name: CI # Build + test gate. Runs on pushes to the long-lived branches and on every PR so # the 39-test suite (and both builds) must pass before merge. on: push: branches: [main, develop] pull_request: jobs: backend: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-dotnet@v4 with: dotnet-version: '8.0.x' - name: Restore run: dotnet restore InboxIntel.sln - name: Build run: dotnet build InboxIntel.sln -c Release --no-restore - name: Test run: dotnet test InboxIntel.sln -c Release --no-build --verbosity normal frontend: runs-on: ubuntu-latest defaults: run: working-directory: frontend steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version: '22' - name: Install run: npm ci - name: Build run: npm run build # AUDIT L-10: the pre-commit hook enforces formatting locally, but --no-verify or web edits # can bypass it — this makes the same check a server-side gate. format: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-dotnet@v4 with: dotnet-version: '8.0.x' - name: dotnet format (verify only) run: dotnet format InboxIntel.sln --verify-no-changes # AUDIT M-7: the search paths the InMemory provider can't translate (FTS ranking, # ts_headline, pg_trgm, pgvector) previously had only manual verification. This job runs # the Category=LiveDb tests against a real pgvector Postgres service container. db-tests: runs-on: ubuntu-latest services: postgres: image: pgvector/pgvector:pg16 env: POSTGRES_USER: test POSTGRES_PASSWORD: test POSTGRES_DB: test env: LIVEDB_CONNECTION: "Host=postgres;Port=5432;Database=test;Username=test;Password=test" steps: - uses: actions/checkout@v4 - uses: actions/setup-dotnet@v4 with: dotnet-version: '8.0.x' - name: Wait for Postgres run: | for i in $(seq 1 30); do (echo > /dev/tcp/postgres/5432) 2>/dev/null && exit 0 sleep 1 done echo "Postgres service did not become reachable" >&2 exit 1 - name: Live-DB tests run: dotnet test InboxIntel.sln --filter "Category=LiveDb" --verbosity normal