rename project from citelens to sourcery #36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| backend: | |
| name: backend (lint + tests + format) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| services: | |
| postgres: | |
| image: pgvector/pgvector:pg16 | |
| env: | |
| POSTGRES_USER: scholarrag | |
| POSTGRES_PASSWORD: scholarrag | |
| POSTGRES_DB: scholarrag | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U scholarrag" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| env: | |
| DATABASE_URL: postgresql://scholarrag:scholarrag@127.0.0.1:5432/scholarrag | |
| PGHOST: 127.0.0.1 | |
| PGPORT: "5432" | |
| PGUSER: scholarrag | |
| PGPASSWORD: scholarrag | |
| PGDATABASE: scholarrag | |
| EMBEDDING_PROVIDER: stub | |
| OPENAI_API_KEY: test-key | |
| # Anchor floor (current actual ≈ 47%). Bump as new tests land. | |
| COVERAGE_MIN: "45" | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| cache: pip | |
| - name: Install deps (pinned via requirements-dev.txt) | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -r requirements.txt -r requirements-dev.txt | |
| - name: Show toolchain versions (for drift debugging) | |
| run: | | |
| ruff --version | |
| pytest --version | |
| python --version | |
| - name: Init schema + apply all migrations | |
| run: | | |
| PGPASSWORD=$PGPASSWORD psql -h 127.0.0.1 -U $PGUSER -d $PGDATABASE -f db/init.sql | |
| for f in db/migrations/*.sql; do | |
| echo "applying $f" | |
| PGPASSWORD=$PGPASSWORD psql -h 127.0.0.1 -U $PGUSER -d $PGDATABASE -f "$f" | |
| done | |
| - name: Lint (ruff) | |
| run: ruff check backend/ scripts/ | |
| - name: Format check (ruff) | |
| run: ruff format --check backend/ scripts/ | |
| - name: Tests + coverage gate | |
| run: | | |
| pytest backend/tests \ | |
| --cov=backend --cov-report=term-missing --cov-report=xml \ | |
| --cov-fail-under=$COVERAGE_MIN --maxfail=5 | |
| - name: Upload coverage report | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: backend-coverage | |
| path: coverage.xml | |
| retention-days: 14 | |
| frontend: | |
| name: frontend (lint + typecheck + build) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| defaults: | |
| run: | |
| working-directory: frontend | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: npm | |
| cache-dependency-path: frontend/package-lock.json | |
| - run: npm ci | |
| - name: Lint | |
| run: npx eslint . --max-warnings 0 | |
| - name: Typecheck | |
| run: npx tsc --noEmit | |
| - name: Build | |
| run: npm run build | |
| security: | |
| name: security (secret scan + filesystem scan) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| security-events: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Gitleaks (committed-secret scan) | |
| uses: gitleaks/gitleaks-action@v2 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| continue-on-error: true | |
| - name: Trivy filesystem scan (deps + IaC) | |
| uses: aquasecurity/trivy-action@master | |
| with: | |
| scan-type: fs | |
| scan-ref: . | |
| format: sarif | |
| output: trivy-results.sarif | |
| severity: HIGH,CRITICAL | |
| ignore-unfixed: true | |
| exit-code: "0" | |
| continue-on-error: true | |
| - name: Upload Trivy SARIF | |
| if: always() | |
| uses: github/codeql-action/upload-sarif@v3 | |
| with: | |
| sarif_file: trivy-results.sarif | |
| continue-on-error: true | |
| helm: | |
| name: helm (lint + template) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Install helm | |
| uses: azure/setup-helm@v4 | |
| with: | |
| version: v3.16.3 | |
| - name: helm lint | |
| run: helm lint helm/sourcery | |
| - name: helm template (dry render) | |
| run: helm template sourcery helm/sourcery --debug | head -200 | |
| pyright: | |
| name: pyright (typecheck) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 8 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| cache: pip | |
| - name: Install deps | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -r requirements.txt -r requirements-dev.txt | |
| - name: pyright (typed core only — see pyproject.toml) | |
| run: pyright | |
| sbom: | |
| name: sbom (cyclonedx) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 8 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| - name: Generate Python SBOM (CycloneDX) | |
| run: | | |
| pip install cyclonedx-bom | |
| cyclonedx-py requirements -i requirements.txt -o sbom-python.json --output-format JSON | |
| - uses: actions/upload-artifact@v4 | |
| with: | |
| name: sbom | |
| path: sbom-python.json | |
| retention-days: 90 |