Skip to content

Program: checked math, void restrictions, permissionless liveness fal… #17

Program: checked math, void restrictions, permissionless liveness fal…

Program: checked math, void restrictions, permissionless liveness fal… #17

Workflow file for this run

name: CI
on:
push:
branches: [main, develop]
pull_request:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
SOLANA_VERSION: "1.18.17"
ANCHOR_VERSION: "0.30.1"
jobs:
# ─── Smart Contract ──────────────────────────────────────────────────
anchor-build:
name: Anchor Build
runs-on: ubuntu-latest
container:
image: backpackapp/build:v0.30.1
env:
# Actions overrides HOME to /github/home inside containers; rustup's
# toolchain config lives in /root, so restore it or rustc has no default.
HOME: /root
steps:
- uses: actions/checkout@v4
- name: Verify Anchor toolchain
run: |
rustup default stable 2>/dev/null || rustup default "$(rustup toolchain list | head -1 | cut -d' ' -f1)" || true
rustc --version
solana --version
anchor --version
- name: Downgrade Cargo.lock to v3 for cargo-build-sbf
run: |
# cargo-build-sbf in this Anchor 0.30.1 image cannot parse v4 lockfiles.
sed -i 's/^version = 4$/version = 3/' Cargo.lock
head -3 Cargo.lock
- name: Build Anchor program
run: anchor build -p instinctfi
cargo-audit:
name: Cargo Security Audit
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install cargo-audit
run: cargo install cargo-audit
- name: Run audit
# RUSTSEC-2024-0344: curve25519-dalek 3.x timing side-channel — transitive
# Solana SDK dep, cannot be upgraded without breaking anchor-lang 0.30.1.
run: cargo audit --ignore RUSTSEC-2024-0344
# ─── Frontend ────────────────────────────────────────────────────────
lint-and-typecheck:
runs-on: ubuntu-latest
defaults:
run:
working-directory: app
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: "npm"
cache-dependency-path: app/package-lock.json
- name: Install dependencies
run: npm ci
- name: TypeScript type-check
run: npx tsc --noEmit
- name: Lint
run: npm run lint
test:
runs-on: ubuntu-latest
defaults:
run:
working-directory: app
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: "npm"
cache-dependency-path: app/package-lock.json
- name: Install dependencies
run: npm ci
- name: Run tests
run: npm test -- --ci --coverage
- name: Upload coverage
if: always()
uses: actions/upload-artifact@v4
with:
name: coverage
path: app/coverage/
retention-days: 14
build:
runs-on: ubuntu-latest
needs: [lint-and-typecheck, test]
defaults:
run:
working-directory: app
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: "npm"
cache-dependency-path: app/package-lock.json
- name: Install dependencies
run: npm ci
- name: Build
run: npm run build
env:
NEXT_PUBLIC_SUPABASE_URL: ${{ secrets.NEXT_PUBLIC_SUPABASE_URL || 'https://placeholder.supabase.co' }}
NEXT_PUBLIC_SUPABASE_ANON_KEY: ${{ secrets.NEXT_PUBLIC_SUPABASE_ANON_KEY || 'placeholder' }}
# Playwright e2e (behavioral checks only in CI). Pixel baselines are
# platform-specific and generated locally, so screenshot comparisons are
# skipped here (--ignore-snapshots); navigation, console-error, and DOM
# assertions still run and fail the build on regressions.
e2e:
runs-on: ubuntu-latest
needs: [lint-and-typecheck]
defaults:
run:
working-directory: app
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: "npm"
cache-dependency-path: app/package-lock.json
- name: Install dependencies
run: npm ci
- name: Install Playwright browsers
run: npx playwright install --with-deps chromium
- name: Start dev server
run: |
npm run dev -- --port 3005 &
for i in $(seq 1 60); do
if curl -sf http://localhost:3005 > /dev/null; then break; fi
sleep 2
done
curl -sf http://localhost:3005 > /dev/null
- name: Run Playwright tests
run: npx playwright test --ignore-snapshots
env:
PW_BASE_URL: http://localhost:3005
- name: Upload Playwright report
if: failure()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: app/playwright-report/
retention-days: 7