Compare commits

...

5 Commits

Author SHA1 Message Date
Arunavo Ray
9d37966c10 ci: only run nix flake check when nix files change 2026-03-06 09:03:32 +05:30
Arunavo Ray
ac16ae56ea ci: increase workflow timeouts to 25m and upgrade CodeQL Action to v4 2026-03-06 08:55:11 +05:30
Arunavo Ray
df3e665978 fix: bump Bun to 1.3.10 and harden startup for non-AVX CPUs (#213)
Bun 1.3.9 crashes with a segfault on CPUs without AVX support due to a
WASM IPInt bug (oven-sh/bun#27340), fixed in 1.3.10 via oven-sh/bun#26922.

- Bump Bun from 1.3.9 to 1.3.10 in Dockerfile, CI workflows, and packageManager
- Skip env config script when no GitHub/Gitea env vars are set
- Make startup scripts (env-config, recovery, repair) fault-tolerant so
  a crash in a non-critical script doesn't abort the entrypoint via set -e
2026-03-06 08:19:44 +05:30
github-actions[bot]
8a26764d2c chore: sync version to 3.12.2 2026-03-05 04:34:51 +00:00
ARUNAVO RAY
ce365a706e ci: persist release version to main (#212) 2026-03-05 09:55:59 +05:30
10 changed files with 94 additions and 42 deletions

View File

@@ -45,6 +45,7 @@ This workflow builds Docker images on pushes and pull requests, and pushes to Gi
- Creates multiple tags for each image (latest, semver, sha) - Creates multiple tags for each image (latest, semver, sha)
- Auto-syncs `package.json` version from `v*` tags during release builds - Auto-syncs `package.json` version from `v*` tags during release builds
- Validates release tags use semver format before building - Validates release tags use semver format before building
- After tag builds succeed, writes the same version back to `main/package.json`
### Docker Security Scan (`docker-scan.yml`) ### Docker Security Scan (`docker-scan.yml`)

View File

@@ -24,7 +24,7 @@ jobs:
build-and-test: build-and-test:
name: Build and Test Astro Project name: Build and Test Astro Project
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 25
steps: steps:
- name: Checkout repository - name: Checkout repository
@@ -33,7 +33,7 @@ jobs:
- name: Setup Bun - name: Setup Bun
uses: oven-sh/setup-bun@v1 uses: oven-sh/setup-bun@v1
with: with:
bun-version: '1.3.6' bun-version: '1.3.10'
- name: Check lockfile and install dependencies - name: Check lockfile and install dependencies
run: | run: |

View File

@@ -36,7 +36,7 @@ env:
jobs: jobs:
docker: docker:
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 25
permissions: permissions:
contents: write contents: write
@@ -253,8 +253,49 @@ jobs:
# Upload security scan results to GitHub Security tab # Upload security scan results to GitHub Security tab
- name: Upload Docker Scout scan results to GitHub Security tab - name: Upload Docker Scout scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v3 uses: github/codeql-action/upload-sarif@v4
if: always() if: always()
continue-on-error: true continue-on-error: true
with: with:
sarif_file: scout-results.sarif sarif_file: scout-results.sarif
sync-version-main:
name: Sync package.json version back to main
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
needs: docker
permissions:
contents: write
steps:
- name: Checkout default branch
uses: actions/checkout@v4
with:
ref: ${{ github.event.repository.default_branch }}
- name: Update package.json version on main
env:
TAG_VERSION: ${{ github.ref_name }}
TARGET_BRANCH: ${{ github.event.repository.default_branch }}
run: |
if [[ ! "$TAG_VERSION" =~ ^v[0-9]+\.[0-9]+\.[0-9]+([.-][0-9A-Za-z.-]+)?(\+[0-9A-Za-z.-]+)?$ ]]; then
echo "::error::Release tag '${TAG_VERSION}' is invalid. Expected semver tag format like v1.2.3 or v1.2.3-rc.1"
exit 1
fi
APP_VERSION="${TAG_VERSION#v}"
echo "Syncing ${TARGET_BRANCH}/package.json to ${APP_VERSION}"
jq --arg version "${APP_VERSION}" '.version = $version' package.json > package.json.tmp
mv package.json.tmp package.json
if git diff --quiet -- package.json; then
echo "package.json on ${TARGET_BRANCH} already at ${APP_VERSION}; nothing to commit."
exit 0
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add package.json
git commit -m "chore: sync version to ${APP_VERSION}"
git push origin "HEAD:${TARGET_BRANCH}"

