Skip to content

Merge pull request #32 from soulteary/release/prepare-2026.08.31-r2 #53

Merge pull request #32 from soulteary/release/prepare-2026.08.31-r2

Merge pull request #32 from soulteary/release/prepare-2026.08.31-r2 #53

Workflow file for this run

name: CI
on:
pull_request:
push:
branches:
- main
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
validate:
runs-on: ubuntu-latest
outputs:
image_changed: ${{ steps.changes.outputs.image_changed }}
release_version: ${{ steps.release.outputs.release_version }}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Install ShellCheck
env:
SHELLCHECK_VERSION: 0.11.0
SHELLCHECK_SHA256: 8c3be12b05d5c177a04c29e3c78ce89ac86f1595681cab149b65b97c4e227198
run: |
set -euo pipefail
archive="/tmp/shellcheck.tar.xz"
curl --location --proto '=https' --tlsv1.2 --retry 3 --fail --silent --show-error \
-o "${archive}" \
"https://github.com/koalaman/shellcheck/releases/download/v${SHELLCHECK_VERSION}/shellcheck-v${SHELLCHECK_VERSION}.linux.x86_64.tar.xz"
echo "${SHELLCHECK_SHA256} ${archive}" | sha256sum -c -
tar --no-same-owner -xJf "${archive}" -C /tmp
echo "/tmp/shellcheck-v${SHELLCHECK_VERSION}" >> "${GITHUB_PATH}"
- name: Detect image changes
id: changes
env:
EVENT_NAME: ${{ github.event_name }}
BASE_SHA: ${{ github.event.pull_request.base.sha || github.event.before }}
HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: |
set -euo pipefail
image_changed=true
if [[ "${EVENT_NAME}" != "workflow_dispatch" ]] \
&& [[ -n "${BASE_SHA}" ]] \
&& [[ ! "${BASE_SHA}" =~ ^0+$ ]] \
&& git cat-file -e "${BASE_SHA}^{commit}" \
&& git diff --quiet "${BASE_SHA}" "${HEAD_SHA}" -- \
.github/workflows/ci.yaml \
.dockerignore \
Dockerfile \
docker-entrypoint-sqlite.sh \
scripts/validate-release.sh \
sqlite-database-integration-loader.php \
sqlite-diagnostics.php \
sqlite-local-core-update.php \
sqlite-select-id-key-fix.php \
tool-update-site-url.php \
tests/image-smoke.sh \
tests/image-smoke-site-url.php; then
image_changed=false
fi
echo "image_changed=${image_changed}" >> "${GITHUB_OUTPUT}"
- name: Validate release consistency
id: release
run: |
set -euo pipefail
release_version="$(sed -nE 's/^ARG IMAGE_VERSION=([^[:space:]]+)$/\1/p' Dockerfile)"
if [[ -z "${release_version}" ]]; then
echo "Expected IMAGE_VERSION in Dockerfile." >&2
exit 1
fi
./scripts/validate-release.sh "${release_version}"
echo "release_version=${release_version}" >> "${GITHUB_OUTPUT}"
- name: Lint shell scripts
run: |
set -euo pipefail
mapfile -d '' shell_files < <(find . -type f -name '*.sh' -print0)
shellcheck "${shell_files[@]}"
- name: Lint PHP files
run: |
set -euo pipefail
while IFS= read -r -d '' php_file; do
php -l "${php_file}"
done < <(find . -type f -name '*.php' -print0)
- name: Run repository tests
run: |
set -euo pipefail
while IFS= read -r -d '' shell_test; do
bash "${shell_test}"
done < <(find tests -maxdepth 1 -type f -name 'test-*.sh' -print0 2>/dev/null || true)
while IFS= read -r -d '' php_test; do
php "${php_test}"
done < <(find tests -maxdepth 1 -type f -name 'test-*.php' -print0 2>/dev/null || true)
- name: Install and run actionlint
env:
ACTIONLINT_VERSION: 1.7.12
ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8
run: |
set -euo pipefail
archive="/tmp/actionlint.tar.gz"
curl --location --proto '=https' --tlsv1.2 --retry 3 --fail --silent --show-error \
-o "${archive}" \
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
echo "${ACTIONLINT_SHA256} ${archive}" | sha256sum -c -
tar --no-same-owner -xzf "${archive}" -C /tmp actionlint
/tmp/actionlint
image-smoke:
needs: validate
if: needs.validate.outputs.image_changed == 'true'
runs-on: ${{ matrix.runner }}
strategy:
fail-fast: false
matrix:
include:
- name: amd64-native
runner: ubuntu-24.04
platform: linux/amd64
parser_mode: native
debian_arch: amd64
qemu: false
- name: arm64-native
runner: ubuntu-24.04-arm
platform: linux/arm64
parser_mode: native
debian_arch: arm64
qemu: false
- name: armv7-fallback
runner: ubuntu-24.04-arm
platform: linux/arm/v7
parser_mode: fallback
debian_arch: armhf
qemu: true
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Verify pinned WordPress base image
run: ./scripts/validate-release.sh "${{ needs.validate.outputs.release_version }}" --verify-upstream
- name: Set up QEMU
if: ${{ matrix.qemu }}
uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Build ${{ matrix.name }} image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
platforms: ${{ matrix.platform }}
load: true
tags: sqlite-wordpress:test
provenance: false
sbom: false
cache-from: type=gha,scope=ci-${{ matrix.name }}
cache-to: type=gha,mode=max,scope=ci-${{ matrix.name }}
- name: Verify packaged runtime
run: >-
./tests/image-smoke.sh
sqlite-wordpress:test
${{ matrix.platform }}
${{ matrix.parser_mode }}
${{ matrix.debian_arch }}