diff --git a/.gitea/workflows/build.yml b/.gitea/workflows/build.yml index 340fb8d..ef24a9e 100644 --- a/.gitea/workflows/build.yml +++ b/.gitea/workflows/build.yml @@ -8,7 +8,27 @@ on: branches: [main] jobs: + test: + runs-on: ubuntu-latest + container: + image: git.librete.ch/public/runner-image:v0.2.0@sha256:f60c587d3c0b0aac04a572db5349e27672bf76baec2ce547a3dcc28cebcf1b7e + timeout-minutes: 10 + steps: + - uses: actions/checkout@v4 + + # The tests need no dependencies. They run in the image's base (Dockerfile FROM), so on the runtime's Node, + # without network. The source is piped in because the job container's paths do not exist on the Docker host. + - name: npm test, on the Node of the image + run: | + base=$(sed -n 's/^FROM \([^ ]*\).*/\1/p' Dockerfile | head -1) + tar -c --exclude=.git . | docker run -i --rm --network none -e npm_config_update_notifier=false "$base" \ + sh -c 'mkdir /w && cd /w && tar -x && npm test' + + # The image is built to check a pull request, and built and published only for a release tag. + # Nothing pulls per-commit images, so main no longer publishes :main and :sha-* images. build: + needs: test + if: github.event_name == 'pull_request' || startsWith(github.ref, 'refs/tags/v') runs-on: ubuntu-latest container: image: git.librete.ch/public/runner-image:v0.2.0@sha256:f60c587d3c0b0aac04a572db5349e27672bf76baec2ce547a3dcc28cebcf1b7e @@ -21,4 +41,4 @@ jobs: registry: ${{ secrets.REGISTRY }} registry_user: ${{ secrets.REGISTRY_USER }} registry_pass: ${{ secrets.REGISTRY_PASS }} - publish: ${{ github.event_name == 'push' && vars.PUBLISH_ENABLED == 'true' }} + publish: ${{ startsWith(github.ref, 'refs/tags/v') && vars.PUBLISH_ENABLED == 'true' }}