CI / changes (push) Successful in 7s
CI / lint (push) Successful in 1m57s
CI / frontend (push) Successful in 2m45s
CI / backend (push) Successful in 1m57s
CI / e2e (push) Failing after 4m10s
CI / semgrep (push) Successful in 1m18s
CI / api-client-drift (push) Successful in 2m9s
CI / storybook-a11y (push) Successful in 11m5s
Angular 22.1.x emits `var(--%NS%name)` for every CSS custom property in a component `styles:` block. No `@angular/core` release substitutes the placeholder, so all `--rhc-*` tokens resolve to nothing and the UI breaks. `npm run ci` does not catch it; only the Storybook axe job does. Pin every `@angular*` entry to the exact version 22.0.5, so a plain `npm install` cannot pull 22.1.x back in. Holding at 22.0.5 leaves three moderate advisories open, which made the audit step fail: GHSA-p297-fm68-3q8c and GHSA-hh8m-fm6v-7cvg. Neither is reachable. The app calls no `withRequestsMadeViaParent` and no `provideClientHydration`, and binds no untrusted value into a directive host binding. The audit gate therefore runs at `--audit-level=high`. A high advisory still fails the build. Restore the default audit level together with the upgrade, after an Angular release substitutes the placeholder. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
51 lines
3.3 KiB
Bash
Executable File
51 lines
3.3 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Run the CI gate locally before pushing, so a red Gitea build is caught here first.
|
|
# Mirrors .github/workflows/ci.yml. The default runs every job that needs no browser or
|
|
# running servers (frontend + backend + api-client-drift). `--full` also runs the
|
|
# storybook-a11y job (self-contained). The e2e job needs the dev servers up, so it is NOT
|
|
# chained here — run it separately (see the note printed at the end).
|
|
#
|
|
# Assumes dependencies are installed (`npm ci` already run); CI installs them itself.
|
|
set -euo pipefail
|
|
cd "$(dirname "$0")/.."
|
|
|
|
# Steps chain with `;`, NOT `&&`. Under `set -e`, bash exempts every command of an
|
|
# AND-OR list except the last, so in `gen && git diff --exit-code` a CRASH in `gen`
|
|
# is silently swallowed — the diff never runs and the script sails on. That is not
|
|
# hypothetical: it hid a real `gen:api` crash (RB-09), which .github/workflows/ci.yml
|
|
# would have caught because it runs each step as its own `- run:`. With `;` errexit
|
|
# fires on the first failure. The one `( cd backend && ... )` below is safe as-is:
|
|
# a subshell propagates its own non-zero status, so errexit sees it.
|
|
|
|
step() { printf '\n\033[1;36m▶ %s\033[0m\n' "$1"; }
|
|
|
|
step "lint"; npm run lint
|
|
step "typecheck (spec files)"; npm run typecheck
|
|
step "dependency boundaries"; npm run dep:check
|
|
step "format:check (prettier)"; npm run format:check
|
|
step "check:tokens"; npm run check:tokens
|
|
step "check:seam"; npm run check:seam
|
|
step "test (vitest + coverage)"; npm run test:coverage
|
|
step "build --localize (nl+en)"; npx ng build ssp --localize; npx ng build behandelportal --localize
|
|
step "npm audit (shipped deps)"; npm audit --omit=dev --audit-level=high
|
|
step "backend format + tests"; ( cd backend && dotnet format BigRegister.slnx --verify-no-changes && dotnet test BigRegister.slnx --filter "Category!=Integration" )
|
|
step "backend dependency audit"; ./scripts/dotnet-audit.sh
|
|
step "showcase snippets drift"; npm run gen:snippets; git diff --exit-code apps/ssp/src/app/showcase/snippets.generated.ts
|
|
step "behaviour spec drift"; npm run gen:behaviour-spec; git diff --exit-code libs/shared/docs/behaviour-spec.mdx
|
|
step "api-client drift"; npm run gen:api; git diff --exit-code libs/shared/src/infrastructure/api-client.ts backend/swagger.json
|
|
|
|
# Accept both `npm run ci -- --full` (arrives as $1) and `npm run ci --full` (npm parses the
|
|
# flag itself and exports npm_config_full=true instead of passing it through). CLAUDE.md
|
|
# documents the second form, which used to skip these two steps silently and still print
|
|
# "local CI passed" — a gate that reported success without running.
|
|
if [[ "${1:-}" == "--full" || "${npm_config_full:-}" == "true" ]]; then
|
|
step "storybook build + axe (ssp)"; npm run build-storybook; npm run test-storybook:ci
|
|
step "storybook build + axe (behandelportal)"; npm run build-storybook:behandelportal; npm run test-storybook:ci:behandelportal
|
|
fi
|
|
|
|
printf '\n\033[1;32m✔ local CI passed\033[0m\n'
|
|
printf 'Note: the e2e job is not chained here (it is slow). Run it standalone with:\n'
|
|
printf ' npm run e2e\n'
|
|
printf 'Playwright starts the backend + ng serve itself (playwright.config.ts webServer),\n'
|
|
printf 'reusing an already-running app on 4200/5000 if present.\n'
|