Commit Graph
42 Commits
Author SHA1 Message Date
popertotsandSisyphus 93883602d9 ci: extract frontend deps checks into separate gating job
CI / Frontend deps check (push) Successful in 39s
CI / Go vulnerabilities (push) Successful in 44s
CI / Build & Vet (push) Successful in 58s
CI / Tests (prod) (push) Has been cancelled
CI / Tests (dev) (push) Has been cancelled
CI / Race (prod) (push) Has been cancelled
CI / Race (dev) (push) Has been cancelled
CI / Frontend build (gate) (push) Has been cancelled
CI / Frontend QC (audit) (push) Has been cancelled
CI / Frontend QC (typecheck) (push) Has been cancelled
CI / Frontend QC (lint) (push) Has been cancelled
frontend-deps runs npm outdated + stale override checks as its own job. frontend-build waits for frontend-deps before starting, so stale deps stop the pipeline before build resources are consumed.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:52:53 +01:00
popertotsandSisyphus 2604f9ab0d ci: add stale override detection to frontend build gate
CI / Go vulnerabilities (push) Successful in 47s
CI / Build & Vet (push) Successful in 1m2s
CI / Tests (prod) (push) Has been cancelled
CI / Tests (dev) (push) Has been cancelled
CI / Race (prod) (push) Has been cancelled
CI / Race (dev) (push) Has been cancelled
CI / Frontend build (gate) (push) Has been cancelled
CI / Frontend QC (audit) (push) Has been cancelled
CI / Frontend QC (typecheck) (push) Has been cancelled
CI / Frontend QC (lint) (push) Has been cancelled
Parses npm explain output for each overridden package. If the parent's required range already satisfies the override target, flags it as stale — dev must remove the override.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:51:32 +01:00
popertotsandSisyphus 4b5d3640bb ci: add dependency staleness check to frontend build gate
CI / Go vulnerabilities (push) Successful in 1m3s
CI / Build & Vet (push) Successful in 1m36s
CI / Frontend build (gate) (push) Successful in 1m36s
CI / Frontend QC (audit) (push) Successful in 1m19s
CI / Frontend QC (typecheck) (push) Successful in 1m30s
CI / Tests (prod) (push) Successful in 1m59s
CI / Tests (dev) (push) Successful in 2m14s
CI / Race (prod) (push) Has been cancelled
CI / Race (dev) (push) Has been cancelled
CI / Frontend QC (lint) (push) Has been cancelled
After npm ci, runs npm outdated --json and fails if any in-range (current != wanted) updates exist. Developer must run npm update locally and commit the lockfile.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:46:54 +01:00
popertotsandSisyphus 914f9993ec ci: remove test/race timeouts, add concurrency cancel-in-progress, fix npm audit vulns
CI / Go vulnerabilities (push) Successful in 35s
CI / Build & Vet (push) Successful in 49s
CI / Frontend build (gate) (push) Successful in 57s
CI / Tests (prod) (push) Has been cancelled
CI / Tests (dev) (push) Has been cancelled
CI / Race (prod) (push) Has been cancelled
CI / Race (dev) (push) Has been cancelled
CI / Frontend QC (audit) (push) Has been cancelled
CI / Frontend QC (typecheck) (push) Has been cancelled
CI / Frontend QC (lint) (push) Has been cancelled
- Remove -timeout 180s/240s from go test and race commands
- Add concurrency group to cancel stale pipelines on new pushes
- Run npm update to bump Vite 7.3.5 -> 7.3.6, fixing nested esbuild vuln
- npm audit now at 0 vulnerabilities

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:43:13 +01:00
popertotsandSisyphus a17d6fd2e6 ci: fail npm audit on any vuln, not just high/critical
CI / Go vulnerabilities (push) Successful in 55s
CI / Build & Vet (push) Successful in 1m15s
CI / Frontend build (gate) (push) Successful in 1m21s
CI / Frontend QC (audit) (push) Failing after 40s
CI / Frontend QC (typecheck) (push) Successful in 1m44s
CI / Tests (prod) (push) Successful in 2m5s
CI / Frontend QC (lint) (push) Successful in 3m10s
CI / Tests (dev) (push) Successful in 3m17s
