From c94e8f9c4fc4c09852f58aa263fd9c0c4cfbd4e1 Mon Sep 17 00:00:00 2001 From: Masked18 Date: Sun, 27 Sep 2026 16:25:09 +0100 Subject: [PATCH] fix(workflows): resolve 12 CI/CD issues across 12 workflow files --- .github/workflows/autoscaling.yml | 26 +++++++++++++-- .github/workflows/backup.yml | 8 ++--- .github/workflows/bundle-size.yml | 1 + .github/workflows/canary.yml | 1 + .github/workflows/coverage.yml | 3 +- .github/workflows/fuzz-testing.yml | 4 +-- .github/workflows/performance-monitoring.yml | 7 ++-- .github/workflows/performance.yml | 23 ++++++------- .github/workflows/release.yml | 2 ++ .github/workflows/sdk-generation.yml | 2 +- .github/workflows/security-audit-pipeline.yml | 5 --- .github/workflows/security-audit.yml | 32 +++++++++++-------- 12 files changed, 70 insertions(+), 44 deletions(-) diff --git a/.github/workflows/autoscaling.yml b/.github/workflows/autoscaling.yml index 71eba1c8..c4de959d 100644 --- a/.github/workflows/autoscaling.yml +++ b/.github/workflows/autoscaling.yml @@ -9,12 +9,32 @@ name: Auto-Scaling # - Max instances: configurable per profile (default 4, burst 8) # - Policies: scale-up on queue depth; scale-down via concurrency cancel + idle timeout -on: workflow_dispatch +on: + workflow_dispatch: + inputs: + scale_profile: + description: 'Scaling profile to apply' + required: false + default: 'balanced' + type: choice + options: + - conservative + - balanced + - burst + min_parallel: + description: 'Override minimum parallel jobs (leave blank to use profile default)' + required: false + type: string + default: '' + max_parallel: + description: 'Override maximum parallel jobs (leave blank to use profile default)' + required: false + type: string + default: '' concurrency: group: autoscaling-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true - env: SERVICE: agenticpay # Scaling profiles — min/max parallel jobs per matrix @@ -153,7 +173,7 @@ jobs: - name: Emit scaling metrics run: | - echo "::notice title=Shard::${{ matrix.shard }}/${{ strategy.job-total }}" + echo "::notice title=Shard::${{ matrix.shard }} of ${{ strategy.job-total }}" echo "::notice title=Max Parallel::${{ needs.resolve-scaling-policy.outputs.max_parallel }}" cost-monitor-hook: diff --git a/.github/workflows/backup.yml b/.github/workflows/backup.yml index ecb7195f..902f4c72 100644 --- a/.github/workflows/backup.yml +++ b/.github/workflows/backup.yml @@ -91,14 +91,14 @@ jobs: - name: Notify on failure if: failure() - uses: slackapi/slack-github-action@v1.24.0 + uses: slackapi/slack-github-action@v2.1.0 with: + webhook: ${{ secrets.SLACK_WEBHOOK_URL }} + webhook-type: incoming-webhook payload: | { "attachments": [{ "color": "danger", "text": "❌ Database backup workflow failed for ${{ github.repository }}" }] - } - env: - SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }} \ No newline at end of file + } \ No newline at end of file diff --git a/.github/workflows/bundle-size.yml b/.github/workflows/bundle-size.yml index 0b7adb33..e936fd43 100644 --- a/.github/workflows/bundle-size.yml +++ b/.github/workflows/bundle-size.yml @@ -23,6 +23,7 @@ jobs: with: node-version: '20' cache: 'npm' + cache-dependency-path: frontend/package-lock.json - name: Install dependencies run: npm ci diff --git a/.github/workflows/canary.yml b/.github/workflows/canary.yml index c20b87ea..07f28758 100644 --- a/.github/workflows/canary.yml +++ b/.github/workflows/canary.yml @@ -39,6 +39,7 @@ jobs: rollback: name: Auto-Rollback + needs: [canary-10, canary-50, production-rollout] if: failure() runs-on: ubuntu-latest steps: diff --git a/.github/workflows/coverage.yml b/.github/workflows/coverage.yml index 