diff --git a/.gitea/workflows/ci-cd.yml b/.gitea/workflows/ci-cd.yml deleted file mode 100644 index 32dd0c8..0000000 --- a/.gitea/workflows/ci-cd.yml +++ /dev/null @@ -1,195 +0,0 @@ -name: CI/CD Pipeline - -on: - push: - branches: - - main - - develop - pull_request: - branches: - - main - - develop - -env: - DOCKER_REGISTRY: docker.io - IMAGE_NAME: basil - -jobs: - test: - name: Run Tests - runs-on: ubuntu-latest - - services: - postgres: - image: postgres:16-alpine - env: - POSTGRES_USER: basil - POSTGRES_PASSWORD: basil - POSTGRES_DB: basil_test - ports: - - 5432:5432 - options: >- - --health-cmd pg_isready - --health-interval 10s - --health-timeout 5s - --health-retries 5 - - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm install - - - name: Build shared package - run: | - cd packages/shared - npm run build - - - name: Generate Prisma Client - run: | - cd packages/api - npm run prisma:generate - - - name: Run database migrations - run: | - cd packages/api - npm run prisma:migrate - env: - DATABASE_URL: postgresql://basil:basil@localhost:5432/basil_test?schema=public - - - name: Run unit tests - API - run: | - cd packages/api - npm run test - env: - DATABASE_URL: postgresql://basil:basil@localhost:5432/basil_test?schema=public - NODE_ENV: test - - - name: Run unit tests - Web - run: | - cd packages/web - npm run test - - - name: Run unit tests - Shared - run: | - cd packages/shared - npm run test - - - name: Install Playwright browsers - run: npx playwright install --with-deps - - - name: Build application for E2E tests - run: npm run build - - - name: Run E2E tests - run: npm run test:e2e - env: - DATABASE_URL: postgresql://basil:basil@localhost:5432/basil_test?schema=public - - - name: Upload test results - if: always() - uses: actions/upload-artifact@v4 - with: - name: test-results - path: | - packages/*/coverage/ - playwright-report/ - retention-days: 30 - - build-and-push: - name: Build and Push Docker Images - runs-on: ubuntu-latest - needs: test - if: github.event_name == 'push' && github.ref == 'refs/heads/main' - - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - - name: Log in to Docker Registry - uses: docker/login-action@v3 - with: - registry: ${{ env.DOCKER_REGISTRY }} - username: ${{ secrets.DOCKER_USERNAME }} - password: ${{ secrets.DOCKER_PASSWORD }} - - - name: Extract metadata for API - id: meta-api - uses: docker/metadata-action@v5 - with: - images: ${{ env.DOCKER_REGISTRY }}/${{ secrets.DOCKER_USERNAME }}/${{ env.IMAGE_NAME }}-api - tags: | - type=sha,prefix={{branch}}- - type=raw,value=latest,enable={{is_default_branch}} - type=semver,pattern={{version}} - type=semver,pattern={{major}}.{{minor}} - - - name: Extract metadata for Web - id: meta-web - uses: docker/metadata-action@v5 - with: - images: ${{ env.DOCKER_REGISTRY }}/${{ secrets.DOCKER_USERNAME }}/${{ env.IMAGE_NAME }}-web - tags: | - type=sha,prefix={{branch}}- - type=raw,value=latest,enable={{is_default_branch}} - type=semver,pattern={{version}} - type=semver,pattern={{major}}.{{minor}} - - - name: Build and push API image - uses: docker/build-push-action@v5 - with: - context: . - file: packages/api/Dockerfile - push: true - tags: ${{ steps.meta-api.outputs.tags }} - labels: ${{ steps.meta-api.outputs.labels }} - cache-from: type=gha - cache-to: type=gha,mode=max - - - name: Build and push Web image - uses: docker/build-push-action@v5 - with: - context: . - file: packages/web/Dockerfile - push: true - tags: ${{ steps.meta-web.outputs.tags }} - labels: ${{ steps.meta-web.outputs.labels }} - cache-from: type=gha - cache-to: type=gha,mode=max - - - name: Trigger deployment webhook - if: success() - run: | - curl -X POST ${{ secrets.DEPLOY_WEBHOOK_URL }} \ - -H "Content-Type: application/json" \ - -d '{"branch": "main", "commit": "${{ github.sha }}", "message": "${{ github.event.head_commit.message }}"}' - - lint: - name: Code Quality - runs-on: ubuntu-latest - - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm install - - - name: Run linter - run: npm run lint diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml deleted file mode 100644 index 9cfd701..0000000 --- a/.gitea/workflows/ci.yml +++ /dev/null @@ -1,183 +0,0 @@ -name: CI Pipeline - -on: - push: - branches: [ main, master, develop ] - pull_request: - branches: [ main, master, develop ] - -jobs: - lint: - name: Lint Code - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Run linters - run: npm run lint - - test-api: - name: Test API Package - runs-on: ubuntu-latest - services: - postgres: - image: postgres:16 - env: - POSTGRES_USER: basil - POSTGRES_PASSWORD: basil - POSTGRES_DB: basil_test - options: >- - --health-cmd pg_isready - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 5432:5432 - - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Run API tests - working-directory: packages/api - env: - DATABASE_URL: postgresql://basil:basil@localhost:5432/basil_test - NODE_ENV: test - run: npm run test - - - name: Upload API test coverage - uses: actions/upload-artifact@v4 - if: always() - with: - name: api-coverage - path: packages/api/coverage/ - retention-days: 7 - - test-web: - name: Test Web Package - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Run web tests - working-directory: packages/web - run: npm run test - - - name: Upload web test coverage - uses: actions/upload-artifact@v4 - if: always() - with: - name: web-coverage - path: packages/web/coverage/ - retention-days: 7 - - test-shared: - name: Test Shared Package - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Run shared package tests - working-directory: packages/shared - run: npm run test - - - name: Upload shared test coverage - uses: actions/upload-artifact@v4 - if: always() - with: - name: shared-coverage - path: packages/shared/coverage/ - retention-days: 7 - - build: - name: Build All Packages - runs-on: ubuntu-latest - needs: [lint, test-api, test-web, test-shared] - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Build all packages - run: npm run build - - - name: Upload build artifacts - uses: actions/upload-artifact@v4 - with: - name: build-artifacts - path: | - packages/api/dist/ - packages/web/dist/ - packages/shared/dist/ - retention-days: 7 - - coverage-report: - name: Generate Coverage Report - runs-on: ubuntu-latest - needs: [test-api, test-web, test-shared] - if: always() - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Download all coverage artifacts - uses: actions/download-artifact@v4 - with: - path: coverage-artifacts - - - name: Display coverage summary - run: | - echo "## Test Coverage Summary" >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "Coverage reports have been generated for all packages." >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "- API Package Coverage" >> $GITHUB_STEP_SUMMARY - echo "- Web Package Coverage" >> $GITHUB_STEP_SUMMARY - echo "- Shared Package Coverage" >> $GITHUB_STEP_SUMMARY diff --git a/.gitea/workflows/docker.yml b/.gitea/workflows/docker.yml deleted file mode 100644 index 1f75cdd..0000000 --- a/.gitea/workflows/docker.yml +++ /dev/null @@ -1,146 +0,0 @@ -name: Docker Build & Deploy - -on: - push: - branches: [ main, master ] - tags: - - 'v*' - pull_request: - branches: [ main, master ] - -jobs: - build-and-test: - name: Build Docker Images - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - - name: Build API image - uses: docker/build-push-action@v5 - with: - context: . - file: ./packages/api/Dockerfile - push: false - tags: basil-api:test - cache-from: type=gha - cache-to: type=gha,mode=max - - - name: Build Web image - uses: docker/build-push-action@v5 - with: - context: . - file: ./packages/web/Dockerfile - push: false - tags: basil-web:test - cache-from: type=gha - cache-to: type=gha,mode=max - - - name: Test Docker Compose - run: | - docker-compose -f docker-compose.yml config - echo "✅ Docker Compose configuration is valid" - - push-images: - name: Push Docker Images - runs-on: ubuntu-latest - needs: build-and-test - if: github.event_name == 'push' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/master' || startsWith(github.ref, 'refs/tags/v')) - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - - name: Login to Container Registry - uses: docker/login-action@v3 - with: - registry: ${{ secrets.DOCKER_REGISTRY }} - username: ${{ secrets.DOCKER_USERNAME }} - password: ${{ secrets.DOCKER_PASSWORD }} - - - name: Extract metadata - id: meta - run: | - if [[ $GITHUB_REF == refs/tags/* ]]; then - VERSION=${GITHUB_REF#refs/tags/} - else - VERSION=latest - fi - echo "version=$VERSION" >> $GITHUB_OUTPUT - echo "date=$(date -u +'%Y-%m-%dT%H:%M:%SZ')" >> $GITHUB_OUTPUT - - - name: Build and push API image - uses: docker/build-push-action@v5 - with: - context: . - file: ./packages/api/Dockerfile - push: true - tags: | - ${{ secrets.DOCKER_REGISTRY }}/basil-api:${{ steps.meta.outputs.version }} - ${{ secrets.DOCKER_REGISTRY }}/basil-api:latest - labels: | - org.opencontainers.image.created=${{ steps.meta.outputs.date }} - org.opencontainers.image.version=${{ steps.meta.outputs.version }} - cache-from: type=gha - cache-to: type=gha,mode=max - - - name: Build and push Web image - uses: docker/build-push-action@v5 - with: - context: . - file: ./packages/web/Dockerfile - push: true - tags: | - ${{ secrets.DOCKER_REGISTRY }}/basil-web:${{ steps.meta.outputs.version }} - ${{ secrets.DOCKER_REGISTRY }}/basil-web:latest - labels: | - org.opencontainers.image.created=${{ steps.meta.outputs.date }} - org.opencontainers.image.version=${{ steps.meta.outputs.version }} - cache-from: type=gha - cache-to: type=gha,mode=max - - - name: Image digest - run: echo "Images have been built and pushed successfully" - - deploy-staging: - name: Deploy to Staging - runs-on: ubuntu-latest - needs: push-images - if: github.ref == 'refs/heads/develop' - environment: - name: staging - url: https://staging.basil.example.com - steps: - - name: Deploy to staging - run: | - echo "Deploying to staging environment..." - echo "This is a placeholder for actual deployment steps." - echo "Examples: SSH to server, run docker-compose pull, restart services, etc." - - deploy-production: - name: Deploy to Production - runs-on: ubuntu-latest - needs: push-images - if: startsWith(github.ref, 'refs/tags/v') - environment: - name: production - url: https://basil.example.com - steps: - - name: Deploy to production - run: | - echo "Deploying to production environment..." - echo "This is a placeholder for actual deployment steps." - echo "Examples: SSH to server, run docker-compose pull, restart services, etc." - - - name: Create deployment summary - run: | - echo "# 🚀 Deployment Summary" >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "**Version**: ${{ github.ref_name }}" >> $GITHUB_STEP_SUMMARY - echo "**Environment**: Production" >> $GITHUB_STEP_SUMMARY - echo "**Status**: Deployed Successfully ✅" >> $GITHUB_STEP_SUMMARY diff --git a/.gitea/workflows/e2e.yml b/.gitea/workflows/e2e.yml deleted file mode 100644 index 8ec80aa..0000000 --- a/.gitea/workflows/e2e.yml +++ /dev/null @@ -1,148 +0,0 @@ -name: E2E Tests - -on: - push: - branches: [ main, master ] - pull_request: - branches: [ main, master ] - schedule: - # Run E2E tests nightly at 2 AM UTC - - cron: '0 2 * * *' - -jobs: - e2e-tests: - name: End-to-End Tests - runs-on: ubuntu-latest - timeout-minutes: 30 - services: - postgres: - image: postgres:16 - env: - POSTGRES_USER: basil - POSTGRES_PASSWORD: basil - POSTGRES_DB: basil - options: >- - --health-cmd pg_isready - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 5432:5432 - - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Install Playwright browsers - run: npx playwright install --with-deps - - - name: Build