CI / Race (prod) (push) Successful in 3m55s
CI / Race (dev) (push) Successful in 5m44s
Change audit-level from high to info so low and moderate findings also fail the CI step.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:35:23 +01:00
popertotsandSisyphus 29958620b6 ci: fix literal ${matrix.task} in step names (Gitea does not resolve them)
CI / Go vulnerabilities (push) Successful in 1m34s
CI / Build & Vet (push) Successful in 2m10s
CI / Frontend build (gate) (push) Successful in 1m59s
CI / Frontend QC (audit) (push) Successful in 55s
CI / Tests (prod) (push) Successful in 1m53s
CI / Frontend QC (typecheck) (push) Successful in 1m51s
CI / Tests (dev) (push) Successful in 2m19s
CI / Frontend QC (lint) (push) Successful in 2m43s
CI / Race (prod) (push) Successful in 3m51s
CI / Race (dev) (push) Failing after 6m44s
Replace with static names. Job names still use matrix templates (those work).

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:29:39 +01:00
popertotsandSisyphus ef26bd59e9 ci: fix go-version to 1.26 (no patch) and clean up step names
CI / Go vulnerabilities (push) Successful in 34s
CI / Build & Vet (push) Successful in 43s
CI / Frontend build (gate) (push) Successful in 54s
CI / Frontend QC (audit) (push) Successful in 1m4s
CI / Tests (prod) (push) Successful in 1m56s
CI / Tests (dev) (push) Successful in 1m55s
CI / Frontend QC (typecheck) (push) Successful in 2m38s
CI / Frontend QC (lint) (push) Successful in 2m41s
CI / Race (prod) (push) Successful in 5m8s
CI / Race (dev) (push) Successful in 6m58s
setup-go resolves '1.26' to latest patch (1.26.5). go.mod follows convention with minor version only. All CI steps now have descriptive names.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:22:23 +01:00
popertotsandSisyphus c344d6c54d chore: upgrade Go from 1.25.7 to 1.26.5
CI / Go vulnerabilities (push) Failing after 54s
CI / Frontend build (gate) (push) Successful in 59s
CI / Build & Vet (push) Successful in 1m40s
CI / Frontend audit (push) Successful in 39s
CI / Tests (prod) (push) Has been skipped
CI / Tests (dev) (push) Has been skipped
CI / Race (prod) (push) Has been skipped
CI / Race (dev) (push) Has been skipped
CI / Frontend typecheck (push) Successful in 1m0s
CI / Frontend lint (push) Successful in 1m23s
Go 1.26.5 released Jul 7, 2026. Includes security fix for GO-2026-5856 (crypto/tls ECH leak). Updates: CI runner (4x setup-go), go.mod, README, obsidian docs.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:11:49 +01:00
popertotsandSisyphus f59b7df97f ci: revert go-version to 1.25, add npm ci fallback in frontend QC jobs
CI / Go vulnerabilities (push) Successful in 33s
CI / Build & Vet (push) Successful in 43s
CI / Frontend build (gate) (push) Successful in 53s
CI / Frontend audit (push) Successful in 55s
CI / Frontend typecheck (push) Successful in 1m33s
CI / Tests (prod) (push) Successful in 2m9s
CI / Tests (dev) (push) Successful in 2m29s
CI / Frontend lint (push) Successful in 2m22s
CI / Race (prod) (push) Successful in 3m10s
CI / Race (dev) (push) Failing after 5m47s
1.25.12 unavailable in runner toolcache — revert to '1.25' which resolves to latest patch. The GO-2026-5856 vuln requires a Go patch release not yet available. Frontend QC jobs now run npm ci before their command since cache restore alone doesn't guarantee node_modules.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:07:17 +01:00
popertotsandSisyphus 7fd74dc65e ci: bump Go from 1.25 to 1.25.12 to fix GO-2026-5856
CI / Build & Vet (push) Failing after 25s
CI / Frontend build (gate) (push) Successful in 45s
CI / Go vulnerabilities (push) Successful in 46s
CI / Tests (prod) (push) Has been skipped
CI / Tests (dev) (push) Has been skipped
CI / Race (prod) (push) Has been skipped
CI / Race (dev) (push) Has been skipped
CI / Frontend typecheck (push) Failing after 7s
CI / Frontend lint (push) Failing after 8s
