Converted insights custom scss to tailwind #1269
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build and Test Application | |
| on: | |
| pull_request: | |
| types: [ opened, synchronize, reopened ] | |
| branches: [ master ] | |
| push: | |
| branches: [ master ] | |
| env: | |
| JAVA_VERSION: 25 | |
| NODE_VERSION: 24 | |
| PNPM_VERSION: 10.33.0 | |
| REGISTRY: ghcr.io | |
| IMAGE_NAME_WEBAPP: ${{ github.repository }}-webapp | |
| IMAGE_NAME_DATA_IMPORT: ${{ github.repository }}-data-import | |
| APP_VERSION: 0.0.${{ github.run_number }} | |
| jobs: | |
| build-and-test: | |
| name: Build & Run All Tests | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| - name: Set up JDK ${{ env.JAVA_VERSION }} | |
| uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5 | |
| with: | |
| java-version: ${{ env.JAVA_VERSION }} | |
| distribution: 'temurin' | |
| cache: 'maven' | |
| - name: Install pnpm | |
| uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 | |
| with: | |
| version: ${{ env.PNPM_VERSION }} | |
| - name: Set up Node.js ${{ env.NODE_VERSION }} | |
| id: pnpm-modules-cache | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: 'pnpm' | |
| cache-dependency-path: 'pnpm-lock.yaml' | |
| - name: Install Frontend Dependencies | |
| run: pnpm install --frozen-lockfile --ignore-scripts | |
| working-directory: insights-webapp/src/main/frontend | |
| - name: Lint Frontend | |
| run: pnpm lint | |
| working-directory: insights-webapp/src/main/frontend | |
| - name: Spotless | |
| run: mvn spotless:check | |
| - name: Checkstyle | |
| run: mvn checkstyle:check | |
| - name: Test Frontend | |
| run: pnpm test --watch=false --browsers=ChromeHeadless | |
| working-directory: insights-webapp/src/main/frontend | |
| - name: Test & Build Backend and run E2E Tests | |
| run: mvn clean package "-Dspring.profiles.active=local-seed" | |
| - name: Upload CI Artifacts on Failure | |
| if: failure() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 | |
| with: | |
| name: test-artifacts | |
| path: | | |
| **/target/surefire-reports/ | |
| **/target/failsafe-reports/ | |
| **/target/cypress/ | |
| retention-days: 7 | |
| docker-publish: | |
| needs: build-and-test | |
| if: github.ref == 'refs/heads/master' && github.event_name == 'push' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| packages: write | |
| # This is used to complete the identity challenge | |
| # with sigstore/fulcio when running outside of PRs. | |
| id-token: write | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| # First setup and build the artifact to ensure it's available for the Docker build | |
| - name: Set up JDK ${{ env.JAVA_VERSION }} | |
| uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5 | |
| with: | |
| java-version: ${{ env.JAVA_VERSION }} | |
| distribution: 'temurin' | |
| cache: 'maven' | |
| - name: Install pnpm | |
| uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 | |
| with: | |
| version: ${{ env.PNPM_VERSION }} | |
| - name: Set up Node.js ${{ env.NODE_VERSION }} | |
| id: pnpm-modules-cache | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: 'pnpm' | |
| cache-dependency-path: 'pnpm-lock.yaml' | |
| - name: Install Frontend Dependencies | |
| run: pnpm install --frozen-lockfile --ignore-scripts | |
| working-directory: insights-webapp/src/main/frontend | |
| - name: Build | |
| run: mvn clean package -DskipTests "-Dspring.profiles.active=prod" -Drevision="${{ env.APP_VERSION }}" | |
| # Install the cosign tool except on PR | |
| # https://github.com/sigstore/cosign-installer | |
| - name: Install cosign | |
| if: github.event_name != 'pull_request' | |
| uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 | |
| with: | |
| cosign-release: 'v3.1.3' | |
| # Set up BuildKit Docker container builder to be able to build | |
| # multi-platform images and export cache | |
| # https://github.com/docker/setup-buildx-action | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4 | |
| # Login against a Docker registry except on PR | |
| # https://github.com/docker/login-action | |
| - name: Log into registry ${{ env.REGISTRY }} | |
