791160347
|
1791160764
|
|
0
|
|
0
|
Edit
Delete
|
|
37077
|
25223
|
51
|
5
|
5cff46dfd5d7f08cd2767aa030e973b3cb2cebd5
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31298
|
2
|
1791160764
|
1791160807
|
1791160347
|
1791160807
|
|
0
|
|
0
|
Edit
Delete
|
|
37078
|
25224
|
51
|
5
|
80ef8d68e96afb51f1b6b62cc34883f0d7712b06
|
0
|
后端 · lint + 类型 + 无DB单测(含契约)
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
server-checks:
name: 后端 · lint + 类型 + 无DB单测(含契约)
runs-on: ubuntu-latest
env:
# 无DB单测会 import config/env(zod 启动校验,仅校验格式不连库):提供合法 DATABASE_URL/JWT_SECRET 让校验通过。
# 纯函数单测(leads.canTransition / platforms.platformConnectionTruth 等)不发查询,无需真实 DB 服务。
DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
JWT_SECRET: ci-jwt-secret-not-for-prod
USE_MOCK_ADAPTERS: 'true'
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: server/package-lock.json
node-version: "20"
- run: npm ci
- run: npx prisma generate
- run: npm run lint
- run: npm run build
- run: npm run test:unit
defaults:
run:
working-directory: server
...
|
server-checks
|
null
|
["ubuntu-latest"]
|
31299
|
1
|
1791163361
|
1791163445
|
1791163359
|
1791163445
|
|
0
|
|
0
|
Edit
Delete
|
|
37079
|
25224
|
51
|
5
|
80ef8d68e96afb51f1b6b62cc34883f0d7712b06
|
0
|
后端 · 真实DB集成测试(多租户/RBAC/并发/状态机/归因)
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
server-integration:
name: 后端 · 真实DB集成测试(多租户/RBAC/并发/状态机/归因)
runs-on: ubuntu-latest
env:
# global-setup 会用这个串跑 prisma migrate deploy + seed,再运行 vitest。
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
# CI 专用占位密钥(仅满足 env.ts 的 zod 校验,绝非生产值)。
JWT_SECRET: ci-jwt-secret-not-for-prod
JWT_REFRESH_SECRET: ci-jwt-refresh-secret-not-for-prod
# 用 Mock 适配层:CI 不打外部 LLM/平台,确定性、零外部依赖。
USE_MOCK_ADAPTERS: 'true'
NODE_ENV: test
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: server/package-lock.json
node-version: "20"
- run: npm ci
- run: npx prisma generate
- run: npm run test:integration
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong_test
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong_test" --health-interval 5s --health-timeout 5s --health-retries 20
defaults:
run:
working-directory: server
...
|
server-integration
|
null
|
["ubuntu-latest"]
|
31300
|
2
|
1791163445
|
1791163486
|
1791163359
|
1791163487
|
|
0
|
|
0
|
Edit
Delete
|
|
37080
|
25224
|
51
|
5
|
80ef8d68e96afb51f1b6b62cc34883f0d7712b06
|
0
|
前端 · 静态契约 + 屏幕治理 + lint + AOT构建
|
1
|
name: CI
"on":
push:
branches: name: CI
"on":
push:
branches: [main]
pull_request:
branches: [main]
jobs:
frontend-static:
name: 前端 · 静态契约 + 屏幕治理 + lint + AOT构建
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
cache: npm
cache-dependency-path: 团购本地生活AI运营App/package-lock.json
node-version: "20"
- run: npm ci
- run: npm run vendor
- run: npm test
- run: npm run lint
- run: npm run build
defaults:
run:
working-directory: 团购本地生活AI运营App
...
|
frontend-static
|
null
|
["ubuntu-latest"]
|
31301
|
1
|
1791163488
|
1791163536
|
1791163359
|
1791163536
|
|
0
|
|
0
|
Edit
Delete
|
|
37081
|
25225
|
51
|
5
|
80ef8d68e96afb51f1b6b62cc34883f0d7712b06
|
0
|
Playwright 全栈回放(chromium 桌面+移动)
|
1
|
name: E2E
"on":
push:
branches name: E2E
"on":
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
jobs:
e2e:
name: Playwright 全栈回放(chromium 桌面+移动)
runs-on: ubuntu-latest
env:
# playwright.config / webServer 据此连库;test-db-up.mjs 会据此名建 bentong_test
TEST_DATABASE_URL: postgresql://bentong:bentong@localhost:5432/bentong_test?schema=public
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "22"
- run: npm ci
working-directory: server
- run: npx prisma generate
working-directory: server
- run: npm ci
working-directory: 团购本地生活AI运营App
- run: npm run vendor
working-directory: 团购本地生活AI运营App
- run: npm ci
working-directory: e2e
- run: npx playwright install --with-deps chromium
working-directory: e2e
- run: npm test
working-directory: e2e
- if: always()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: e2e/playwright-report
retention-days: "7"
timeout-minutes: "25"
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: bentong
POSTGRES_PASSWORD: bentong
POSTGRES_USER: bentong
ports:
- 5432:5432
options: --health-cmd "pg_isready -U bentong -d bentong" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
e2e
|
null
|
["ubuntu-latest"]
|
31302
|
2
|
1791163536
|
1791163580
|
1791163359
|
1791163580
|
|
0
|
|
0
|
Edit
Delete
|
|
37082
|
25226
|
57
|
5
|
4b6378cb80cd602a26e25a066b9c302d50b981df
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version-file: .node-version
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
- name: Runtime and development dependency audit
run: pnpm check:deps
permissions:
contents: read
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
31303
|
3
|
1791168073
|
1791168141
|
1791168072
|
1791168141
|
|
0
|
|
0
|
Edit
Delete
|
|
37083
|
25227
|
57
|
5
|
0430e7e07522a0283fb6baf65978368cb42d246d
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version-file: .node-version
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
- name: Runtime and development dependency audit
run: pnpm check:deps
permissions:
contents: read
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
31304
|
2
|
1791168163
|
1791168224
|
1791168141
|
1791168224
|
|
0
|
|
0
|
Edit
Delete
|
|
37084
|
25228
|
13
|
5
|
6c80c00976d1c5ac4aaa5f76d10cf1e7b4f59448
|
0
|
Analyze (java)
|
1
|
name: CodeQL Analysis
"on":
push:
name: CodeQL Analysis
"on":
push:
branches: [develop, master, main]
pull_request:
branches: [develop, master, main]
schedule:
# 每周一凌晨3点运行
- cron: '0 3 * * 1'
jobs:
analyze:
name: Analyze (java)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Setup Java
uses: actions/setup-java@v4
with:
cache: gradle
distribution: temurin
java-version: "17"
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
queries: +security-extended,security-and-quality
- name: Grant Execute Permission
run: chmod +x ./gradlew
- name: Build
run: ./gradlew assembleDebug --stacktrace
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
category: /language:${{ matrix.language }}
timeout-minutes: "30"
strategy:
fail-fast: "false"
matrix:
language:
- java
permissions:
actions: read
contents: read
security-events: write
...
|
analyze
|
null
|
["ubuntu-latest"]
|
31305
|
2
|
1791169216
|
1791169239
|
1791169215
|
1791169239
|
|
0
|
|
0
|
Edit
Delete
|