CI / Frontend audit (push) Successful in 9s
govulncheck found crypto/tls vuln fixed in 1.25.12. Bump all 4 setup-go instances.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:03:45 +01:00
popertotsandSisyphus 0a73c07f09 ci: split frontend into build gate then parallel typecheck/lint/audit
CI / Go vulnerabilities (push) Failing after 39s
CI / Build & Vet (push) Successful in 44s
CI / Tests (prod) (push) Has been skipped
CI / Tests (dev) (push) Has been skipped
CI / Race (prod) (push) Has been skipped
CI / Race (dev) (push) Has been skipped
CI / Frontend build (gate) (push) Successful in 55s
CI / Frontend typecheck (push) Failing after 10s
CI / Frontend lint (push) Failing after 12s
CI / Frontend audit (push) Successful in 13s
npm run build runs first as the gate. On success, typecheck, lint, and npm audit fire in parallel — all restoring node_modules from the build job's cache.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 17:02:21 +01:00
popertotsandSisyphus e5f823eecd ci: gate test and race behind both vet and vulns
CI / Go vulnerabilities (push) Failing after 41s
CI / Build & Vet (push) Successful in 46s
CI / Tests (prod) (push) Has been skipped
CI / Tests (dev) (push) Has been skipped
CI / Race (prod) (push) Has been skipped
CI / Race (dev) (push) Has been skipped
CI / Frontend lint & types (push) Successful in 1m20s
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-09 16:58:18 +01:00
popertotsandSisyphus 8326b15e72 ci: split dev/prod test and race jobs into parallel matrix
CI / Go vulnerabilities (push) Successful in 36s
CI / Build & Vet (push) Successful in 46s
CI / Frontend lint & types (push) Successful in 2m13s
CI / Tests (prod) (push) Successful in 1m28s
CI / Tests (dev) (push) Successful in 2m2s
CI / Race (prod) (push) Successful in 3m8s
CI / Race (dev) (push) Successful in 4m44s
Extract Build & Vet into a separate gate job. Use matrix strategy for test and race jobs so dev and prod variants run concurrently after vet passes. Cache keys include label to avoid collisions.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-07 00:15:25 +01:00
popertotsandSisyphus f4969645c4 chore: update CI, DB init, and documentation
CI / Go vulnerabilities (push) Successful in 37s
CI / Tests (push) Successful in 1m44s
CI / Frontend lint & types (push) Successful in 1m51s
CI / Race detector (push) Successful in 4m42s
Update CI workflow, PostgreSQL init script, README, and obsidian technical docs.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-07 00:10:18 +01:00
popertotsandSisyphus d8dfad2b32 ci: add Go and npm dependency caching via actions/cache
CI / Go vulnerabilities (push) Successful in 58s
CI / Tests (push) Successful in 1m53s
CI / Frontend lint & types (push) Successful in 2m12s
CI / Race detector (push) Successful in 3m59s
Add actions/cache@v4 to all four CI jobs. Go module cache (go/pkg/mod + go-build) keyed on go.sum for test, race, and vulns jobs. npm cache (~/.npm + node_modules) keyed on package-lock.json for frontend job. Cuts dependency download time to near-zero on cache hit.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-07-05 20:37:59 +01:00
popertots a00ed3c283 ci: re-add test and race jobs alongside lint and vulns
CI / Go vulnerabilities (push) Successful in 36s
CI / Tests (push) Successful in 1m34s
CI / Frontend lint & types (push) Successful in 1m41s
CI / Race detector (push) Failing after 3m30s
2026-06-25 19:39:09 +01:00
popertots 82e6f75354 ci: split govulncheck and frontend checks into parallel jobs
Lint & Vuln Scan / Go vulnerabilities (push) Successful in 22s
Lint & Vuln Scan / Frontend lint & types (push) Failing after 30s
2026-06-25 16:41:18 +01:00
popertots c481400215 ci: strip to lint/vulns only, fix Post-step node toolcache
Frontend Lint & Vulns / Lint & vulns (push) Successful in 1m19s
Remove test and race jobs until lint + vulns are fully green.
