Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
80 changes: 74 additions & 6 deletions .github/workflows/upload.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,26 +9,37 @@ on:
- main
pull_request: {}

concurrency:
group: cos-upload-${{ github.repository }}-${{ github.event_name == 'pull_request' && format('pr-{0}-{1}', github.event.pull_request.number, github.run_id) || 'production' }}
cancel-in-progress: false

jobs:
test:
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- uses: actions/setup-node@v6
- uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6.5.0
with:
node-version: 24
package-manager-cache: false

- name: Enable Corepack
run: |
corepack enable
corepack prepare yarn@4.18.0 --activate
yarn --version

- uses: calcit-lang/setup-calcit@v1
- uses: calcit-lang/setup-calcit@ca701be5a471759e442aa053cd100720bbe1f09f # v1.5.0
with:
tools: calcit,caps
caps-version: "0.1.1"

- name: Install dependencies
run: |
set -euo pipefail
caps --strict --ci
yarn install --immutable

Expand All @@ -37,20 +48,76 @@ jobs:

- name: Validate snapshot and types
run: |
set -euo pipefail
test "$(calcit --version)" = "0.27.0"
test -f calcit.cirru
test -f deps.cirru
test ! -e compact.cirru
test ! -e package.cirru
calcit calcit.cirru edit format
git diff --exit-code -- calcit.cirru
calcit calcit.cirru --check-only
calcit calcit.cirru analyze check-public \
--ns app.comp.container --ns app.config --ns app.main \
--ns app.schema --ns app.updater --summary-only --format json
calcit calcit.cirru analyze dynamic-methods --summary-only --format json | jq -e '.data.summary.findings == 0'

- name: Select frontend CDN path
id: asset-path
env:
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
if [[ "$GITHUB_EVENT_NAME" == "pull_request" ]]; then
prefix="${GITHUB_REPOSITORY}/pr/${PR_NUMBER}/${GITHUB_RUN_ID}/"
else
prefix="${GITHUB_REPOSITORY}/"
fi
base_url="https://cos-sh.tiye.me/${prefix}"
echo "VITE_BASE_URL=${base_url}" >> "$GITHUB_ENV"
echo "prefix=${prefix}" >> "$GITHUB_OUTPUT"
echo "base-url=${base_url}" >> "$GITHUB_OUTPUT"

- name: Compile and build
run: |
set -euo pipefail
calcit calcit.cirru js
node --test scripts/typed-reel-render.test.mjs
yarn vite build --base=./
yarn vite build --base="$VITE_BASE_URL"

- name: Check COS credentials
id: cos-credentials
if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository
env:
COS_BUCKET: ${{ secrets.COS_BUCKET }}
COS_SECRET_ID: ${{ secrets.COS_SECRET_ID }}
COS_SECRET_KEY: ${{ secrets.COS_SECRET_KEY }}
Comment on lines +89 to +93

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

已检查仓库:存在多位 write 协作者,目前唯一环境 copilot 没有保护规则,因此这条风险成立。已向维护者请求选择:配置有审批保护且使用独立预览密钥的部署环境,或暂时把 COS 上传限制到 main。不会仅添加空 environment 名称就宣称已受保护,也不会在没有维护者决定时擅自修改协作者权限或密钥配置。此线程保持未解决。

run: |
if [[ -n "$COS_BUCKET" && -n "$COS_SECRET_ID" && -n "$COS_SECRET_KEY" ]]; then
echo "available=true" >> "$GITHUB_OUTPUT"
elif [[ "$GITHUB_EVENT_NAME" == "pull_request" ]]; then
echo "available=false" >> "$GITHUB_OUTPUT"
echo "::warning::COS secrets missing; upload verification skipped."
else
echo "::error::COS_BUCKET, COS_SECRET_ID and COS_SECRET_KEY are required."
exit 1
fi

- name: Upload and verify frontend assets
if: steps.cos-credentials.outputs.available == 'true'
uses: worktools/cos-upload-action@17e6d213fe9f6772a6090a13c8ba044cd6cbcb09 # v1.1.1
with:
source-dir: dist
bucket: ${{ secrets.COS_BUCKET }}
region: ap-shanghai
prefix: ${{ steps.asset-path.outputs.prefix }}
public-base-url: ${{ steps.asset-path.outputs.base-url }}
secret-id: ${{ secrets.COS_SECRET_ID }}
secret-key: ${{ secrets.COS_SECRET_KEY }}

