name: CI on: pull_request: branches: - production paths-ignore: - ".flue/**" - ".github/workflows/flue-ci.yml" - ".github/workflows/flue-deploy.yml" concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true jobs: typos: name: Typos runs-on: ubuntu-latest permissions: contents: read steps: - name: Check out repo uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: fetch-depth: 1 - name: Check for typos uses: crate-ci/typos@d43b6c087ac471e2ea7b8af622ff15f05c0c365b # v1.50.1 with: files: src/content/docs src/content/partials src/content/changelog config: ./_typos.toml pre-build: name: Pre Build runs-on: ubuntu-latest permissions: contents: read pull-requests: write steps: - name: Check out repo uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: fetch-depth: 1 - name: Set up pnpm uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 with: version: 11 - name: Set up node uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6 id: setup-node with: node-version: 24.x cache: pnpm - name: Check for CRLF line endings run: | if git grep -Il $'\r'; then echo "::error::CRLF line endings detected. Configure your editor to use LF line endings (this repo has an .editorconfig file that most editors respect automatically)." exit 1 fi - name: Check for invalid file extensions run: | FILES=$( find src/content \ -type f \ -not -name '*.mdx' \ -not -name '*.md' \ -not -name '*.json' \ -not -name '*.yml' \ -not -name '*.yaml' \ -not -name '*.txt' \ -not -wholename 'src/content/collections/*' ) if [ -n "$FILES" ]; then echo "Found files with invalid file extensions:\n\n$FILES" exit 1 fi - name: Install dependencies run: pnpm install --frozen-lockfile - name: Check Astro and CF Worker run: pnpm run check - name: Set up reviewdog uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0 with: reviewdog_version: v0.21.0 - name: Run eslint env: REVIEWDOG_GITHUB_API_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | pnpm run lint --format eslint-formatter-checkstyle | \ reviewdog -f=checkstyle -name=eslint -reporter=github-pr-review -fail-level=error -filter-mode=nofilter - name: Check formatting # The codebase is always fully formatted, so checking all # prettier-scoped files is equivalent to checking only changed files. run: pnpm run format:check - name: Validate redirects run: pnpm exec tsm bin/validate-redirects.ts - name: Check component docs reference run: pnpm exec tsx bin/check-component-docs.ts - name: Tests run: pnpm run test:prebuild build: name: Build needs: pre-build runs-on: ubuntu-latest outputs: succeeded: ${{ steps.build.outputs.succeeded }} permissions: contents: read steps: - name: Check out repo uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: fetch-depth: 1 - name: Set up pnpm uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 with: version: 11 - name: Set up node uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6 id: setup-node with: node-version: 24.x cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile - name: Restore Astro cache uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5 with: path: | node_modules/.astro key: astro-cache-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}-${{ github.event.pull_request.head.sha || github.sha }} restore-keys: | astro-cache-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}- astro-cache-${{ runner.os }}- - name: Build id: build env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} NODE_OPTIONS: "--max-old-space-size=8192" run: | set -o pipefail pnpm run build 2>&1 | tee build.log echo "succeeded=true" >> "$GITHUB_OUTPUT" - name: Upload build artifact uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7 with: name: dist path: dist - name: Upload build log if: always() uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7 with: name: build-log path: build.log if-no-files-found: ignore post-build: name: Post Build needs: build runs-on: ubuntu-latest permissions: contents: read pull-requests: write steps: - name: Check out repo uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: fetch-depth: 1 - name: Set up pnpm uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 with: version: 11 - name: Set up node uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6 id: setup-node with: node-version: 24.x cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile - name: Download artifact uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 with: name: dist path: dist - name: Tests (Workers) run: pnpm run test:postbuild notify: name: Notify needs: [pre-build, post-build] if: always() runs-on: ubuntu-latest permissions: contents: read pull-requests: write steps: - name: Check out repo uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: fetch-depth: 1 - name: Set up pnpm uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 with: version: 11 - name: Set up node uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6 id: setup-node with: node-version: 24.x cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile - name: Post PR CI failure comment continue-on-error: true env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: pnpm exec tsx bin/post-pr-ci-failure-comment/index.ts publish-preview: name: Deploy Preview needs: build if: github.event.pull_request.head.repo.full_name == github.repository && needs.build.outputs.succeeded == 'true' runs-on: ubuntu-latest permissions: contents: read pull-requests: write steps: - name: Check out repo uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: fetch-depth: 1 - name: Set up pnpm uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5 with: version: 11 - name: Set up node uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # v6 id: setup-node with: node-version: 24.x cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile - name: Download artifact uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 with: name: dist path: dist - name: Deploy to Cloudflare Workers id: deploy env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} PR_HEAD_SHA: ${{ github.event.pull_request.head.sha }} PR_HEAD_REF: ${{ github.event.pull_request.head.ref }} run: | SHORT_SHA="${PR_HEAD_SHA:0:8}" BRANCH_SLUG=$(echo "$PR_HEAD_REF" | iconv -c -t ascii//TRANSLIT | sed -E 's/[~^]+//g' | sed -E 's/[^a-zA-Z0-9]+/-/g' | sed -E 's/^-+|-+$//g' | tr A-Z a-z) echo "branch_slug=${BRANCH_SLUG}" >> "$GITHUB_OUTPUT" echo "short_sha=${SHORT_SHA}" >> "$GITHUB_OUTPUT" # These two deploys are independent (different Worker names in the # same dispatch namespace), so run them concurrently instead of # back-to-back. pnpm exec wrangler deploy --config wrangler.preview.json --dispatch-namespace preview-deployments --name "${SHORT_SHA}" & short_sha_pid=$! pnpm exec wrangler deploy --config wrangler.preview.json --dispatch-namespace preview-deployments --name "${BRANCH_SLUG}" & branch_slug_pid=$! wait "$short_sha_pid" wait "$branch_slug_pid" - name: Post preview URL on PR env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} BRANCH_SLUG: ${{ steps.deploy.outputs.branch_slug }} SHORT_SHA: ${{ steps.deploy.outputs.short_sha }} run: pnpm exec tsx bin/post-preview-url-comment/index.ts continue-on-error: true