The node:22-alpine3.21 base image ships node at /usr/local/bin but
actions/setup-node expects it in the toolcache at /opt/hostedtoolcache.
Create a symlink so all Post-action cleanup steps (cache-save) find
node and don't exit 255.
2026-06-25 14:05:57 +01:00
popertots 3f0155597a ci: add CGO_ENABLED, build-base for race; auto-fix prettier before lint
Backend CI / Tests (push) Successful in 1m3s
Backend CI / Race detector (push) Successful in 1m47s
Backend CI / Lint & vulns (push) Failing after 3m21s
- Race job: install build-base (gcc) and set CGO_ENABLED=1 for Go's
  race detector on Alpine (requires cgo)
- Quality job: run npm run format (prettier --write) before lint to
  auto-fix formatting issues instead of failing CI for style nits
- Runner config on server updated to capacity: 8 (parallel jobs)
2026-06-25 13:15:15 +01:00
popertots a4a475a07d ci: fix quality job working-directory and adjust timeouts
Backend CI / Tests (push) Successful in 1m12s
Backend CI / Race detector (push) Failing after 21s
Backend CI / Lint & vulns (push) Failing after 27s
working-directory wasn't being honored for npm steps in the quality
job. Switch to explicit cd frontend && commands.

Reduce race timeout from 300s to 240s.
2026-06-25 13:03:50 +01:00
popertots aa875339b5 ci: add race detector, govulncheck, and frontend quality jobs
Backend CI / Tests (push) Successful in 59s
Backend CI / Race detector (push) Failing after 13s
Backend CI / Lint & vulns (push) Failing after 59s
Three parallel jobs:
- test: existing Go tests (unchanged)
- race: Go tests with -race flag (catches data races)
- quality: govulncheck + svelte-check + eslint/prettier (no PG needed)

Race job has its own PG service container so all three can run in parallel.
2026-06-25 12:57:15 +01:00
popertots 1b982b118b fix: use ./... in CI and restore local dev host connection
Backend Tests / test (push) Successful in 1m3s
CI test command: switch from explicit package list to ./... so new
packages are automatically included.

local-dev-2.sh: override POSTGRES_HOST=localhost for the host-side
go run -tags dev ./main.go. The dev-tagged Connect() now reads
POSTGRES_HOST from env (needed for CI where service containers use
Docker DNS). Locally, .env sets POSTGRES_HOST=postgres, but that
name only resolves inside Docker — not from the host where the dev
server runs. Override to localhost so it connects via Docker's port
forwarding.
2026-06-25 12:11:45 +01:00
popertots 3fd66d5414 ci: remove -a flag and debug log now fix is confirmed
Backend Tests / test (push) Successful in 1m0s
2026-06-25 12:04:56 +01:00
popertots 2db552db44 ci: add -a flag and debug print for savedPOSTGRESHost
Backend Tests / test (push) Successful in 1m33s
2026-06-25 11:52:22 +01:00
popertots 248756a1fe fix(db): prevent POSTGRES_HOST env var leakage between tests
Backend Tests / test (push) Successful in 59s
resetEnv() conditionally set POSTGRES_HOST only when empty. When
TestConnect_InvalidCredentials explicitly set it to 'localhost' and
then called resetEnv(), the value was preserved because it wasn't
empty. This leaked into TestConcurrentQueries, which then tried to
connect to localhost:5432 instead of the workflow-configured postgres
hostname.

