ci: split check.yml, drop dead caches, prebuild cargo-audit (#232) #309

Merged
maximus merged 2 commits from issue-232-split-ci-workflows into main 2026-07-27 22:53:17 +00:00
6 changed files with 237 additions and 124 deletions
Showing only changes of commit 263ebe1495 - Show all commits

View file

@ -0,0 +1,58 @@
name: Security audit
# Daily RustSec coverage (#232).
#
# check-rust.yml only runs when src-tauri/ changes, which is roughly 1 PR in
# 40 — without this workflow a new advisory published against an unchanged
# dependency would go unnoticed for weeks.
#
# Runs without a Rust toolchain: cargo-audit only reads Cargo.lock, so the
# binary is invoked directly instead of as a `cargo` subcommand. That keeps
# this to ~1-2 min rather than the ~22 min a scheduled check-rust would cost
# every day on a capacity-1 runner.
#
# Note: PATH is deliberately NOT overridden at job level (unlike check-rust,
# which needs /root/.cargo/bin for the toolchain) so that the install dir
# taiki-e/install-action appends to $GITHUB_PATH stays effective.
on:
schedule:
# 06:00 UTC daily
- cron: '0 6 * * *'
workflow_dispatch:
concurrency:
group: ci-audit-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
audit:
runs-on: ubuntu
container: ubuntu:22.04
steps:
- name: Install Node.js 20
run: |
apt-get update
apt-get install -y --no-install-recommends \
curl ca-certificates git tar gzip
# Node.js is required by actions/checkout and taiki-e/install-action
# (JavaScript actions need `node` in the container PATH).
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
apt-get install -y nodejs
node --version
- name: Checkout
uses: https://github.com/actions/checkout@v4
- name: Install cargo-audit
uses: https://github.com/taiki-e/install-action@v2
with:
tool: cargo-audit
# Unlike the PR run in check-rust.yml, this one is meant to fail loudly:
# it IS the notification channel for a newly published advisory.
- name: cargo audit
run: cargo-audit audit --file src-tauri/Cargo.lock

View file

@ -0,0 +1,63 @@
name: PR Check — Frontend
# Frontend half of the former check.yml (split in #232).
#
# Filtered with paths-ignore rather than an allowlist: this job costs ~2.5 min,
# so running it when it was not strictly needed is cheap, while silently NOT
# running it is not. A root-level config file added later would drop out of an
# allowlist without anyone noticing; here it fails safe.
#
# No `branches:` filter — see check-rust.yml.
on:
pull_request:
paths-ignore:
- 'src-tauri/**'
- 'docs/**'
- 'reports/**'
- 'tasks/**'
- '.github/**'
- '.forgejo/workflows/check-rust.yml'
- '.forgejo/workflows/audit.yml'
- '.forgejo/workflows/release.yml'
- '*.md'
- 'LICENSE'
# Distinct group from the rust workflow — see check-rust.yml.
concurrency:
group: ci-frontend-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
frontend:
runs-on: ubuntu
container: ubuntu:22.04
steps:
- name: Install Node.js 20
run: |
apt-get update
apt-get install -y --no-install-recommends curl ca-certificates git
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
apt-get install -y nodejs
node --version
npm --version
- name: Checkout
uses: https://github.com/actions/checkout@v4
# No npm cache step here, deliberately — same reason as the cargo caches
# in check-rust.yml: the restore misses and the save times out against
# the runner's cache server (#234), which cost ~23s per run for nothing.
# Restore it together with rust-cache once #234 is fixed.
- name: Install dependencies
run: npm ci
- name: Build (tsc + vite)
run: npm run build
- name: Tests (vitest)
run: npm test