View File

@@ -40,13 +40,13 @@ env:
FAKE_GITHUB_PORT: 4580 FAKE_GITHUB_PORT: 4580
GIT_SERVER_PORT: 4590 GIT_SERVER_PORT: 4590
APP_PORT: 4321 APP_PORT: 4321
BUN_VERSION: "1.3.6" BUN_VERSION: "1.3.10"
jobs: jobs:
e2e-tests: e2e-tests:
name: E2E Integration Tests name: E2E Integration Tests
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 25
steps: steps:
- name: Checkout repository - name: Checkout repository

View File

@@ -21,7 +21,7 @@ jobs:
yamllint: yamllint:
name: Lint YAML name: Lint YAML
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 25
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- uses: actions/setup-python@v5 - uses: actions/setup-python@v5
@@ -36,7 +36,7 @@ jobs:
helm-template: helm-template:
name: Helm lint & template name: Helm lint & template
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 25
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Setup Helm - name: Setup Helm

View File

@@ -5,18 +5,18 @@ on:
branches: [main, nix] branches: [main, nix]
tags: tags:
- 'v*' - 'v*'
paths-ignore: paths:
- 'README.md' - 'flake.nix'
- 'docs/**' - 'flake.lock'
- 'www/**' - 'bun.nix'
- 'helm/**' - '.github/workflows/nix-build.yml'
pull_request: pull_request:
branches: [main] branches: [main]
paths-ignore: paths:
- 'README.md' - 'flake.nix'
- 'docs/**' - 'flake.lock'
- 'www/**' - 'bun.nix'
- 'helm/**' - '.github/workflows/nix-build.yml'
permissions: permissions:
contents: read contents: read
@@ -24,7 +24,7 @@ permissions:
jobs: jobs:
check: check:
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 10 timeout-minutes: 25
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4

View File

@@ -1,6 +1,6 @@
# syntax=docker/dockerfile:1.4 # syntax=docker/dockerfile:1.4
FROM oven/bun:1.3.9-debian AS base FROM oven/bun:1.3.10-debian AS base
WORKDIR /app WORKDIR /app
RUN apt-get update && apt-get install -y --no-install-recommends \ RUN apt-get update && apt-get install -y --no-install-recommends \
python3 make g++ gcc wget sqlite3 openssl ca-certificates \ python3 make g++ gcc wget sqlite3 openssl ca-certificates \
@@ -26,7 +26,7 @@ COPY bun.lock* ./
RUN bun install --production --omit=peer --frozen-lockfile RUN bun install --production --omit=peer --frozen-lockfile
# ---------------------------- # ----------------------------
FROM oven/bun:1.3.9-debian AS runner FROM oven/bun:1.3.10-debian AS runner
WORKDIR /app WORKDIR /app
RUN apt-get update && apt-get install -y --no-install-recommends \ RUN apt-get update && apt-get install -y --no-install-recommends \
git git-lfs wget sqlite3 openssl ca-certificates \ git git-lfs wget sqlite3 openssl ca-certificates \

