Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
192 changes: 192 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,192 @@
name: CI

on:
pull_request:
push:
branches:
- main
- staging

jobs:
format:
name: Formatting checks
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 22

- name: Install dashboard dependencies
working-directory: dashboard
run: npm ci

- name: Check dashboard formatting (Prettier)
working-directory: dashboard
run: npm run format:check

- name: Install listener dependencies
working-directory: listener
run: npm ci

- name: Check listener formatting (Prettier)
working-directory: listener
run: npm run format:check

frontend:
name: Frontend (lint, typecheck, test)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 20
cache: "npm"
cache-dependency-path: dashboard/package-lock.json
- name: Install dependencies
working-directory: dashboard
run: npm ci
- name: Run lint
working-directory: dashboard
run: npm run lint
- name: TypeScript check (build)
working-directory: dashboard
run: npm run build
- name: Run tests
working-directory: dashboard
run: npm test --silent
- name: Run wallet integration tests
working-directory: dashboard
run: npm run test:wallet --silent
- name: Upload wallet test report
if: always()
uses: actions/upload-artifact@v4
with:
name: wallet-integration-report
path: dashboard/reports/wallet-integration.json

listener:
name: Listener (lint, typecheck, test)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 20
cache: "npm"
cache-dependency-path: listener/package-lock.json
- name: Install dependencies
working-directory: listener
run: npm ci
- name: Run lint
working-directory: listener
run: npm run lint
- name: TypeScript check
working-directory: listener
run: npm run typecheck
- name: Run tests
working-directory: listener
run: npm test --silent

check-migrations:
name: Check Pending Migrations
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 20
cache: "npm"
cache-dependency-path: listener/package-lock.json
- name: Install dependencies
working-directory: listener
run: npm ci
- name: Create test database and apply all migrations
working-directory: listener
run: |
mkdir -p ./data
npm run migrate
- name: Check for pending migrations
working-directory: listener
run: npm run check-migrations

license-check:
name: License compliance
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 20

# Install license-checker once globally — cheaper than adding it to each
# package's devDependencies and re-installing across three npm ci runs.
- name: Install license-checker
run: npm install -g license-checker@25

- name: Install dashboard dependencies
working-directory: dashboard
run: npm ci

- name: Check dashboard licenses
working-directory: dashboard
run: npm run license:check

- name: Install listener dependencies
working-directory: listener
run: npm ci

- name: Check listener licenses
working-directory: listener
run: npm run license:check

- name: Install frontend dependencies
working-directory: frontend
run: npm ci

- name: Check frontend licenses
working-directory: frontend
run: npm run license:check

- name: Install Rust toolchain
uses: actions-rs/toolchain@v1
with:
toolchain: stable
profile: minimal
override: true

- name: Check Rust licenses
uses: EmbarkStudios/cargo-deny-action@v2
with:
command: check licenses
manifest-path: contract/Cargo.toml

rust:
name: Rust (fmt check, tests, fuzz)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Rust toolchain
uses: actions-rs/toolchain@v1
with:
toolchain: stable
profile: minimal
override: true
- name: Check formatting
working-directory: contract
run: |
rustup component add rustfmt || true
cargo fmt --all -- --check
- name: Run unit tests
working-directory: contract
run: cargo test --workspace --all-features --verbose
- name: Run fuzz tests
working-directory: contract
run: cargo test fuzz_ --verbose -- --nocapture
50 changes: 50 additions & 0 deletions contract/deny.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
# cargo-deny configuration
# Docs: https://embarkstudios.github.io/cargo-deny/

[graph]
# Treat dev-dependencies as out-of-scope for license checks —
# only production (non-dev) crates need to meet the license policy.
exclude-dev = true

# ---------------------------------------------------------------------------
# License policy
# ---------------------------------------------------------------------------
[licenses]
# Confidence threshold for license text matching (0.0–1.0).
# 0.8 is cargo-deny's default; keep it to avoid false negatives.
confidence-threshold = 0.8

# Approved SPDX identifiers. These align with the Node.js policy in
# scripts/license-policy.json so the whole project shares one policy.
allow = [
"MIT",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"ISC",
"BSD-2-Clause",
"BSD-3-Clause",
"0BSD",
"CC0-1.0",
"Unicode-DFS-2016",
"Unlicense",
"Zlib",
]

# Crates that carry multiple licenses (A OR B) are acceptable as long as
# at least one expression satisfies the allow list — cargo-deny handles
# this automatically with `allow` rather than `deny`.

# ---------------------------------------------------------------------------
# Advisories (security)
# ---------------------------------------------------------------------------
[advisories]
# Fail on any unpatched vulnerability in the RustSec advisory database.
ignore = []

# ---------------------------------------------------------------------------
# Bans (duplicate crates / wildcard deps)
# ---------------------------------------------------------------------------
[bans]
# Warn when the same crate appears more than once with different versions.
multiple-versions = "warn"
wildcards = "deny"
Loading
Loading