Repository navigation
fix: small component robustness and a11y issues #1572
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI/CD Workflow | |
| on: | |
| pull_request: | |
| push: | |
| branches: | |
| - main | |
| jobs: | |
| securesdlc: | |
| uses: inkonchain/.github/.github/workflows/securesdlc.yml@main | |
| secrets: inherit | |
| install_modules: | |
| needs: securesdlc | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: volta-cli/action@v4 | |
| - uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v4.4.0 | |
| with: | |
| run_install: false | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "22.x" | |
| cache: "pnpm" | |
| - name: Add pnpm store path to env var | |
| id: pnpm-cache | |
| shell: bash | |
| run: echo "STORE_PATH=$(pnpm store path)" >> $GITHUB_OUTPUT | |
| # Restore the cache BEFORE installing: restoring afterwards can extract a | |
| # stale node_modules (via restore-keys) on top of a fresh install and then | |
| # save that poisoned state under the new lockfile's cache key. | |
| - name: Cache node modules | |
| uses: actions/cache@v4 | |
| with: | |
| path: | | |
| ${{ steps.pnpm-cache.outputs.STORE_PATH }} | |
| **/node_modules | |
| key: ${{ runner.os }}-pnpm-store-v2-${{ hashFiles('**/pnpm-lock.yaml') }} | |
| restore-keys: | | |
| ${{ runner.os }}-pnpm-store-v2- | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| js-lint: | |
| needs: install_modules | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: ./.github/actions/base-setup | |
| name: Base Setup | |
| - name: JS linting | |
| run: pnpm run lint:js | |
| md-lint: | |
| needs: install_modules | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: ./.github/actions/base-setup | |
| name: Base Setup | |
| - name: MDX linting | |
| run: pnpm run lint:mdx | |
| format: | |
| needs: install_modules | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: ./.github/actions/base-setup | |
| name: Base Setup | |
| - name: Run formatting | |
| run: pnpm run format:js | |
| # spell-check: | |
| # needs: install_modules | |
| # runs-on: ubuntu-latest | |
| # steps: | |
| # - uses: actions/checkout@v4 | |
| # - uses: ./.github/actions/base-setup | |
| # name: Base Setup | |
| # - name: Run Spellcheck | |
| # run: pnpm run spellcheck:lint | |
| build: | |
| needs: install_modules | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: ./.github/actions/base-setup | |
| name: Base Setup | |
| - name: Building app | |
| run: pnpm run build | |
| - name: Cache build | |
| uses: actions/cache/save@v4 | |
| with: | |
| path: .next | |
| key: ${{ runner.os }}-build-store-${{ hashFiles('.next') }} | |
| # Deploys to the foundation-owned Vercel team using a token (no Vercel GitHub | |
| # App install needed on this org). Preview deploys only run for branches in | |
| # this repo, since fork PRs can't access secrets. | |
| vercel-preview: | |
| if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository | |
| runs-on: ubuntu-latest | |
| needs: build | |
| permissions: | |
| contents: read | |
| env: | |
| VERCEL_ORG_ID: team_EiiXT7xNqKi1zE7Mqbq4JYAO | |
| VERCEL_PROJECT_ID: prj_65DDk6laQQj9MHWKaPNBDxDxviDp | |
| steps: | |
| - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| with: | |
| persist-credentials: false | |
| - name: Deploy preview to Vercel | |
| run: | | |
| URL=$(npx vercel@latest deploy --yes --token=${{ secrets.VERCEL_TOKEN }}) | |
| echo "### Vercel preview" >> $GITHUB_STEP_SUMMARY | |
| echo "$URL" >> $GITHUB_STEP_SUMMARY | |
| vercel-deploy: | |
| if: github.ref == 'refs/heads/main' | |
| runs-on: ubuntu-latest | |
| needs: build | |
| # Serialize production deploys so rapid merges can't complete out of | |
| # order and briefly promote an older commit. | |
| concurrency: | |
| group: vercel-production-deploy | |
| cancel-in-progress: false | |
| permissions: | |
| contents: read | |
| env: | |
| VERCEL_ORG_ID: team_EiiXT7xNqKi1zE7Mqbq4JYAO | |
| VERCEL_PROJECT_ID: prj_65DDk6laQQj9MHWKaPNBDxDxviDp | |
| steps: | |
| - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| with: | |
| persist-credentials: false | |
| - name: Deploy to Vercel (production) | |
| run: npx vercel@latest deploy --prod --yes --token=${{ secrets.VERCEL_TOKEN }} |