View file

@ -0,0 +1,88 @@
name: PR Check — Rust
# Rust half of the former check.yml (split in #232).
#
# Only runs when Rust actually changes. On this repo roughly 1 PR in 40 touches
# src-tauri/, and the runner has capacity 1 — jobs queue instead of running in
# parallel, so every minute spent here is a minute the next PR waits.
#
# No `branches:` filter on purpose. `branches: [main]` never matched a PR
# stacked on top of another feature branch, which is what /autopilot produces:
# 4 of the 5 PRs in the feature-gating milestone ran no CI at all.
on:
pull_request:
paths:
- 'src-tauri/**'
- '.forgejo/workflows/check-rust.yml'
# Cancel obsolete runs (e.g. on force-push) so only the latest commit runs.
# Distinct from the frontend group: a shared group would make the two
# workflows cancel each other on a PR that touches both.
concurrency:
group: ci-rust-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
rust:
runs-on: ubuntu
container: ubuntu:22.04
env:
PATH: /root/.cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
CARGO_TERM_COLOR: always
# Nothing persists between runs (see the caching note below), so
# incremental artifacts get written and never reused — pure overhead.
# Test debug info is dead weight here for the same reason.
CARGO_INCREMENTAL: 0
CARGO_PROFILE_TEST_DEBUG: 0
steps:
- name: Install system dependencies, Node.js and Rust
run: |
apt-get update
apt-get install -y --no-install-recommends \
curl wget git ca-certificates build-essential pkg-config \
libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev libssl-dev \
libdbus-1-dev
# Node.js is required by actions/checkout and taiki-e/install-action
# (they are JavaScript actions and need `node` in the container PATH).
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
apt-get install -y nodejs
# Rust toolchain
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --default-toolchain stable --profile minimal
node --version
rustc --version
cargo --version
- name: Checkout
uses: https://github.com/actions/checkout@v4
# No actions/cache step here, deliberately. The job container cannot
# reach the runner's cache server (#234): the restore times out into a
# miss AND the save times out, so the cache cost ~7 min per run and
# returned nothing. Bring caching back through Swatinem/rust-cache once
# #234 is fixed — not before, it shares the same backend.
- name: cargo check
run: cargo check --manifest-path src-tauri/Cargo.toml --all-targets
- name: cargo test
run: cargo test --manifest-path src-tauri/Cargo.toml --all-targets
# Prebuilt binary. `cargo install --locked cargo-audit` recompiled the
# tool from source on every single run (~4m40s). No continue-on-error:
# a tooling failure should fail the job rather than be swallowed.
- name: Install cargo-audit
uses: https://github.com/taiki-e/install-action@v2
with:
tool: cargo-audit
# Advisories are informational — they can land on unrelated crates and
# would otherwise stall unrelated work — so the step is non-blocking.
# It no longer hides real failures behind `|| true` though. Daily
# RustSec coverage outside Rust PRs lives in audit.yml.
- name: cargo audit
continue-on-error: true
run: cargo audit --file src-tauri/Cargo.lock

View file

@ -1,115 +0,0 @@
name: PR Check
# Validates Rust + frontend on every PR opened against main.
# Goal: catch compile errors, type errors, and failing tests BEFORE merge,
# instead of waiting for the release tag (which is when release.yml runs).
#
# Trigger is `pull_request` only — the previous `push` trigger duplicated
# every run when a branch was pushed and immediately opened as a PR (#171).
# Trade-off: branches pushed without an open PR don't get CI feedback. Open
# a draft PR if you want feedback before requesting review.
on:
pull_request:
branches:
- main
# Cancel obsolete runs (e.g. on force-push) so only the latest commit runs.
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
rust:
runs-on: ubuntu
container: ubuntu:22.04
env:
PATH: /root/.cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
CARGO_TERM_COLOR: always
steps:
- name: Install system dependencies, Node.js and Rust
run: |
apt-get update
apt-get install -y --no-install-recommends \
curl wget git ca-certificates build-essential pkg-config \
libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev libssl-dev \
libdbus-1-dev
# Node.js is required by actions/checkout and actions/cache (they
# are JavaScript actions and need `node` in the container PATH).
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
apt-get install -y nodejs
# Rust toolchain
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --default-toolchain stable --profile minimal
node --version
rustc --version
cargo --version
- name: Checkout
uses: https://github.com/actions/checkout@v4
- name: Cache cargo registry and git
uses: https://github.com/actions/cache@v4
with:
path: |
~/.cargo/registry
~/.cargo/git
key: ${{ runner.os }}-cargo-registry-${{ hashFiles('src-tauri/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-registry-
- name: Cache cargo build target
uses: https://github.com/actions/cache@v4
with:
path: src-tauri/target
key: ${{ runner.os }}-cargo-target-${{ hashFiles('src-tauri/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-target-
- name: cargo check
run: cargo check --manifest-path src-tauri/Cargo.toml --all-targets
- name: cargo test
run: cargo test --manifest-path src-tauri/Cargo.toml --all-targets
# Informational audit of transitive dependencies. Failure does not
# block the CI (advisories can appear on unrelated crates and stall
# unrelated work); surface them in the job log so we see them on
# every PR run and can react in a follow-up.
- name: cargo audit
continue-on-error: true
run: |
cargo install --locked cargo-audit || true
cargo audit --file src-tauri/Cargo.lock || true
frontend:
runs-on: ubuntu
container: ubuntu:22.04
steps:
- name: Install Node.js 20
run: |
apt-get update
apt-get install -y --no-install-recommends curl ca-certificates git
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
apt-get install -y nodejs
node --version
npm --version
- name: Checkout
uses: https://github.com/actions/checkout@v4
- name: Cache npm cache
uses: https://github.com/actions/cache@v4
with:
path: ~/.npm
key: ${{ runner.os }}-npm-${{ hashFiles('package-lock.json') }}
restore-keys: |
${{ runner.os }}-npm-
- name: Install dependencies
run: npm ci
- name: Build (tsc + vite)
run: npm run build
- name: Tests (vitest)
run: npm test

