name: ci # Formatting, linting, types and tests on every push and pull request. # # Blocking: ruff format, ruff check, pytest, prettier and svelte-check. # Non-blocking: eslint, which reports two `{@html}` XSS findings in collapsible-text.svelte. # Those are a real vulnerability rather than a lint nit — book descriptions from EPUB files # are not sanitized — and fixing them is a backend change. Drop the `continue-on-error` once # that lands, at which point every check blocks. # # The release workflow runs the blocking half again before it publishes anything. on: push: branches: ['**'] pull_request: jobs: backend: runs-on: ubuntu-latest # pytest-databases starts PostgreSQL in a container and then connects to it, and those are # two different addresses that have to be set separately: # # DOCKER_HOST which daemon to create the container on (_service.py get_docker_host) # POSTGRES_HOST where the test then connects (docker/postgres.py, default # 127.0.0.1 -- the job container's own loopback, where nothing listens, # because the database is a sibling container on another namespace) # # Setting only the first leaves the tests dialling 127.0.0.1 and timing out with # "Service 'pytest_databases_postgres' failed to come online". # # If the runner is ever given its own dind sidecar, drop this services block and keep the # two env vars pointed at whatever host it exposes. services: docker: image: docker:27-dind options: --privileged env: DOCKER_TLS_CERTDIR: '' env: DOCKER_HOST: tcp://docker:2375 POSTGRES_HOST: docker defaults: run: working-directory: backend steps: - uses: actions/checkout@v4 # astral-sh/setup-uv is not mirrored on gitea.com, unlike the actions used elsewhere # here, so install uv directly rather than depending on DEFAULT_ACTIONS_URL. - name: Install uv run: | curl -LsSf https://astral.sh/uv/install.sh | sh echo "$HOME/.local/bin" >> "$GITHUB_PATH" - name: Install dependencies run: uv sync --locked - name: Format run: uv run ruff format --check src/ tests/ - name: Lint run: uv run ruff check src/ tests/ - name: Tests run: uv run pytest tests/ -q frontend: runs-on: ubuntu-latest defaults: run: working-directory: frontend steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: 24 - name: Enable pnpm run: corepack enable - name: Install dependencies run: pnpm install --frozen-lockfile # Split out of `pnpm lint` (which is prettier && eslint) so formatting can block # while eslint does not. - name: Format run: pnpm exec prettier --check . - name: Lint run: pnpm exec eslint . continue-on-error: true - name: Types run: pnpm check