6ecf0383..a9235d03 100644 --- a/.github/workflows/coverage.yml +++ b/.github/workflows/coverage.yml @@ -23,6 +23,7 @@ jobs: with: node-version: '20' cache: 'npm' + cache-dependency-path: frontend/package-lock.json - name: Install dependencies run: npm ci @@ -36,6 +37,6 @@ jobs: uses: codecov/codecov-action@v4 with: token: ${{ secrets.CODECOV_TOKEN }} - directory: frontend/coverage + directory: coverage flags: frontend fail_ci_if_error: false diff --git a/.github/workflows/fuzz-testing.yml b/.github/workflows/fuzz-testing.yml index 3e44d9e9..91258b15 100644 --- a/.github/workflows/fuzz-testing.yml +++ b/.github/workflows/fuzz-testing.yml @@ -126,7 +126,7 @@ jobs: - name: Install Rust uses: dtolnay/rust-toolchain@stable with: - components: rustfmt, clippy, llvm-tools-preview + components: rustfmt, clippy, llvm-tools - name: Install grcov run: cargo install grcov @@ -149,7 +149,7 @@ jobs: --output-path coverage.lcov - name: Upload Coverage to Codecov - uses: codecov/codecov-action@v5 + uses: codecov/codecov-action@v4 with: file: contracts/coverage.lcov flags: fuzz-testing diff --git a/.github/workflows/performance-monitoring.yml b/.github/workflows/performance-monitoring.yml index 6ffc07db..6b2d74fa 100644 --- a/.github/workflows/performance-monitoring.yml +++ b/.github/workflows/performance-monitoring.yml @@ -28,15 +28,16 @@ jobs: - name: Build bundle run: npm run build + working-directory: frontend env: NODE_ENV: production ANALYZE: 'false' + NEXT_TELEMETRY_DISABLED: '1' - name: Check bundle size run: | BUNDLE_SIZE=$(du -sb frontend/.next/static | awk '{print $1}') - BUNDLE_SIZE_MB=$(echo "scale=2; $BUNDLE_SIZE / 1048576" | bc) - MAX_SIZE_MB=5.0 + BUNDLE_SIZE_MB=$(echo "scale=2; $BUNDLE_SIZE / 1048576" | bc) MAX_SIZE_MB=5.0 echo "Bundle Size: ${BUNDLE_SIZE_MB}MB" @@ -49,7 +50,7 @@ jobs: - name: Analyze bundle with lighthouse run: | - npm install -g @lhci/cli@0.11.x + npm install -g @lhci/cli@0.14.x lhci autorun --config=./lighthouse/lighthouse.config.json || true continue-on-error: true diff --git a/.github/workflows/performance.yml b/.github/workflows/performance.yml index 6a0cf12f..8fecf601 100644 --- a/.github/workflows/performance.yml +++ b/.github/workflows/performance.yml @@ -40,15 +40,12 @@ jobs: NEXT_PUBLIC_VERCEL_ENV: preview NODE_ENV: production - - name: Export static build for LHCI - run: npx next export -o out - working-directory: frontend - continue-on-error: true - - name: Start preview server + # next export was removed in Next.js 14; use `next start` against the + # production build instead. run: | - npx serve out -l 3000 & - sleep 3 + npx next start -p 3000 & + sleep 5 echo "Server ready" working-directory: frontend continue-on-error: true @@ -165,11 +162,15 @@ jobs: fi - name: Block PR on budget exceeded - if: steps.bundle-check.outputs.js_size > 500 || steps.bundle-check.outputs.css_size > 200 run: | - echo "::error::Bundle size budget exceeded. JS: ${{ steps.bundle-check.outputs.js_size }}KB, CSS: ${{ steps.bundle-check.outputs.css_size }}KB" - echo "To override: add label 'performance-override' to this PR" - exit 1 + JS_SIZE="${{ steps.bundle-check.outputs.js_size }}" + CSS_SIZE="${{ steps.bundle-check.outputs.css_size }}" + if [ "${JS_SIZE}" -gt 500 ] || [ "${CSS_SIZE}" -gt 200 ]; then + echo "::error::Bundle size budget exceeded. JS: ${JS_SIZE}KB, CSS: ${CSS_SIZE}KB" + echo "To override: add label 'performance-override' to this PR" + exit 1 + fi + echo "✅ Bundle size within budget (JS: ${JS_SIZE}KB, CSS: ${CSS_SIZE}KB)" performance-trend: name: Performance Trend diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 5b03fdb6..e4e1f407 