name: build on: push: branches: [main] tags: ["v*"] pull_request: branches: [main] jobs: test: runs-on: ubuntu-latest container: image: git.librete.ch/public/runner-image:v0.2.0@sha256:f60c587d3c0b0aac04a572db5349e27672bf76baec2ce547a3dcc28cebcf1b7e timeout-minutes: 10 steps: - uses: actions/checkout@v4 # The tests need no dependencies. They run in the image's base (Dockerfile FROM), so on the runtime's Node, # without network. The source is piped in because the job container's paths do not exist on the Docker host. - name: npm test, on the Node of the image run: | base=$(sed -n 's/^FROM \([^ ]*\).*/\1/p' Dockerfile | head -1) tar -c --exclude=.git . | docker run -i --rm --network none -e npm_config_update_notifier=false "$base" \ sh -c 'mkdir /w && cd /w && tar -x && npm test' # The image is built to check a pull request, and built and published only for a release tag. # Nothing pulls per-commit images, so main no longer publishes :main and :sha-* images. build: needs: test if: github.event_name == 'pull_request' || startsWith(github.ref, 'refs/tags/v') runs-on: ubuntu-latest container: image: git.librete.ch/public/runner-image:v0.2.0@sha256:f60c587d3c0b0aac04a572db5349e27672bf76baec2ce547a3dcc28cebcf1b7e timeout-minutes: 20 steps: - uses: actions/checkout@v4 - uses: https://git.librete.ch/public/actions/.gitea/actions/docker-build@main with: registry: ${{ secrets.REGISTRY }} registry_user: ${{ secrets.REGISTRY_USER }} registry_pass: ${{ secrets.REGISTRY_PASS }} publish: ${{ startsWith(github.ref, 'refs/tags/v') && vars.PUBLISH_ENABLED == 'true' }}