Program: checked math, void restrictions, permissionless liveness fal… #17
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main, develop] | |
| pull_request: | |
| branches: [main] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| env: | |
| SOLANA_VERSION: "1.18.17" | |
| ANCHOR_VERSION: "0.30.1" | |
| jobs: | |
| # ─── Smart Contract ────────────────────────────────────────────────── | |
| anchor-build: | |
| name: Anchor Build | |
| runs-on: ubuntu-latest | |
| container: | |
| image: backpackapp/build:v0.30.1 | |
| env: | |
| # Actions overrides HOME to /github/home inside containers; rustup's | |
| # toolchain config lives in /root, so restore it or rustc has no default. | |
| HOME: /root | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Verify Anchor toolchain | |
| run: | | |
| rustup default stable 2>/dev/null || rustup default "$(rustup toolchain list | head -1 | cut -d' ' -f1)" || true | |
| rustc --version | |
| solana --version | |
| anchor --version | |
| - name: Downgrade Cargo.lock to v3 for cargo-build-sbf | |
| run: | | |
| # cargo-build-sbf in this Anchor 0.30.1 image cannot parse v4 lockfiles. | |
| sed -i 's/^version = 4$/version = 3/' Cargo.lock | |
| head -3 Cargo.lock | |
| - name: Build Anchor program | |
| run: anchor build -p instinctfi | |
| cargo-audit: | |
| name: Cargo Security Audit | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Install cargo-audit | |
| run: cargo install cargo-audit | |
| - name: Run audit | |
| # RUSTSEC-2024-0344: curve25519-dalek 3.x timing side-channel — transitive | |
| # Solana SDK dep, cannot be upgraded without breaking anchor-lang 0.30.1. | |
| run: cargo audit --ignore RUSTSEC-2024-0344 | |
| # ─── Frontend ──────────────────────────────────────────────────────── | |
| lint-and-typecheck: | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: app | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: "npm" | |
| cache-dependency-path: app/package-lock.json | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: TypeScript type-check | |
| run: npx tsc --noEmit | |
| - name: Lint | |
| run: npm run lint | |
| test: | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: app | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: "npm" | |
| cache-dependency-path: app/package-lock.json | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Run tests | |
| run: npm test -- --ci --coverage | |
| - name: Upload coverage | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: coverage | |
| path: app/coverage/ | |
| retention-days: 14 | |
| build: | |
| runs-on: ubuntu-latest | |
| needs: [lint-and-typecheck, test] | |
| defaults: | |
| run: | |
| working-directory: app | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: "npm" | |
| cache-dependency-path: app/package-lock.json | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Build | |
| run: npm run build | |
| env: | |
| NEXT_PUBLIC_SUPABASE_URL: ${{ secrets.NEXT_PUBLIC_SUPABASE_URL || 'https://placeholder.supabase.co' }} | |
| NEXT_PUBLIC_SUPABASE_ANON_KEY: ${{ secrets.NEXT_PUBLIC_SUPABASE_ANON_KEY || 'placeholder' }} | |
| # Playwright e2e (behavioral checks only in CI). Pixel baselines are | |
| # platform-specific and generated locally, so screenshot comparisons are | |
| # skipped here (--ignore-snapshots); navigation, console-error, and DOM | |
| # assertions still run and fail the build on regressions. | |
| e2e: | |
| runs-on: ubuntu-latest | |
| needs: [lint-and-typecheck] | |
| defaults: | |
| run: | |
| working-directory: app | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: "npm" | |
| cache-dependency-path: app/package-lock.json | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Install Playwright browsers | |
| run: npx playwright install --with-deps chromium | |
| - name: Start dev server | |
| run: | | |
| npm run dev -- --port 3005 & | |
| for i in $(seq 1 60); do | |
| if curl -sf http://localhost:3005 > /dev/null; then break; fi | |
| sleep 2 | |
| done | |
| curl -sf http://localhost:3005 > /dev/null | |
| - name: Run Playwright tests | |
| run: npx playwright test --ignore-snapshots | |
| env: | |
| PW_BASE_URL: http://localhost:3005 | |
| - name: Upload Playwright report | |
| if: failure() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: playwright-report | |
| path: app/playwright-report/ | |
| retention-days: 7 |