name: Quality gates on: push: branches: [main] pull_request: branches: [main] permissions: contents: read jobs: quality: runs-on: ubuntu-latest timeout-minutes: 15 steps: - name: Check out source uses: actions/checkout@v4 with: fetch-depth: 0 - name: Set up Node.js uses: actions/setup-node@v4 with: node-version: 22 cache: npm - name: Set up pinned Python uses: actions/setup-python@v5 with: python-version: '3.11' - name: Install reproducibly run: | npm ci python3 -m pip install --break-system-packages -r requirements-test.txt printf 'TIMMY_PYTHON=%s\n' "$(python3 -c 'import sys; print(sys.executable)')" >> "$GITHUB_ENV" - name: Install browser run: npx playwright install --with-deps chromium - name: Unit and security tests run: | npm test python3 tests/staging-deploy.test.py -v python3 tests/reencode-image.test.py -v - name: Mobile browser acceptance run: | npm start > /tmp/timmy-server.log 2>&1 & server_pid=$! trap 'kill "$server_pid"' EXIT for attempt in $(seq 1 30); do if curl --fail --silent http://127.0.0.1:4173/ > /dev/null; then break fi if [ "$attempt" -eq 30 ]; then cat /tmp/timmy-server.log exit 1 fi sleep 1 done npm run test:ui npm run test:photo npm run test:sleek - name: Dependency audit run: npm audit --audit-level=high - name: Syntax checks run: | npm run check:syntax node --check tests/staging.acceptance.mjs - name: Image runtime pin and re-encode smoke run: python3 -c "import importlib.util,json,pathlib; s=importlib.util.spec_from_file_location('d','scripts/deploy_staging.py'); m=importlib.util.module_from_spec(s); s.loader.exec_module(m); print(json.dumps(m.verify_image_runtime(pathlib.Path('.'))))" - name: Diff hygiene run: npm run check:diff