#!/usr/bin/env bash # Run the CI gate locally before pushing, so a red Gitea build is caught here first. # Mirrors .github/workflows/ci.yml. The default runs every job that needs no browser or # running servers (frontend + backend + api-client-drift). `--full` also runs the # storybook-a11y job (self-contained). The e2e job needs the dev servers up, so it is NOT # chained here — run it separately (see the note printed at the end). # # Assumes dependencies are installed (`npm ci` already run); CI installs them itself. set -euo pipefail cd "$(dirname "$0")/.." # Steps chain with `;`, NOT `&&`. Under `set -e`, bash exempts every command of an # AND-OR list except the last, so in `gen && git diff --exit-code` a CRASH in `gen` # is silently swallowed — the diff never runs and the script sails on. That is not # hypothetical: it hid a real `gen:api` crash (RB-09), which .github/workflows/ci.yml # would have caught because it runs each step as its own `- run:`. With `;` errexit # fires on the first failure. The one `( cd backend && ... )` below is safe as-is: # a subshell propagates its own non-zero status, so errexit sees it. step() { printf '\n\033[1;36m▶ %s\033[0m\n' "$1"; } step "lint"; npm run lint step "typecheck (spec files)"; npm run typecheck step "dependency boundaries"; npm run dep:check step "format:check (prettier)"; npm run format:check step "check:tokens"; npm run check:tokens step "check:seam"; npm run check:seam step "test (vitest + coverage)"; npm run test:coverage step "build --localize (nl+en)"; npx ng build ssp --localize; npx ng build behandelportal --localize step "npm audit (shipped deps)"; npm audit --omit=dev --audit-level=high step "backend format + tests"; ( cd backend && dotnet format BigRegister.slnx --verify-no-changes && dotnet test BigRegister.slnx --filter "Category!=Integration" ) step "backend dependency audit"; ./scripts/dotnet-audit.sh step "showcase snippets drift"; npm run gen:snippets; git diff --exit-code apps/ssp/src/app/showcase/snippets.generated.ts step "behaviour spec drift"; npm run gen:behaviour-spec; git diff --exit-code libs/shared/docs/behaviour-spec.mdx step "api-client drift"; npm run gen:api; git diff --exit-code libs/shared/src/infrastructure/api-client.ts backend/swagger.json # Accept both `npm run ci -- --full` (arrives as $1) and `npm run ci --full` (npm parses the # flag itself and exports npm_config_full=true instead of passing it through). CLAUDE.md # documents the second form, which used to skip these two steps silently and still print # "local CI passed" — a gate that reported success without running. if [[ "${1:-}" == "--full" || "${npm_config_full:-}" == "true" ]]; then step "storybook build + axe (ssp)"; npm run build-storybook; npm run test-storybook:ci step "storybook build + axe (behandelportal)"; npm run build-storybook:behandelportal; npm run test-storybook:ci:behandelportal fi printf '\n\033[1;32m✔ local CI passed\033[0m\n' printf 'Note: the e2e job is not chained here (it is slow). Run it standalone with:\n' printf ' npm run e2e\n' printf 'Playwright starts the backend + ng serve itself (playwright.config.ts webServer),\n' printf 'reusing an already-running app on 4200/5000 if present.\n'