Repository navigation
ci: Publish prebuilt assets for Pilot - #604
Conversation
Build the app's assets in CI for each push and publish them on the release assets-<branch>, so Pilot benches download them instead of building on the server.
|
| jobs: | ||
| assets: | ||
| name: Pre-build assets | ||
| uses: frappe/pilot/.github/workflows/app-assets.yml@develop |
There was a problem hiding this comment.
Mutable workflow has write access The Pilot workflow is loaded from its
develop branch, so it can change without a Gameplan change. On the next Gameplan push, that code receives contents: write and could replace published assets or other repository contents. Pin it to a reviewed commit SHA. How this was verified: The called workflow uses a mutable external ref and receives the caller job’s write permission.
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/assets.yml
Line: 10
Comment:
**Mutable workflow has write access** The Pilot workflow is loaded from its `develop` branch, so it can change without a Gameplan change. On the next Gameplan push, that code receives `contents: write` and could replace published assets or other repository contents. Pin it to a reviewed commit SHA. **How this was verified:** The called workflow uses a mutable external ref and receives the caller job’s write permission.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
Test reportBackend ✅ 1280 passed · 7m 49s 50 modules
Coverage 90.3% (3,632 / 4,020 statements) Backend coverage by area
Least covered
Measured over product code only. Excluded: test suite ( Cypress ✅ 157 passed · 9m 38s 45 specs
Coverage 73.1% (6,343 / 8,677 statements) Frontend coverage by area
Least covered
Collected by Cypress against an istanbul-instrumented build, so it marks lines that ran, not lines a spec asserted on — read it to find untouched areas, not as a quality score against the backend number. Excluded: generated doctype types ( Updated for commit 73633ca. |
Summary
Build the Gameplan assets in CI and publish them on the release
assets-<branch>. Pilot benches download them and skip the asset build, the slowest and most memory-hungry step of an install or update.What changed
Pre-build assetsworkflow for pushes todevelop.See Prebuilt Assets.