- name: Deploy to server
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
id: deploy
uses: Pendect/action-rsyncer@v2.0.0
uses: Pendect/action-rsyncer@8e05ffa5c93e5d9c9b167796b26044d2c616b2b9 # v2.0.0
env:
DEPLOY_KEY: ${{secrets.rsync_private_key}}
with:
Expand All @@ -61,4 +128,5 @@ jobs:
dest: "rsync-user@tiye.me:/web-assets/repo/${{ github.repository }}/${{ github.event_name == 'pull_request' && format('pr/{0}/', github.event.pull_request.number) || '' }}"

- name: Display status from deploy
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
run: echo "${{ steps.deploy.outputs.status }}"
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@

.compact-inc.cirru
.calcit-error.cirru
.calcit/
compact.cirru
package.cirru

js-out/
node_modules/
Expand Down
2 changes: 1 addition & 1 deletion .yarnrc.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
nodeLinker: node-modules
npmPreapprovedPackages:
- "@calcit/procs@0.23.1"
- "@calcit/procs@0.27.0"
24 changes: 23 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,29 @@ Demo http://repo.respo-mvc.org/markup/ .

### Usages

_TODO_
Use Calcit/procs 0.27.0, Caps 0.1.1, Node.js 24 and Yarn 4.18.0.
Canonical source and dependencies are `calcit.cirru` and `deps.cirru`;
retired compact/package snapshots are not used. Edit source with the Calcit CLI.

```sh
caps --strict --ci
yarn install --immutable
caps verify --toolchain
calcit calcit.cirru js
yarn vite
```

CI retains strict dependency resolution, entry/type checks and the existing
typed Reel rendering test, and checks all application public definitions.

### Deployment

Frontend build uses `VITE_BASE_URL`, pointing to
`https://cos-sh.tiye.me/Respo/markup/` on main and
`https://cos-sh.tiye.me/Respo/markup/pr/<number>/<run-id>/` for PR previews.
COS action v1.1.1 uploads `dist` and verifies through `public-base-url`;
no separate upload verification script is needed. Production server deployment
keeps its original source and destination; PRs do not deploy to the server.

### Workflow

Expand Down
2 changes: 1 addition & 1 deletion calcit.cirru
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
:about "|Machine-generated snapshot. Do not edit directly — changes will be overwritten. Use `calcit query` to inspect and `calcit edit`/`calcit tree` to modify. Run `calcit docs agents --contract` before mutations; use `--full` for first orientation or changed contract digest. Manual edits must follow format and schema conventions, then run `calcit edit format`."
:package |app
:entries $ {} $ :default
{} (:description |) (:init-fn 'app.main/main!) (:mode :native) (:reload-fn 'app.main/reload!)
{} (:description |) (:init-fn 'app.main/main!) (:mode :js) (:reload-fn 'app.main/reload!) (:target :browser)
:feature-policy $ {}
:modules $ [] |respo.calcit/ |respo-ui.calcit/ |reel.calcit/
:type-slots $ {}
Expand Down
8 changes: 4 additions & 4 deletions deps.cirru
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@

{} (:calcit-version |0.23.1)
{} (:calcit-version |0.27.0)
:version |0.0.5
:dependencies $ {} (|Respo/reel.calcit |0.6.32)
|Respo/respo-ui.calcit |0.7.31
|Respo/respo.calcit |0.16.113
:dependencies $ {} (|Respo/reel.calcit |0.6.33-alpha.2)
|Respo/respo-ui.calcit |0.7.32-alpha.3
|Respo/respo.calcit |0.16.114-alpha.5
Comment thread
tiye marked this conversation as resolved.
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"packageManager": "yarn@4.18.0",
"dependencies": {
"@calcit/procs": "0.23.1"
"@calcit/procs": "0.27.0"
},
"devDependencies": {
"bottom-tip": "^0.1.5",
Expand Down
10 changes: 5 additions & 5 deletions yarn.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading