Repository navigation
Merge pull request #32 from soulteary/release/prepare-2026.08.31-r2 #53
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| push: | |
| branches: | |
| - main | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| validate: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| image_changed: ${{ steps.changes.outputs.image_changed }} | |
| release_version: ${{ steps.release.outputs.release_version }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Install ShellCheck | |
| env: | |
| SHELLCHECK_VERSION: 0.11.0 | |
| SHELLCHECK_SHA256: 8c3be12b05d5c177a04c29e3c78ce89ac86f1595681cab149b65b97c4e227198 | |
| run: | | |
| set -euo pipefail | |
| archive="/tmp/shellcheck.tar.xz" | |
| curl --location --proto '=https' --tlsv1.2 --retry 3 --fail --silent --show-error \ | |
| -o "${archive}" \ | |
| "https://github.com/koalaman/shellcheck/releases/download/v${SHELLCHECK_VERSION}/shellcheck-v${SHELLCHECK_VERSION}.linux.x86_64.tar.xz" | |
| echo "${SHELLCHECK_SHA256} ${archive}" | sha256sum -c - | |
| tar --no-same-owner -xJf "${archive}" -C /tmp | |
| echo "/tmp/shellcheck-v${SHELLCHECK_VERSION}" >> "${GITHUB_PATH}" | |
| - name: Detect image changes | |
| id: changes | |
| env: | |
| EVENT_NAME: ${{ github.event_name }} | |
| BASE_SHA: ${{ github.event.pull_request.base.sha || github.event.before }} | |
| HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }} | |
| run: | | |
| set -euo pipefail | |
| image_changed=true | |
| if [[ "${EVENT_NAME}" != "workflow_dispatch" ]] \ | |
| && [[ -n "${BASE_SHA}" ]] \ | |
| && [[ ! "${BASE_SHA}" =~ ^0+$ ]] \ | |
| && git cat-file -e "${BASE_SHA}^{commit}" \ | |
| && git diff --quiet "${BASE_SHA}" "${HEAD_SHA}" -- \ | |
| .github/workflows/ci.yaml \ | |
| .dockerignore \ | |
| Dockerfile \ | |
| docker-entrypoint-sqlite.sh \ | |
| scripts/validate-release.sh \ | |
| sqlite-database-integration-loader.php \ | |
| sqlite-diagnostics.php \ | |
| sqlite-local-core-update.php \ | |
| sqlite-select-id-key-fix.php \ | |
| tool-update-site-url.php \ | |
| tests/image-smoke.sh \ | |
| tests/image-smoke-site-url.php; then | |
| image_changed=false | |
| fi | |
| echo "image_changed=${image_changed}" >> "${GITHUB_OUTPUT}" | |
| - name: Validate release consistency | |
| id: release | |
| run: | | |
| set -euo pipefail | |
| release_version="$(sed -nE 's/^ARG IMAGE_VERSION=([^[:space:]]+)$/\1/p' Dockerfile)" | |
| if [[ -z "${release_version}" ]]; then | |
| echo "Expected IMAGE_VERSION in Dockerfile." >&2 | |
| exit 1 | |
| fi | |
| ./scripts/validate-release.sh "${release_version}" | |
| echo "release_version=${release_version}" >> "${GITHUB_OUTPUT}" | |
| - name: Lint shell scripts | |
| run: | | |
| set -euo pipefail | |
| mapfile -d '' shell_files < <(find . -type f -name '*.sh' -print0) | |
| shellcheck "${shell_files[@]}" | |
| - name: Lint PHP files | |
| run: | | |
| set -euo pipefail | |
| while IFS= read -r -d '' php_file; do | |
| php -l "${php_file}" | |
| done < <(find . -type f -name '*.php' -print0) | |
| - name: Run repository tests | |
| run: | | |
| set -euo pipefail | |
| while IFS= read -r -d '' shell_test; do | |
| bash "${shell_test}" | |
| done < <(find tests -maxdepth 1 -type f -name 'test-*.sh' -print0 2>/dev/null || true) | |
| while IFS= read -r -d '' php_test; do | |
| php "${php_test}" | |
| done < <(find tests -maxdepth 1 -type f -name 'test-*.php' -print0 2>/dev/null || true) | |
| - name: Install and run actionlint | |
| env: | |
| ACTIONLINT_VERSION: 1.7.12 | |
| ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 | |
| run: | | |
| set -euo pipefail | |
| archive="/tmp/actionlint.tar.gz" | |
| curl --location --proto '=https' --tlsv1.2 --retry 3 --fail --silent --show-error \ | |
| -o "${archive}" \ | |
| "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" | |
| echo "${ACTIONLINT_SHA256} ${archive}" | sha256sum -c - | |
| tar --no-same-owner -xzf "${archive}" -C /tmp actionlint | |
| /tmp/actionlint | |
| image-smoke: | |
| needs: validate | |
| if: needs.validate.outputs.image_changed == 'true' | |
| runs-on: ${{ matrix.runner }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - name: amd64-native | |
| runner: ubuntu-24.04 | |
| platform: linux/amd64 | |
| parser_mode: native | |
| debian_arch: amd64 | |
| qemu: false | |
| - name: arm64-native | |
| runner: ubuntu-24.04-arm | |
| platform: linux/arm64 | |
| parser_mode: native | |
| debian_arch: arm64 | |
| qemu: false | |
| - name: armv7-fallback | |
| runner: ubuntu-24.04-arm | |
| platform: linux/arm/v7 | |
| parser_mode: fallback | |
| debian_arch: armhf | |
| qemu: true | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Verify pinned WordPress base image | |
| run: ./scripts/validate-release.sh "${{ needs.validate.outputs.release_version }}" --verify-upstream | |
| - name: Set up QEMU | |
| if: ${{ matrix.qemu }} | |
| uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 | |
| - name: Build ${{ matrix.name }} image | |
| uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 | |
| with: | |
| context: . | |
| platforms: ${{ matrix.platform }} | |
| load: true | |
| tags: sqlite-wordpress:test | |
| provenance: false | |
| sbom: false | |
| cache-from: type=gha,scope=ci-${{ matrix.name }} | |
| cache-to: type=gha,mode=max,scope=ci-${{ matrix.name }} | |
| - name: Verify packaged runtime | |
| run: >- | |
| ./tests/image-smoke.sh | |
| sqlite-wordpress:test | |
| ${{ matrix.platform }} | |
| ${{ matrix.parser_mode }} | |
| ${{ matrix.debian_arch }} |