View file

@ -159,9 +159,15 @@ Pour maintenir l'éligibilité aux crédits d'impôt R&D (RS&DE fédéral + CRIC
## CI/CD ## CI/CD
- **`check.yml`** (Forgejo Actions + miroir GitHub) — déclenché sur chaque push de branche (sauf `main`) et chaque PR vers `main`. Lance `cargo check`, `cargo test`, `npm run build` (tsc + vite) et `npm test` (vitest). Doit être vert avant tout merge. Workflows Forgejo Actions dans `.forgejo/workflows/`. Le runner est à **capacité 1** — les jobs se suivent, ils ne tournent pas en parallèle.
- **`check-rust.yml`** — déclenché sur les PR touchant `src-tauri/**`. Lance `cargo check`, `cargo test` et un `cargo audit` informatif. Doit être vert avant tout merge.
- **`check-frontend.yml`** — déclenché sur les PR, sauf si tous les fichiers modifiés sont du Rust, de la doc ou du markdown. Lance `npm run build` (tsc + vite) et `npm test` (vitest). Doit être vert avant tout merge.
- **`audit.yml`** — audit RustSec quotidien (06:00 UTC) + `workflow_dispatch`, pour couvrir les avis de sécurité entre deux PR Rust. Échec bloquant.
- **`release.yml`** — déclenché par les tags `v*`. Build Windows (NSIS `.exe`) + Linux (`.deb`, `.rpm`), signe les binaires et publie le JSON d'updater pour les mises à jour automatiques. - **`release.yml`** — déclenché par les tags `v*`. Build Windows (NSIS `.exe`) + Linux (`.deb`, `.rpm`), signe les binaires et publie le JSON d'updater pour les mises à jour automatiques.
Aucun workflow `check-*` ne filtre sur `branches:` : une PR stackée sur une autre branche de feature déclenche donc bien la CI. Le cache Actions est retiré partout tant que [#234](https://git.lacompagniemaximus.com/maximus/simpl-resultat/issues/234) (connectivité du serveur de cache) n'est pas réglé — restore et save échouent tous les deux. Le miroir `.github/workflows/` est dormant (aucune PR côté GitHub).
--- ---
## Ressources clés ## Ressources clés

View file

@ -65,8 +65,12 @@ simpl-resultat/
│ │ └── main.rs │ │ └── main.rs
│ ├── capabilities/ # Permissions Tauri │ ├── capabilities/ # Permissions Tauri
│ └── Cargo.toml │ └── Cargo.toml
├── .github/workflows/ # CI/CD ├── .forgejo/workflows/ # CI/CD (hôte primaire)
│ ├── check-rust.yml
│ ├── check-frontend.yml
│ ├── audit.yml
│ └── release.yml │ └── release.yml
├── .github/workflows/ # Miroir GitHub (dormant)
├── docs/ # Documentation technique ├── docs/ # Documentation technique
└── config/ # Configuration └── config/ # Configuration
``` ```
@ -414,16 +418,25 @@ Page spéciale : `ProfileSelectionPage` (affichée quand aucun profil n'est acti
## CI/CD ## CI/CD
Deux workflows Forgejo Actions (avec miroir GitHub) dans `.forgejo/workflows/` : Quatre workflows Forgejo Actions dans `.forgejo/workflows/`. Le runner est à **capacité 1** : les jobs se suivent, ils ne tournent pas en parallèle.
### `check.yml` — Vérifications sur branches et PR ### `check-rust.yml` — Vérifications Rust sur PR
Déclenché sur chaque push de branche (sauf `main`) et chaque PR vers `main`. Lance en parallèle : Déclenché sur les PR qui touchent `src-tauri/**` (ou le workflow lui-même). Lance `cargo check` puis `cargo test`, et un `cargo audit` informatif (non bloquant, binaire pré-buildé via `taiki-e/install-action`).
- `cargo check` + `cargo test` (Rust)
- `npm run build` (tsc + vite)
- `npm test` (vitest)
Doit être vert avant tout merge. Évite de découvrir des régressions au moment du tag de release. Aucun `branches:` : une PR stackée sur une autre branche de feature — ce que produit `/autopilot` — déclenche donc bien la CI. Aucune étape de cache non plus : le conteneur de job n'atteint pas le serveur de cache du runner ([#234](https://git.lacompagniemaximus.com/maximus/simpl-resultat/issues/234)), le restore et le save échouent tous les deux. Le cache reviendra via `Swatinem/rust-cache` une fois #234 réglé.
### `check-frontend.yml` — Vérifications frontend sur PR
Déclenché sur les PR, sauf si tous les fichiers modifiés sont du Rust, de la doc ou du markdown (`paths-ignore`). Lance `npm ci`, `npm run build` (tsc + vite) et `npm test` (vitest). Le cache npm est retiré pour la même raison que côté Rust.
### `audit.yml` — Audit RustSec quotidien
`schedule` quotidien (06:00 UTC) + `workflow_dispatch`. `check-rust.yml` ne tournant que sur les PR qui touchent le Rust — environ 1 PR sur 40 — ce workflow garantit qu'un avis de sécurité publié sur une dépendance inchangée ne passe pas inaperçu. Échec bloquant : c'est le canal de notification.
Les deux workflows `check-*` doivent être verts avant tout merge. Ils évitent de découvrir des régressions au moment du tag de release.
> Le miroir GitHub (`.github/workflows/check.yml`) est laissé tel quel : aucune PR n'est ouverte côté GitHub, un push-mirror ne déclenche pas d'événement `pull_request`.
### `release.yml` — Build et publication ### `release.yml` — Build et publication