| if: github.event_name != 'pull_request' | |
| uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 | |
| with: | |
| registry: ${{ env.REGISTRY }} | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| # Extract metadata (tags, labels) for both images | |
| # https://github.com/docker/metadata-action | |
| - name: Extract Docker metadata for the webapp | |
| id: meta-webapp | |
| uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6 | |
| with: | |
| images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME_WEBAPP }} | |
| tags: | | |
| type=raw,value=${{ env.APP_VERSION }} | |
| type=raw,value=latest,enable={{is_default_branch}} | |
| type=ref,event=branch | |
| labels: | | |
| org.opencontainers.image.title=insights-webapp | |
| org.opencontainers.image.description=Frank!Framework Insights webapp: REST API and Angular frontend | |
| org.opencontainers.image.version=${{ env.APP_VERSION }} | |
| - name: Extract Docker metadata for the data import service | |
| id: meta-data-import | |
| uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6 | |
| with: | |
| images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME_DATA_IMPORT }} | |
| tags: | | |
| type=raw,value=${{ env.APP_VERSION }} | |
| type=raw,value=latest,enable={{is_default_branch}} | |
| type=ref,event=branch | |
| labels: | | |
| org.opencontainers.image.title=insights-data-import | |
| org.opencontainers.image.description=Frank!Framework Insights data import service: GitHub ingestion and Trivy vulnerability scanning | |
| org.opencontainers.image.version=${{ env.APP_VERSION }} | |
| # Build and push both images with Buildx (don't push on PR). | |
| # https://github.com/docker/build-push-action | |
| - name: Build and push the webapp image | |
| id: build-and-push-webapp | |
| uses: docker/build-push-action@9e436ba9f2d7bcd1d038c8e55d039d37896ddc5d | |
| with: | |
| context: . | |
| file: docker/Dockerfile | |
| target: webapp | |
| push: ${{ github.event_name != 'pull_request' }} | |
| tags: ${{ steps.meta-webapp.outputs.tags }} | |
| labels: ${{ steps.meta-webapp.outputs.labels }} | |
| annotations: ${{ steps.meta-webapp.outputs.annotations }} | |
| cache-from: type=gha,scope=webapp | |
| cache-to: type=gha,mode=max,scope=webapp | |
| - name: Build and push the data import image | |
| id: build-and-push-data-import | |
| uses: docker/build-push-action@9e436ba9f2d7bcd1d038c8e55d039d37896ddc5d | |
| with: | |
| context: . | |
| file: docker/Dockerfile | |
| target: data-import | |
| push: ${{ github.event_name != 'pull_request' }} | |
| tags: ${{ steps.meta-data-import.outputs.tags }} | |
| labels: ${{ steps.meta-data-import.outputs.labels }} | |
| annotations: ${{ steps.meta-data-import.outputs.annotations }} | |
| cache-from: type=gha,scope=data-import | |
| cache-to: type=gha,mode=max,scope=data-import | |
| # Sign the resulting Docker image digests except on PRs. | |
| # This will only write to the public Rekor transparency log when the Docker | |
| # repository is public to avoid leaking data. If you would like to publish | |
| # transparency data even for private images, pass --force to cosign below. | |
| # https://github.com/sigstore/cosign | |
| # Signing happens per digest, so one call covers every tag pointing at it. | |
| - name: Sign the published webapp image | |
| if: ${{ github.event_name != 'pull_request' }} | |
| env: | |
| # https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-an-intermediate-environment-variable | |
| IMAGE: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME_WEBAPP }} | |
| DIGEST: ${{ steps.build-and-push-webapp.outputs.digest }} | |
| # This step uses the identity token to provision an ephemeral certificate | |
| # against the sigstore community Fulcio instance. | |
| run: cosign sign --yes "${IMAGE}@${DIGEST}" | |
| - name: Sign the published data import image | |
| if: ${{ github.event_name != 'pull_request' }} | |
| env: | |
| IMAGE: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME_DATA_IMPORT }} | |
| DIGEST: ${{ steps.build-and-push-data-import.outputs.digest }} | |
| run: cosign sign --yes "${IMAGE}@${DIGEST}" |