mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-05 13:01:37 +00:00
427a383dfe
By default, `actions/checkout` saves the job's auth token
(`GITHUB_TOKEN` or the provided PAT) in the local git config so
later steps can run authenticated git commands. That token then
stays on disk for the rest of the job, where it can leak:
* If an artifact upload includes the checkout directory, the token
is packaged with it and anyone with artifact access can extract
it. On public repos that is anyone, and the token can be used
while the job is still running ("ArtiPACKED", flagged by
`zizmor` as `artipacked`).
* Any later step, third-party action, or build dependency can read
the token from the git config, which widens the impact of a
supply-chain compromise.
None of our workflows need authenticated git after checkout, so
disable credential persistence. If a step needs to push in
267 lines
7.9 KiB
YAML
267 lines
7.9 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
pull_request:
|
|
branches:
|
|
- "*"
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
|
|
lint-python:
|
|
name: lint ${{ matrix.service }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- service: backend
|
|
working_directory: src/backend
|
|
pylint_targets: meet demo core
|
|
- service: agents
|
|
working_directory: src/agents
|
|
pylint_targets: ""
|
|
- service: summary
|
|
working_directory: src/summary
|
|
pylint_targets: ""
|
|
uses: suitenumerique/ci/.github/workflows/_python-lint.yml@ca6401ac83e981e5b0a94f06f68baaa6e6d0a436 # v0.0.1
|
|
with:
|
|
working_directory: ${{ matrix.working_directory }}
|
|
python_version: "3.13"
|
|
pylint_targets: ${{ matrix.pylint_targets }}
|
|
|
|
test-back:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/backend
|
|
|
|
services:
|
|
postgres:
|
|
image: postgres:16
|
|
env:
|
|
POSTGRES_DB: meet
|
|
POSTGRES_USER: dinum
|
|
POSTGRES_PASSWORD: pass
|
|
ports:
|
|
- 5432:5432
|
|
# needed because the postgres container does not provide a healthcheck
|
|
options: --health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5
|
|
redis:
|
|
image: redis:5
|
|
ports:
|
|
- 6379:6379
|
|
# Set health checks to wait until redis has started
|
|
options: >-
|
|
--health-cmd "redis-cli ping"
|
|
--health-interval 10s
|
|
--health-timeout 5s
|
|
--health-retries 5
|
|
|
|
env:
|
|
DJANGO_CONFIGURATION: Test
|
|
DJANGO_SETTINGS_MODULE: meet.settings
|
|
DJANGO_SECRET_KEY: ThisIsAnExampleKeyForTestPurposeOnly
|
|
OIDC_OP_JWKS_ENDPOINT: /endpoint-for-test-purpose-only
|
|
DB_HOST: localhost
|
|
DB_NAME: meet
|
|
DB_USER: dinum
|
|
DB_PASSWORD: pass
|
|
DB_PORT: 5432
|
|
REDIS_URL: redis://localhost:6379/1
|
|
STORAGES_STATICFILES_BACKEND: django.contrib.staticfiles.storage.StaticFilesStorage
|
|
AWS_S3_ENDPOINT_URL: http://localhost:9000
|
|
AWS_S3_ACCESS_KEY_ID: meet-access-key
|
|
AWS_S3_SECRET_ACCESS_KEY: meet-secret-access-key
|
|
AWS_S3_REGION_NAME: local
|
|
OIDC_RS_CLIENT_ID: meet
|
|
OIDC_RS_CLIENT_SECRET: ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_OP_INTROSPECTION_ENDPOINT: https://oidc.example.com/introspect
|
|
OIDC_OP_URL: https://oidc.example.com
|
|
MEDIA_BASE_URL: http://localhost:8083
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Create writable /data
|
|
run: |
|
|
sudo mkdir -p /data/media && \
|
|
sudo mkdir -p /data/static
|
|
|
|
- name: Build or restore the mail templates
|
|
uses: suitenumerique/ci/actions/mail-templates@ca6401ac83e981e5b0a94f06f68baaa6e6d0a436 # v0.0.1
|
|
|
|