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -30,6 +30,8 @@ jobs: - uses: actions/setup-node@v4 with: node-version: ${{ env.NODE_VERSION }} + cache: 'npm' + cache-dependency-path: package-lock.json - run: npm ci diff --git a/.github/workflows/sdk-generation.yml b/.github/workflows/sdk-generation.yml index 2cbe08c4..7ead512e 100644 --- a/.github/workflows/sdk-generation.yml +++ b/.github/workflows/sdk-generation.yml @@ -77,7 +77,7 @@ jobs: path: backend/docs/api/openapi/ - name: Install oasdiff - run: npm install -g @openapi-diff/openapi-diff + run: npm install -g @oasdiff/oasdiff - name: Fetch previous OpenAPI spec run: | diff --git a/.github/workflows/security-audit-pipeline.yml b/.github/workflows/security-audit-pipeline.yml index a38cef44..3001f923 100644 --- a/.github/workflows/security-audit-pipeline.yml +++ b/.github/workflows/security-audit-pipeline.yml @@ -229,11 +229,6 @@ jobs: if: >- ${{ (github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && (github.event.inputs.scan_type == 'all' || github.event.inputs.scan_type == 'dast' || github.event_name != 'workflow_dispatch') }} - services: - backend: - image: node:20-alpine - ports: - - 3001:3001 steps: - name: Checkout uses: actions/checkout@v4 diff --git a/.github/workflows/security-audit.yml b/.github/workflows/security-audit.yml index b8c1d042..c4ca363f 100644 --- a/.github/workflows/security-audit.yml +++ b/.github/workflows/security-audit.yml @@ -62,34 +62,37 @@ jobs: --exclude-low \ --solc-remaps "" || true - # Convert to human-readable format + # Generate a human-readable Markdown checklist slither . \ --exclude-dependencies \ --exclude-low \ - --risk high,medium \ - --output-to-file {severity}-{type}-slither-report.md + --checklist \ + --markdown-root . \ + 2>&1 > slither-checklist.md || true - name: Parse Slither Results id: parse_slither working-directory: contracts run: | - if [ -f "HIGH-high-slither-report.md" ]; then - echo "slither_high_findings=true" >> $GITHUB_OUTPUT - echo "## 🔴 Slither: Critical Findings Found" >> $GITHUB_STEP_SUMMARY - cat HIGH-high-slither-report.md >> $GITHUB_STEP_SUMMARY - fi + if [ -f "slither-checklist.md" ]; then + # Check for high severity in the checklist output + if grep -qi "high" slither-checklist.md; then + echo "slither_high_findings=true" >> $GITHUB_OUTPUT + echo "## 🔴 Slither: Critical Findings Found" >> $GITHUB_STEP_SUMMARY + cat slither-checklist.md >> $GITHUB_STEP_SUMMARY + fi - if [ -f "MEDIUM-medium-slither-report.md" ]; then - echo "slither_medium_findings=true" >> $GITHUB_OUTPUT - echo "## 🟠 Slither: Medium-Risk Findings" >> $GITHUB_STEP_SUMMARY - cat MEDIUM-medium-slither-report.md >> $GITHUB_STEP_SUMMARY + if grep -qi "medium" slither-checklist.md; then + echo "slither_medium_findings=true" >> $GITHUB_OUTPUT + echo "## 🟠 Slither: Medium-Risk Findings" >> $GITHUB_STEP_SUMMARY + fi fi - name: Move Slither reports if: always() working-directory: contracts run: | - mv -f *slither-report.md ${{ github.workspace }}/${{ env.SECURITY_REPORT_DIR }}/ || true + mv -f slither-checklist.md ${{ github.workspace }}/${{ env.SECURITY_REPORT_DIR }}/slither-checklist.md || true mv -f ${{ runner.temp }}/slither-report.json ${{ github.workspace }}/${{ env.SECURITY_REPORT_DIR }}/ || true - name: Upload Slither Artifacts @@ -169,7 +172,8 @@ jobs: for file in mythril-*.json; do if [ -f "$file" ]; then # Count issues by severity - CRITICAL=$((CRITICAL + $(jq '[.issues[] | select(.severity=="High")] | length' "$file" 2>/dev/null || echo 0))) + FILE_CRITICAL=$(jq '[.issues[] | select(.severity=="High")] | length' "$file" 2>/dev/null || echo 0) + CRITICAL_COUNT=$((CRITICAL_COUNT + FILE_CRITICAL)) fi done