-
Notifications
You must be signed in to change notification settings - Fork 300
284 lines (275 loc) · 14.2 KB
/
Copy pathcode-qa.yml
File metadata and controls
284 lines (275 loc) · 14.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
name: Code QA Roo Code
on:
workflow_dispatch:
push:
branches: [main]
pull_request:
types: [opened, reopened, ready_for_review, synchronize]
merge_group:
types: [checks_requested]
# Least privilege: every job below escalates only where it needs to.
permissions:
contents: read
jobs:
dependency-review:
runs-on: ubuntu-latest
# Only meaningful for PRs — validates the dependency diff of the pull
# request against GitHub's advisory database before merge.
if: github.event_name == 'pull_request'
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# This job never pushes — don't persist the GITHUB_TOKEN.
persist-credentials: false
- name: Dependency review
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
invisible-chars:
runs-on: ubuntu-latest
# Reject invisible / homoglyph Unicode that GitHub's diff UI renders
# invisibly and most editors hide. These compile fine, which is the
# risk: identifier-splitting, string-literal injection, and the
# "Trojan Source" bidi-override attack (U+202A-U+202E). Scanning raw
# bytes catches them in strings, identifiers, and comments alike.
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# This job never pushes — don't persist the GITHUB_TOKEN.
persist-credentials: false
- name: Reject invisible / homoglyph Unicode
run: |
# zero-width (U+200B-200F), word joiner (U+2060), BOM (U+FEFF),
# bidi overrides (U+202A-202E), soft hyphen (U+00AD).
# Covers source, release-adjacent executable scripts
# (*.sh / *.cjs / *.cts / *.mts), and the executable shell
# blocks inside GitHub workflow/action YAML.
if grep -rnP '[\x{200B}-\x{200F}\x{202A}-\x{202E}\x{2060}\x{FEFF}\x{00AD}]' \
--include='*.ts' --include='*.tsx' --include='*.js' --include='*.mjs' \
--include='*.cjs' --include='*.cts' --include='*.mts' --include='*.sh' \
--include='*.yml' --include='*.yaml' \
--exclude-dir=node_modules --exclude-dir=dist --exclude-dir=out \
--exclude-dir=coverage --exclude-dir=.turbo --exclude-dir=.vinxi \
src webview-ui packages apps .github; then
echo "::error::Found invisible or homoglyph Unicode characters (zero-width / bidi-override / BOM / soft hyphen)"
exit 1
fi
check-translations:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Setup Node.js and pnpm
uses: ./.github/actions/setup-node-pnpm
- name: Verify all translations are complete
run: node scripts/find-missing-translations.js
knip:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Setup Node.js and pnpm
uses: ./.github/actions/setup-node-pnpm
- name: Run knip checks
run: pnpm knip
compile:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Setup Node.js and pnpm
uses: ./.github/actions/setup-node-pnpm
- name: Lint
run: pnpm lint
- name: Check types
run: pnpm check-types
- name: Validate Code QA workflow
run: pnpm test:code-qa-ci
- name: Model-check task lifecycle protocols
run: pnpm lifecycle:model-check
- name: Validate MCP OAuth integration
run: pnpm mcp:integration-check
build-vsix:
name: Build test VSIX
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Setup Node.js and pnpm
uses: ./.github/actions/setup-node-pnpm
with:
install-args: "--frozen-lockfile"
- name: Build workspace packages
run: |
pnpm --filter @roo-code/build build
pnpm --filter @roo-code/vscode-webview build
- name: Package extension
run: pnpm --filter ./src vsix
- name: Upload test VSIX
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: zoo-code-vsix-pr-${{ github.event.pull_request.number }}
path: bin/*.vsix
if-no-files-found: error
retention-days: 7
unit-test:
name: platform-unit-test (${{ matrix.name }})
runs-on: ${{ matrix.os }}
concurrency:
# Duplicate runs for one commit must not race the OS-specific Turbo cache save.
group: unit-test-${{ github.repository }}-${{ github.sha }}-${{ matrix.name }}
cancel-in-progress: false
strategy:
matrix:
include:
- os: ubuntu-latest
name: ubuntu-latest
codecov-flag: ubuntu
collect-coverage: true
- os: windows-latest
name: windows-latest
codecov-flag: windows
collect-coverage: false
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Setup Node.js and pnpm
uses: ./.github/actions/setup-node-pnpm
- name: Restore Turbo cache
id: turbo-cache
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: .turbo/cache
key: ${{ runner.os }}-turbo-${{ hashFiles('**/pnpm-lock.yaml') }}-${{ github.sha }}
