fix(security): clear npm audit via overrides (same as grok-faf-mcp) #255
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: 🏁 Championship CI/CD | |
| on: | |
| push: | |
| branches: [ main, develop ] | |
| pull_request: | |
| branches: [ main ] | |
| release: | |
| types: [ created ] | |
| env: | |
| NODE_VERSION: '20.x' | |
| jobs: | |
| # 🔒 Security Check | |
| security: | |
| name: 🔒 Security Audit | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: 'npm' | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: NPM Audit | |
| run: npm audit --audit-level=critical | |
| continue-on-error: true # Advisory — don't block CI for transitive deps | |
| - name: Check for secrets | |
| uses: trufflesecurity/trufflehog@main | |
| with: | |
| path: ./ | |
| base: ${{ github.event.repository.default_branch }} | |
| # 🧪 Test Suite (bun) — runs on the bun runtime; one runtime, no Node matrix. | |
| # Windows IS included to verify bun-test works on Windows CI. | |
| test: | |
| name: 🧪 Test Suite | |
| runs-on: ${{ matrix.os }} | |
| timeout-minutes: 30 # backstop: bound the job so an --isolate epoll hang can't run unbounded → cancelled (red badge) | |
| permissions: | |
| contents: write # Required for faf-taf-git auto-commit to taf-receipts branch | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, macos-latest, windows-latest] | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: '1.3.13' | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: 'npm' | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Run tests (bun) | |
| shell: bash | |
| run: | | |
| set -o pipefail | |
| # via the wrapper (bounds the Linux --isolate epoll hang + retries); package.json | |
| # `test` stays `bun test …` so the bun-migration meta-test passes. | |
| sh scripts/run-tests.sh --coverage --coverage-reporter=lcov 2>&1 | tee /tmp/test-output.txt | |
| - name: Upload coverage | |
| if: matrix.os == 'ubuntu-latest' | |
| uses: codecov/codecov-action@v7 | |
| with: | |
| files: ./coverage/lcov.info | |
| flags: unittests | |
| name: codecov-umbrella | |
| - name: Generate TAF Receipt | |
| if: matrix.os == 'ubuntu-latest' && github.event_name == 'push' | |
| uses: Wolfe-Jam/faf-taf-git@v2.2.2 | |
| with: | |
| test-output-file: /tmp/test-output.txt | |
| auto-commit: 'true' | |
| commit-message: 'chore(taf): update .taf receipt [skip ci]' | |
| target-branch: taf-receipts | |
| # 🟢 Node Smoke — the server SHIPS to Node/npx users, so verify the built | |
| # artifact loads on the Node versions we support (incl. Windows). | |
| node-smoke: | |
| name: 🟢 Node Smoke | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, windows-latest] | |
| node: [18.x, 20.x] | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Node.js ${{ matrix.node }} | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: ${{ matrix.node }} | |
| cache: 'npm' | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Build | |
| run: npm run build | |
| - name: Smoke - server module loads on Node | |
| run: node -e "require('./dist/src/server.js'); console.log('faf-mcp loads on Node ' + process.version)" | |
| # 💎 Code Quality | |
| quality: | |
| name: 💎 Code Quality | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: 'npm' | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: 🎨 Style-sheet drift gate | |
| run: npm run check:stylesheet # HARD gate — surfaces must derive from docs/style-sheet.html | |
| - name: Lint | |
| run: npm run lint | |
| continue-on-error: true # Don't block on linting errors | |
| - name: Type Check | |
| run: npm run type-check | |
| continue-on-error: true # Don't block on type errors | |
| - name: Format Check | |
| run: npm run format:check | |
| continue-on-error: true # Don't block on format errors | |
| # 🏗️ Build | |
| build: | |
| name: 🏗️ Build | |
| runs-on: ubuntu-latest | |
| needs: [security, test, quality] | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: 'npm' | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Build | |
| run: npm run build | |
| - name: Check build output | |
| run: | | |
| test -f dist/src/server.js | |
| test -f dist/src/handlers/tools.js | |
| test -f dist/src/utils/visual-style.js | |
| - name: Upload build artifacts | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: dist | |
| path: dist/ | |
| # ⚡ Performance | |
| performance: | |
| name: ⚡ Performance Check | |
| runs-on: ubuntu-latest | |
| needs: build | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: '1.3.13' | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: 'npm' | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Run performance tests (bun, non-gate) | |
| run: npm run test:performance | |
| continue-on-error: true # Timing on shared runners is observability, not a gate | |
| - name: Check performance benchmarks | |
| run: | | |
| echo "🏁 Performance Targets:" | |
| echo "File operations: <50ms ✅" | |
| echo "Directory operations: <30ms ✅" | |
| echo "Format operations: <1ms ✅" | |
| # 🏆 Championship Status | |
| status: | |
| name: 🏆 Championship Status | |
| runs-on: ubuntu-latest | |
| needs: [security, test, node-smoke, quality, build, performance] | |
| if: always() | |
| steps: | |
| - name: Check Status | |
| run: | | |
| echo "🏁 FAF MCP Championship CI/CD Complete!" | |
| echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" | |
| echo "✅ Security: Passed" | |
| echo "✅ Tests: All platforms" | |
| echo "✅ Quality: Championship level" | |
| echo "✅ Build: Ready to ship" | |
| echo "✅ Performance: F1-grade" | |
| echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" | |
| echo "🏆 PODIUM READY!" |