Fix: capture the POSTGRES_HOST value at init() time in a package-level
variable (savedPOSTGRESHost) and always restore it in resetEnv(), so
the correct value is always used regardless of which tests ran before.
2026-06-25 01:21:15 +01:00
popertots b646497eb7 ci: add TEST_DB_HOST and debug echo to verify env propagation
Backend Tests / test (push) Failing after 59s
2026-06-25 01:17:25 +01:00
popertots 0ac69a92c7 fix(db): use POSTGRES_HOST env var in dev Connect()
Backend Tests / test (push) Failing after 49s
The dev-tagged Connect() in db_dev.go hardcoded localhost:5432 in the
DSN instead of reading the POSTGRES_HOST env var. Since CI tests run
with -tags "test,dev", db_dev.go is compiled and the POSTGRES_HOST=postgres
env var was silently ignored, causing db package tests to try connecting
to 127.0.0.1:5432 where no PostgreSQL is listening (service container
is only reachable via Docker DNS hostname postgres).

Also remove the -a flag from the workflow now that caching is no longer
suspected of causing issues.
2026-06-25 01:08:28 +01:00
popertots 30d4e75b16 ci: force full rebuild with -a flag
Backend Tests / test (push) Failing after 58s
2026-06-25 01:03:23 +01:00
popertots 3cb6a7f6ad ci: set POSTGRES_HOST directly in workflow
Backend Tests / test (push) Failing after 1m1s
2026-06-25 00:56:45 +01:00
popertots ca86e223c0 ci: add PGPASSWORD to create db step
Backend Tests / test (push) Failing after 53s
2026-06-25 00:54:17 +01:00
popertots 3aefc7ae43 ci: create crussell_test_db for db package tests
Backend Tests / test (push) Failing after 59s
2026-06-25 00:52:48 +01:00
popertots f3a41585d2 ci: add TEST_DB_HOST env var for service container connectivity
Backend Tests / test (push) Failing after 58s
2026-06-25 00:47:18 +01:00
popertots ab06c7e596 ci: use service name postgres for db host
Backend Tests / test (push) Failing after 51s
2026-06-25 00:43:22 +01:00
popertots 7624047a95 ci: use sh default shell for alpine runner
Backend Tests / test (push) Failing after 1m18s
2026-06-25 00:40:02 +01:00
popertots 2ecc9a798c ci: add bash to apk install for alpine runner
Backend Tests / test (push) Failing after 9s
2026-06-25 00:38:04 +01:00
popertots a27fc9205e ci: remove host port mapping from PG service container
Backend Tests / test (push) Failing after 9s
2026-06-25 00:33:46 +01:00
popertots 43ea0b2366 ci: fix yaml and disable setup-go cache
Backend Tests / test (push) Failing after 2s
2026-06-25 00:31:20 +01:00
popertots 69b3a179f4 ci: disable setup-go cache to prevent hanging 2026-06-25 00:29:46 +01:00
popertots 8b47234f3b chore: bump workflow description to trigger fresh run 2026-06-25 00:22:54 +01:00
popertots ae151cb197 ci: fix actions runtime - use node base image for JS action support
Backend Tests / test (push) Failing after 5m2s
2026-06-25 00:20:10 +01:00
popertots f9ebfe8a5d ci: switch runner to golang alpine image, drop apt for apk
Backend Tests / test (push) Failing after 4s
2026-06-25 00:15:45 +01:00
popertotsandSisyphus 32e47b06be chore: add .gitea and .sisyphus config directories
Backend Tests / test (push) Failing after 28s
Add Gitea CI configuration and Sisyphus workspace/plan files.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-06-24 23:44:14 +01:00