Skip to content

Converted insights custom scss to tailwind #1269

Converted insights custom scss to tailwind

Converted insights custom scss to tailwind #1269

Workflow file for this run

name: Build and Test Application
on:
pull_request:
types: [ opened, synchronize, reopened ]
branches: [ master ]
push:
branches: [ master ]
env:
JAVA_VERSION: 25
NODE_VERSION: 24
PNPM_VERSION: 10.33.0
REGISTRY: ghcr.io
IMAGE_NAME_WEBAPP: ${{ github.repository }}-webapp
IMAGE_NAME_DATA_IMPORT: ${{ github.repository }}-data-import
APP_VERSION: 0.0.${{ github.run_number }}
jobs:
build-and-test:
name: Build & Run All Tests
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Set up JDK ${{ env.JAVA_VERSION }}
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5
with:
java-version: ${{ env.JAVA_VERSION }}
distribution: 'temurin'
cache: 'maven'
- name: Install pnpm
uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061
with:
version: ${{ env.PNPM_VERSION }}
- name: Set up Node.js ${{ env.NODE_VERSION }}
id: pnpm-modules-cache
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: ${{ env.NODE_VERSION }}
cache: 'pnpm'
cache-dependency-path: 'pnpm-lock.yaml'
- name: Install Frontend Dependencies
run: pnpm install --frozen-lockfile --ignore-scripts
working-directory: insights-webapp/src/main/frontend
- name: Lint Frontend
run: pnpm lint
working-directory: insights-webapp/src/main/frontend
- name: Spotless
run: mvn spotless:check
- name: Checkstyle
run: mvn checkstyle:check
- name: Test Frontend
run: pnpm test --watch=false --browsers=ChromeHeadless
working-directory: insights-webapp/src/main/frontend
- name: Test & Build Backend and run E2E Tests
run: mvn clean package "-Dspring.profiles.active=local-seed"
- name: Upload CI Artifacts on Failure
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: test-artifacts
path: |
**/target/surefire-reports/
**/target/failsafe-reports/
**/target/cypress/
retention-days: 7
docker-publish:
needs: build-and-test
if: github.ref == 'refs/heads/master' && github.event_name == 'push'
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
# This is used to complete the identity challenge
# with sigstore/fulcio when running outside of PRs.
id-token: write
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
# First setup and build the artifact to ensure it's available for the Docker build
- name: Set up JDK ${{ env.JAVA_VERSION }}
uses: actions/setup-java@b6effb05e454b25005698d916606bdc6ffcbf961 # v5
with:
java-version: ${{ env.JAVA_VERSION }}
distribution: 'temurin'
cache: 'maven'
- name: Install pnpm
uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061
with:
version: ${{ env.PNPM_VERSION }}
- name: Set up Node.js ${{ env.NODE_VERSION }}
id: pnpm-modules-cache
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: ${{ env.NODE_VERSION }}
cache: 'pnpm'
cache-dependency-path: 'pnpm-lock.yaml'
- name: Install Frontend Dependencies
run: pnpm install --frozen-lockfile --ignore-scripts
working-directory: insights-webapp/src/main/frontend
- name: Build
run: mvn clean package -DskipTests "-Dspring.profiles.active=prod" -Drevision="${{ env.APP_VERSION }}"
# Install the cosign tool except on PR
# https://github.com/sigstore/cosign-installer
- name: Install cosign
if: github.event_name != 'pull_request'
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
with:
cosign-release: 'v3.1.3'
# Set up BuildKit Docker container builder to be able to build
# multi-platform images and export cache
# https://github.com/docker/setup-buildx-action
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4
# Login against a Docker registry except on PR
# https://github.com/docker/login-action
- name: Log into registry ${{ env.REGISTRY }}
if: github.event_name != 'pull_request'
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
# Extract metadata (tags, labels) for both images
# https://github.com/docker/metadata-action
- name: Extract Docker metadata for the webapp
id: meta-webapp
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME_WEBAPP }}
tags: |
type=raw,value=${{ env.APP_VERSION }}
type=raw,value=latest,enable={{is_default_branch}}
type=ref,event=branch
labels: |
org.opencontainers.image.title=insights-webapp
org.opencontainers.image.description=Frank!Framework Insights webapp: REST API and Angular frontend
org.opencontainers.image.version=${{ env.APP_VERSION }}
- name: Extract Docker metadata for the data import service
id: meta-data-import
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME_DATA_IMPORT }}
tags: |
type=raw,value=${{ env.APP_VERSION }}
type=raw,value=latest,enable={{is_default_branch}}
type=ref,event=branch
labels: |
org.opencontainers.image.title=insights-data-import
org.opencontainers.image.description=Frank!Framework Insights data import service: GitHub ingestion and Trivy vulnerability scanning
org.opencontainers.image.version=${{ env.APP_VERSION }}
# Build and push both images with Buildx (don't push on PR).
# https://github.com/docker/build-push-action
- name: Build and push the webapp image
id: build-and-push-webapp
uses: docker/build-push-action@9e436ba9f2d7bcd1d038c8e55d039d37896ddc5d
with:
context: .
file: docker/Dockerfile
target: webapp
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta-webapp.outputs.tags }}
labels: ${{ steps.meta-webapp.outputs.labels }}
annotations: ${{ steps.meta-webapp.outputs.annotations }}
cache-from: type=gha,scope=webapp
cache-to: type=gha,mode=max,scope=webapp
- name: Build and push the data import image
id: build-and-push-data-import
uses: docker/build-push-action@9e436ba9f2d7bcd1d038c8e55d039d37896ddc5d
with:
context: .
file: docker/Dockerfile
target: data-import
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta-data-import.outputs.tags }}
labels: ${{ steps.meta-data-import.outputs.labels }}
annotations: ${{ steps.meta-data-import.outputs.annotations }}
cache-from: type=gha,scope=data-import
cache-to: type=gha,mode=max,scope=data-import
# Sign the resulting Docker image digests except on PRs.
# This will only write to the public Rekor transparency log when the Docker
# repository is public to avoid leaking data. If you would like to publish
# transparency data even for private images, pass --force to cosign below.
# https://github.com/sigstore/cosign
# Signing happens per digest, so one call covers every tag pointing at it.
- name: Sign the published webapp image
if: ${{ github.event_name != 'pull_request' }}
env:
# https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-an-intermediate-environment-variable
IMAGE: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME_WEBAPP }}
DIGEST: ${{ steps.build-and-push-webapp.outputs.digest }}
# This step uses the identity token to provision an ephemeral certificate
# against the sigstore community Fulcio instance.
run: cosign sign --yes "${IMAGE}@${DIGEST}"
- name: Sign the published data import image
if: ${{ github.event_name != 'pull_request' }}
env:
IMAGE: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME_DATA_IMPORT }}
DIGEST: ${{ steps.build-and-push-data-import.outputs.digest }}
run: cosign sign --yes "${IMAGE}@${DIGEST}"