restore-keys: |
${{ runner.os }}-turbo-${{ hashFiles('**/pnpm-lock.yaml') }}-
${{ runner.os }}-turbo-
# Windows never uploads coverage, so Windows runs the same test
# suites through the uninstrumented Turbo tasks. Ubuntu stays the
# authoritative coverage lane.
- name: Run non-extension package coverage
if: matrix.collect-coverage
run: pnpm turbo run test:coverage --filter="!@roo-code/core" --filter="!zoo-code" --log-order grouped --output-logs new-only
- name: Run non-extension package tests
if: ${{ !matrix.collect-coverage }}
run: pnpm turbo run test --filter="!@roo-code/core" --filter="!zoo-code" --log-order grouped --output-logs new-only
- name: Run extension coverage lanes
if: matrix.collect-coverage
run: pnpm turbo run test:coverage:api test:coverage:core test:coverage:services test:coverage:misc test:coverage:tree-sitter --filter="zoo-code" --concurrency=2 --log-order grouped --output-logs new-only
- name: Run extension test lanes
if: ${{ !matrix.collect-coverage }}
run: pnpm turbo run test:api test:core test:services test:misc test:tree-sitter --filter="zoo-code" --concurrency=2 --log-order grouped --output-logs new-only
# Runs outside Turbo so changes to .coderabbit.yaml and
# .github/workflows/label-pr-review-state.yml always bust the
# result — those files are outside the src/ package boundary and
# cannot be declared as Turbo inputs.
- name: Run workflow config tests
run: pnpm --dir src run test:workflow
- name: Verify extension coverage contract
if: matrix.collect-coverage
run: pnpm --dir src run verify:coverage-contract
- name: Run extension dist smoke test
run: pnpm turbo run test:dist --filter="zoo-code" --log-order grouped --output-logs new-only
- name: Run core unit coverage
if: matrix.collect-coverage
run: pnpm turbo run test:coverage:unit --filter="@roo-code/core" --log-order grouped --output-logs new-only
- name: Run core unit tests
if: ${{ !matrix.collect-coverage }}
run: pnpm turbo run test:unit --filter="@roo-code/core" --log-order grouped --output-logs new-only
- name: Run core integration coverage
if: matrix.collect-coverage
run: pnpm turbo run test:coverage:integration --filter="@roo-code/core" --log-order grouped --output-logs new-only
- name: Run core integration tests
if: ${{ !matrix.collect-coverage }}
run: pnpm turbo run test:integration --filter="@roo-code/core" --log-order grouped --output-logs new-only
- name: Verify extension coverage reports
if: matrix.collect-coverage
run: |
node src/scripts/verify-lcov.mjs src/coverage/api/lcov.info
node src/scripts/verify-lcov.mjs src/coverage/core/lcov.info
node src/scripts/verify-lcov.mjs src/coverage/services/lcov.info
node src/scripts/verify-lcov.mjs src/coverage/misc/lcov.info
node src/scripts/verify-lcov.mjs src/coverage/tree-sitter/lcov.info
- name: Merge extension coverage reports
if: matrix.collect-coverage
run: |
mkdir -p src/coverage/merged
pnpm --dir src run merge:coverage
node src/scripts/verify-lcov.mjs src/coverage/merged/lcov.info
# Validate cache boundaries before publishing any new Turbo entries.
- name: Verify coverage cache inputs
if: matrix.collect-coverage
run: pnpm --dir src run verify:coverage-cache-inputs
- name: Save Turbo cache
if: steps.turbo-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: .turbo/cache
key: ${{ steps.turbo-cache.outputs.cache-primary-key }}
# Only ubuntu uploads coverage. Windows still runs the same test
# lanes for behavioral confidence, but duplicating coverage uploads
# there mostly adds Codecov overhead without changing pass/fail
# behavior.
# Coverage is uploaded in separate steps so each LCOV gets the
# correct flag set. Extension lanes instrument the same sources, so
# union them before upload; a line is covered when any lane executes
# it. Core and webview reports retain their independent flags.
# See https://docs.codecov.com/docs/flags
- name: Upload non-core coverage to Codecov
if: matrix.collect-coverage
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
files: >-
src/coverage/merged/lcov.info,
packages/cloud/coverage/lcov.info,
packages/telemetry/coverage/lcov.info,
apps/cli/coverage/lcov.info
disable_search: true
flags: ${{ matrix.codecov-flag }}
token: ${{ secrets.CODECOV_TOKEN }}
- name: Upload webview JSDOM coverage to Codecov
if: matrix.collect-coverage
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
files: webview-ui/coverage/lcov.info
disable_search: true
flags: webview-ui
token: ${{ secrets.CODECOV_TOKEN }}
- name: Upload core unit coverage to Codecov
if: matrix.collect-coverage
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
files: packages/core/coverage/unit/lcov.info
disable_search: true
flags: ${{ matrix.codecov-flag }},core-unit
token: ${{ secrets.CODECOV_TOKEN }}
- name: Upload core integration coverage to Codecov
if: matrix.collect-coverage
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
files: packages/core/coverage/integration/lcov.info
disable_search: true
flags: ${{ matrix.codecov-flag }},core-integration
token: ${{ secrets.CODECOV_TOKEN }}
- name: Upload coverage reports to GitHub
if: matrix.collect-coverage
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: coverage-reports-${{ matrix.name }}
path: |
src/coverage/api/lcov.info
src/coverage/core/lcov.info
src/coverage/services/lcov.info
src/coverage/misc/lcov.info
src/coverage/tree-sitter/lcov.info
src/coverage/merged/lcov.info
webview-ui/coverage/lcov.info
packages/cloud/coverage/lcov.info
packages/telemetry/coverage/lcov.info
apps/cli/coverage/lcov.info
packages/core/coverage/unit/lcov.info
packages/core/coverage/integration/lcov.info
retention-days: 7