# Creates the access key and the bucket on startup
|
|
- name: Start Garage
|
|
run: |
|
|
docker run -d --name garage \
|
|
-p 9000:9000 \
|
|
-v "${GITHUB_WORKSPACE}/docker/files/etc/garage/garage.toml:/etc/garage.toml:ro" \
|
|
-e "GARAGE_RPC_SECRET=$(openssl rand -hex 32)" \
|
|
-e "GARAGE_DEFAULT_ACCESS_KEY=meet-access-key" \
|
|
-e "GARAGE_DEFAULT_SECRET_KEY=meet-secret-access-key" \
|
|
-e "GARAGE_DEFAULT_BUCKET=meet-media-storage" \
|
|
dxflrs/garage:v2.4.1 \
|
|
/garage server --single-node --default-bucket
|
|
|
|
- name: Wait for Garage to be ready
|
|
run: |
|
|
timeout 30 sh -c 'until docker exec garage /garage health; do sleep 1; done'
|
|
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
- name: Install the dependencies
|
|
run: uv sync --locked --all-extras
|
|
|
|
- name: Install gettext (required to compile messages)
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y gettext
|
|
|
|
- name: Generate a MO file from strings extracted from the project
|
|
run: uv run --no-sync --no-build python manage.py compilemessages
|
|
|
|
- name: Run tests
|
|
run: uv run --no-sync --no-build pytest -n 2
|
|
|
|
test-summary:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/summary
|
|
|
|
env:
|
|
AUTHORIZED_TENANTS: '[{"id": "test-tenant", "api_key": "test-api-token", "webhook_url": "https://example.com/webhook", "webhook_api_key": "test-webhook-api-key"}]'
|
|
AWS_STORAGE_BUCKET_NAME: "http://meet-media-storage"
|
|
AWS_S3_ENDPOINT_URL: "garage:9000"
|
|
AWS_S3_ACCESS_KEY_ID: "meet-access-key"
|
|
AWS_S3_SECRET_ACCESS_KEY: "meet-secret-access-key"
|
|
WHISPERX_BASE_URL: "https://configure-your-url.com"
|
|
WHISPERX_ASR_MODEL: "large-v2"
|
|
WHISPERX_API_KEY: "test-whisperx-secret"
|
|
WHISPERX_DEFAULT_LANGUAGE: "fr"
|
|
LLM_BASE_URL: "https://configure-your-url.com"
|
|
LLM_API_KEY: "test-llm-secret"
|
|
LLM_MODEL: "test-llm-model"
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install ffmpeg
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y ffmpeg
|
|
|
|
- name: Install Python
|
|
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7.6.0
|
|
|
|
- name: Install the project
|
|
run: uv sync --locked --all-extras
|
|
|
|
- name: Run summary tests
|
|
run: uv run --no-sync --no-build pytest
|
|
|
|
lint-front:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install dependencies
|
|
run: cd src/frontend/ && npm ci --ignore-scripts
|
|
|
|
- name: Check linting
|
|
run: cd src/frontend/ && npm run lint
|
|
|
|
- name: Check format
|
|
run: cd src/frontend/ && npm run check
|
|
|
|
test-front:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install Node.js
|
|
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0
|
|
with:
|
|
node-version: "24"
|
|
|
|
- name: Install dependencies
|
|
run: cd src/frontend/ && npm ci --ignore-scripts
|
|
|
|
- name: Run tests
|
|
run: cd src/frontend/ && npm test
|
|
|
|
lint-sdk:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
defaults:
|
|
run:
|
|
working-directory: src/sdk/library
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install dependencies
|
|
run: npm ci --ignore-scripts
|
|
|
|
- name: Check linting
|
|
run: npm run lint
|
|
|
|
- name: Check format
|
|
run: npm run check
|
|
|
|
build-sdk:
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
needs: lint-sdk
|
|
defaults:
|
|
run:
|
|
working-directory: src/sdk/library
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install dependencies
|
|
run: npm ci --ignore-scripts
|
|
|
|
- name: Build SDK
|
|
run: npm run build
|