View File

@@ -139,16 +139,29 @@ fi
# Initialize configuration from environment variables if provided # Initialize configuration from environment variables if provided
echo "Checking for environment configuration..." echo "Checking for environment configuration..."
if [ -f "dist/scripts/startup-env-config.js" ]; then
echo "Loading configuration from environment variables..." # Only run the env config script if relevant env vars are set
bun dist/scripts/startup-env-config.js # This avoids spawning a heavy Bun process on memory-constrained systems
ENV_CONFIG_EXIT_CODE=$? HAS_ENV_CONFIG=false
elif [ -f "scripts/startup-env-config.ts" ]; then if [ -n "$GITHUB_USERNAME" ] || [ -n "$GITHUB_TOKEN" ] || [ -n "$GITEA_URL" ] || [ -n "$GITEA_USERNAME" ] || [ -n "$GITEA_TOKEN" ]; then
echo "Loading configuration from environment variables..." HAS_ENV_CONFIG=true
bun scripts/startup-env-config.ts fi
ENV_CONFIG_EXIT_CODE=$?
if [ "$HAS_ENV_CONFIG" = "true" ]; then
if [ -f "dist/scripts/startup-env-config.js" ]; then
echo "Loading configuration from environment variables..."
bun dist/scripts/startup-env-config.js || ENV_CONFIG_EXIT_CODE=$?
ENV_CONFIG_EXIT_CODE=${ENV_CONFIG_EXIT_CODE:-0}
elif [ -f "scripts/startup-env-config.ts" ]; then
echo "Loading configuration from environment variables..."
bun scripts/startup-env-config.ts || ENV_CONFIG_EXIT_CODE=$?
ENV_CONFIG_EXIT_CODE=${ENV_CONFIG_EXIT_CODE:-0}
else
echo "Environment configuration script not found. Skipping."
ENV_CONFIG_EXIT_CODE=0
fi
else else
echo "Environment configuration script not found. Skipping." echo "No GitHub/Gitea environment variables found, skipping env config initialization."
ENV_CONFIG_EXIT_CODE=0 ENV_CONFIG_EXIT_CODE=0
fi fi
@@ -161,17 +174,15 @@ fi
# Run startup recovery to handle any interrupted jobs # Run startup recovery to handle any interrupted jobs
echo "Running startup recovery..." echo "Running startup recovery..."
RECOVERY_EXIT_CODE=0
if [ -f "dist/scripts/startup-recovery.js" ]; then if [ -f "dist/scripts/startup-recovery.js" ]; then
echo "Running startup recovery using compiled script..." echo "Running startup recovery using compiled script..."
bun dist/scripts/startup-recovery.js --timeout=30000 bun dist/scripts/startup-recovery.js --timeout=30000 || RECOVERY_EXIT_CODE=$?
RECOVERY_EXIT_CODE=$?
elif [ -f "scripts/startup-recovery.ts" ]; then elif [ -f "scripts/startup-recovery.ts" ]; then
echo "Running startup recovery using TypeScript script..." echo "Running startup recovery using TypeScript script..."
bun scripts/startup-recovery.ts --timeout=30000 bun scripts/startup-recovery.ts --timeout=30000 || RECOVERY_EXIT_CODE=$?
RECOVERY_EXIT_CODE=$?
else else
echo "Warning: Startup recovery script not found. Skipping recovery." echo "Warning: Startup recovery script not found. Skipping recovery."
RECOVERY_EXIT_CODE=0
fi fi
# Log recovery result # Log recovery result
@@ -185,17 +196,15 @@ fi
# Run repository status repair to fix any inconsistent mirroring states # Run repository status repair to fix any inconsistent mirroring states
echo "Running repository status repair..." echo "Running repository status repair..."
REPAIR_EXIT_CODE=0
if [ -f "dist/scripts/repair-mirrored-repos.js" ]; then if [ -f "dist/scripts/repair-mirrored-repos.js" ]; then
echo "Running repository repair using compiled script..." echo "Running repository repair using compiled script..."
bun dist/scripts/repair-mirrored-repos.js --startup bun dist/scripts/repair-mirrored-repos.js --startup || REPAIR_EXIT_CODE=$?
REPAIR_EXIT_CODE=$?
elif [ -f "scripts/repair-mirrored-repos.ts" ]; then elif [ -f "scripts/repair-mirrored-repos.ts" ]; then
echo "Running repository repair using TypeScript script..." echo "Running repository repair using TypeScript script..."
bun scripts/repair-mirrored-repos.ts --startup bun scripts/repair-mirrored-repos.ts --startup || REPAIR_EXIT_CODE=$?
REPAIR_EXIT_CODE=$?
else else
echo "Warning: Repository repair script not found. Skipping repair." echo "Warning: Repository repair script not found. Skipping repair."
REPAIR_EXIT_CODE=0
fi fi
# Log repair result # Log repair result

View File

@@ -328,6 +328,7 @@ git push origin vX.Y.Z
5. **CI version sync (automatic)**: 5. **CI version sync (automatic)**:
- On `v*` tags, release CI updates `package.json` version in the build context from the tag (`vX.Y.Z` -> `X.Y.Z`), so Docker release images always report the correct app version. - On `v*` tags, release CI updates `package.json` version in the build context from the tag (`vX.Y.Z` -> `X.Y.Z`), so Docker release images always report the correct app version.
- After the release build succeeds, CI commits the same `package.json` version back to `main` automatically.
## Contributing ## Contributing

View File

@@ -1,7 +1,7 @@
{ {
"name": "gitea-mirror", "name": "gitea-mirror",
"type": "module", "type": "module",
"version": "3.10.1", "version": "3.12.2",
"engines": { "engines": {
"bun": ">=1.2.9" "bun": ">=1.2.9"
}, },
@@ -119,5 +119,5 @@
"tsx": "^4.21.0", "tsx": "^4.21.0",
"vitest": "^4.0.18" "vitest": "^4.0.18"
}, },
"packageManager": "bun@1.3.3" "packageManager": "bun@1.3.10"
} }