Files
atomic-design-poc/scripts/ci-local.sh
T
ehoandClaude Opus 5 adfaa32a42 ci: gate on known advisories in the .NET dependency tree (RB-14)
npm audit --omit=dev gates the shipped frontend bundle; nothing equivalent
existed for the backend, so the entire .NET dependency tree — direct and
transitive — was unscanned (BIO-016 lists it first under "Absent").

The ticket's literal wording would not have worked. `dotnet list package
--vulnerable` is a reporting command: it prints the advisory table and exits
0 regardless. Verified with a throwaway project on System.Net.Http 4.3.0 —
severity High, GHSA-7jgj-8wvc-jh57, exit code 0. A bare `- run: dotnet list
package --vulnerable` would have added a line that reads like coverage in a
compliance review and enforces nothing, which is worse than leaving the gap
visible.

scripts/dotnet-audit.sh runs the scan and matches "has the following
vulnerable packages" — the exact sentence dotnet prints per project on a hit.
One script, two callers (ci.yml and ci-local.sh), so the workflow and the
local gate cannot drift apart.

No severity threshold and no suppression list: picking either before a real
advisory forces the question would be guessing at a policy nobody needs yet.
Secret scanning, BIO-016's other named absence, stays on the checklist.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-27 16:24:16 +02:00

47 lines
2.9 KiB
Bash
Executable File

#!/usr/bin/env bash
# Run the CI gate locally before pushing, so a red Gitea build is caught here first.
# Mirrors .github/workflows/ci.yml. The default runs every job that needs no browser or
# running servers (frontend + backend + api-client-drift). `--full` also runs the
# storybook-a11y job (self-contained). The e2e job needs the dev servers up, so it is NOT
# chained here — run it separately (see the note printed at the end).
#
# Assumes dependencies are installed (`npm ci` already run); CI installs them itself.
set -euo pipefail
cd "$(dirname "$0")/.."
# Steps chain with `;`, NOT `&&`. Under `set -e`, bash exempts every command of an
# AND-OR list except the last, so in `gen && git diff --exit-code` a CRASH in `gen`
# is silently swallowed — the diff never runs and the script sails on. That is not
# hypothetical: it hid a real `gen:api` crash (RB-09), which .github/workflows/ci.yml
# would have caught because it runs each step as its own `- run:`. With `;` errexit
# fires on the first failure. The one `( cd backend && ... )` below is safe as-is:
# a subshell propagates its own non-zero status, so errexit sees it.
step() { printf '\n\033[1;36m▶ %s\033[0m\n' "$1"; }
step "lint"; npm run lint
step "typecheck (spec files)"; npm run typecheck
step "dependency boundaries"; npm run dep:check
step "format:check (prettier)"; npm run format:check
step "check:tokens"; npm run check:tokens
step "check:seam"; npm run check:seam
step "test (vitest + coverage)"; npm run test:coverage
step "build --localize (nl+en)"; npx ng build ssp --localize; npx ng build behandelportal --localize
step "npm audit (shipped deps)"; npm audit --omit=dev
step "backend format + tests"; ( cd backend && dotnet format BigRegister.slnx --verify-no-changes && dotnet test BigRegister.slnx --filter "Category!=Integration" )
step "backend dependency audit"; ./scripts/dotnet-audit.sh
step "showcase snippets drift"; npm run gen:snippets; git diff --exit-code apps/ssp/src/app/showcase/snippets.generated.ts
step "behaviour spec drift"; npm run gen:behaviour-spec; git diff --exit-code libs/shared/docs/behaviour-spec.mdx
step "api-client drift"; npm run gen:api; git diff --exit-code libs/shared/src/infrastructure/api-client.ts backend/swagger.json
if [[ "${1:-}" == "--full" ]]; then
step "storybook build + axe (ssp)"; npm run build-storybook; npm run test-storybook:ci
step "storybook build + axe (behandelportal)"; npm run build-storybook:behandelportal; npm run test-storybook:ci:behandelportal
fi
printf '\n\033[1;32m✔ local CI passed\033[0m\n'
printf 'Note: the e2e job is not chained here (it is slow). Run it standalone with:\n'
printf ' npm run e2e\n'
printf 'Playwright starts the backend + ng serve itself (playwright.config.ts webServer),\n'
printf 'reusing an already-running app on 4200/5000 if present.\n'