From 5668733b09d6c61e9299b91a60d33b1fb60d6f3d Mon Sep 17 00:00:00 2001 From: Aarav Sharma Date: Fri, 11 Sep 2026 12:14:49 -0600 Subject: [PATCH] ci: split CI workflow into dedicated test and publish workflows --- .github/workflows/{ci.yml => publish.yml} | 14 +++++--- .github/workflows/test.yml | 43 +++++++++++++++++++++++ README.md | 3 +- 3 files changed, 54 insertions(+), 6 deletions(-) rename .github/workflows/{ci.yml => publish.yml} (76%) create mode 100644 .github/workflows/test.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/publish.yml similarity index 76% rename from .github/workflows/ci.yml rename to .github/workflows/publish.yml index c37d340..055451c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/publish.yml @@ -1,11 +1,14 @@ -name: CI +name: Publish + +# Default permissions are least-privilege; the publish job elevates to +# contents: write / packages: write below. This satisfies zizmor's +# excessive-permissions check. +permissions: + contents: read on: push: - branches: [main] tags: ['v*'] - pull_request: - branches: [main] jobs: test: @@ -34,8 +37,9 @@ jobs: publish: name: Publish to GitHub Packages runs-on: ubuntu-latest + # Tag pushes can't depend on the separate Test workflow, so tests are + # re-run here and the publish job is gated on them succeeding. needs: test - if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') permissions: contents: write packages: write diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml new file mode 100644 index 0000000..3db8cbe --- /dev/null +++ b/.github/workflows/test.yml @@ -0,0 +1,43 @@ +name: Test + +# Default permissions are least-privilege; no job needs elevated access. +# This satisfies zizmor's excessive-permissions check. +permissions: + contents: read + +# A newer push to the same ref cancels any older run that is still +# in progress, so superseded runs don't tie up runners or produce +# stale check results. +concurrency: + group: test-${{ github.ref }} + cancel-in-progress: true + +on: + push: + branches: [main] + pull_request: + branches: [main] + +jobs: + test: + name: Build & Test + runs-on: ubuntu-latest + steps: + - name: Checkout + uses: actions/checkout@v4 + + - name: Set up JDK 17 + uses: actions/setup-java@v5 + with: + distribution: 'temurin' + java-version: '17' + + - name: Run tests + run: gradle --no-daemon test + + - name: Upload test results + if: always() + uses: actions/upload-artifact@v4 + with: + name: test-results + path: build/reports/tests/test/ diff --git a/README.md b/README.md index 4d89e42..b3b3a6b 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,7 @@ # Synapse -[![CI](https://github.com/IamCoder18/synapse/actions/workflows/ci.yml/badge.svg)](https://github.com/IamCoder18/synapse/actions/workflows/ci.yml) +[![Test](https://github.com/IamCoder18/synapse/actions/workflows/test.yml/badge.svg)](https://github.com/IamCoder18/synapse/actions/workflows/test.yml) +[![Publish](https://github.com/IamCoder18/synapse/actions/workflows/publish.yml/badge.svg)](https://github.com/IamCoder18/synapse/actions/workflows/publish.yml) [![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](./LICENSE) [![Latest release](https://img.shields.io/github/v/tag/IamCoder18/synapse?label=release)](https://github.com/IamCoder18/synapse/releases) [![Maven Package](https://img.shields.io/badge/Maven-GitHub%20Packages-blue)](https://github.com/IamCoder18/synapse/packages)