From 0c6d1483de42a323290b47485fd8b26038b391d4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BCller?= Date: Thu, 10 Sep 2026 19:41:09 +0200 Subject: [PATCH] :recycle: Port CI workflow from GitHub Actions to Gitea Actions The runner now lives on Gitea; move the workflow to .gitea/workflows/ and delete the stale .github copy (Gitea ignores .github/, so it's drift bait). Use the native gitea.ref context for the tag gate; keep actions pinned to their GitHub sources (the runner has internet + caches them). Drop the upload-artifact coverage step in favour of the self-hosted webserver plan tracked in the backlog. Add an empty-secret gate as publish's first step so a tag push without NPM_TOKEN fails loudly instead of silently no-oppping. --- {.github => .gitea}/workflows/ci.yml | 22 +++++++++++++--------- 1 file changed, 13 insertions(+), 9 deletions(-) rename {.github => .gitea}/workflows/ci.yml (66%) diff --git a/.github/workflows/ci.yml b/.gitea/workflows/ci.yml similarity index 66% rename from .github/workflows/ci.yml rename to .gitea/workflows/ci.yml index 1c9bdd0..189cdd8 100644 --- a/.github/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -20,15 +20,10 @@ jobs: - run: npm run build - run: npm run check - run: npm run test:ci - - name: Upload coverage - uses: actions/upload-artifact@v4 - with: - name: coverage - path: coverage - # Advisory scans (dead code, dependency freshness). Non-blocking: surfaced on - # the PR for visibility, but must never gate a merge — so continue-on-error and - # intentionally NOT in `publish`'s `needs`. + # Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in + # the Actions tab for visibility, but must never gate a merge — so + # continue-on-error and intentionally NOT in `publish`'s `needs`. maintain: runs-on: ubuntu-latest continue-on-error: true @@ -42,10 +37,19 @@ jobs: - run: npm run maintain publish: - if: startsWith(github.ref, 'refs/tags/') + if: startsWith(gitea.ref, 'refs/tags/') needs: build runs-on: ubuntu-latest steps: + # Double-gate: publish only runs on a tag *and* aborts here if NPM_TOKEN + # is unset, so a tag push never silently no-ops (or half-publishes). Set + # NPM_TOKEN in the Gitea repo: Settings → Actions → Secrets. + - name: Assert NPM_TOKEN is configured + run: | + if [ -z "${{ secrets.NPM_TOKEN }}" ]; then + echo "::error::NPM_TOKEN secret is not set — refusing to publish." + exit 1 + fi - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: