daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

ci.yml (1597B)


      1 # Quality gate. Vercel builds and deploys on its own; this workflow exists so a
      2 # broken dataset, a type error or a failing test is visible on the PR / commit
      3 # before (or regardless of) the deploy. Nothing here writes to the repo.
      4 name: CI
      5 
      6 on:
      7   push:
      8     branches: [main]
      9   pull_request:
     10   workflow_dispatch:
     11 
     12 permissions:
     13   contents: read
     14 
     15 concurrency:
     16   group: ci-${{ github.ref }}
     17   cancel-in-progress: true
     18 
     19 jobs:
     20   quality:
     21     name: check · test · validate data
     22     runs-on: ubuntu-latest
     23     steps:
     24       - uses: actions/checkout@v4
     25       - uses: actions/setup-node@v4
     26         with:
     27           node-version: 22
     28           cache: npm
     29       - run: npm ci
     30       - name: Typecheck (astro check)
     31         run: npm run check
     32       - name: Unit tests (node --test)
     33         run: npm test
     34       - name: Validate committed dataset
     35         run: npm run validate:data
     36 
     37   build:
     38     name: astro build + pagefind
     39     runs-on: ubuntu-latest
     40     steps:
     41       - uses: actions/checkout@v4
     42       - uses: actions/setup-node@v4
     43         with:
     44           node-version: 22
     45           cache: npm
     46       - run: npm ci
     47       - run: npm run build
     48       - name: Sanity-check the output
     49         run: |
     50           test -f dist/index.html
     51           test -f dist/catalog/index.html
     52           test -f dist/sitemap-index.xml
     53           test -f dist/pagefind/pagefind.js
     54           # Canonicals must not point at a redirect (vercel.json: trailingSlash false).
     55           if grep -q 'rel="canonical" href="[^"]*/"' dist/catalog/index.html; then
     56             echo "::error::canonical on /catalog carries a trailing slash"; exit 1; fi