packages - run: npm run build - - - name: Run database migrations - working-directory: packages/api - env: - DATABASE_URL: postgresql://basil:basil@localhost:5432/basil - run: npm run prisma:migrate - - - name: Start application - env: - DATABASE_URL: postgresql://basil:basil@localhost:5432/basil - PORT: 3001 - NODE_ENV: test - run: | - npm run dev & - sleep 10 - - - name: Run E2E tests - run: npm run test:e2e - - - name: Upload Playwright report - uses: actions/upload-artifact@v4 - if: always() - with: - name: playwright-report - path: playwright-report/ - retention-days: 14 - - - name: Upload test results - uses: actions/upload-artifact@v4 - if: always() - with: - name: playwright-results - path: test-results/ - retention-days: 7 - - e2e-mobile: - name: E2E Tests (Mobile) - runs-on: ubuntu-latest - timeout-minutes: 30 - if: github.event_name == 'push' && github.ref == 'refs/heads/main' - services: - postgres: - image: postgres:16 - env: - POSTGRES_USER: basil - POSTGRES_PASSWORD: basil - POSTGRES_DB: basil - options: >- - --health-cmd pg_isready - --health-interval 10s - --health-timeout 5s - --health-retries 5 - ports: - - 5432:5432 - - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Install Playwright browsers - run: npx playwright install --with-deps - - - name: Build packages - run: npm run build - - - name: Run database migrations - working-directory: packages/api - env: - DATABASE_URL: postgresql://basil:basil@localhost:5432/basil - run: npm run prisma:migrate - - - name: Start application - env: - DATABASE_URL: postgresql://basil:basil@localhost:5432/basil - PORT: 3001 - NODE_ENV: test - run: | - npm run dev & - sleep 10 - - - name: Run E2E tests on mobile - run: npx playwright test --project="Mobile Chrome" --project="Mobile Safari" - - - name: Upload mobile test results - uses: actions/upload-artifact@v4 - if: always() - with: - name: playwright-mobile-results - path: test-results/ - retention-days: 7 diff --git a/.gitea/workflows/security.yml b/.gitea/workflows/security.yml deleted file mode 100644 index 9301849..0000000 --- a/.gitea/workflows/security.yml +++ /dev/null @@ -1,146 +0,0 @@ -name: Security Scanning - -on: - push: - branches: [ main, master, develop ] - pull_request: - branches: [ main, master ] - schedule: - # Run security scans weekly on Monday at 9 AM UTC - - cron: '0 9 * * 1' - -jobs: - dependency-audit: - name: NPM Audit - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Run npm audit - run: npm audit --audit-level=moderate - continue-on-error: true - - - name: Run npm audit in API package - working-directory: packages/api - run: npm audit --audit-level=moderate - continue-on-error: true - - - name: Run npm audit in Web package - working-directory: packages/web - run: npm audit --audit-level=moderate - continue-on-error: true - - - name: Generate audit report - if: always() - run: | - echo "## Security Audit Report" >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "NPM audit has been completed for all packages." >> $GITHUB_STEP_SUMMARY - echo "Review the logs above for any vulnerabilities." >> $GITHUB_STEP_SUMMARY - - dependency-check: - name: Dependency License Check - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Check for outdated dependencies - run: npm outdated || true - - - name: List all dependencies - run: | - echo "## Dependency List" >> $GITHUB_STEP_SUMMARY - npm list --all || true - - code-scanning: - name: Code Quality Scan - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: '20' - cache: 'npm' - - - name: Install dependencies - run: npm ci - - - name: Run ESLint with security rules - run: npm run lint - continue-on-error: true - - - name: Check for hardcoded secrets (basic) - run: | - echo "Scanning for potential secrets..." - if grep -r -i -E "(password|secret|api[_-]?key|token|credential)" --include="*.ts" --include="*.js" --exclude-dir=node_modules --exclude-dir=dist . | grep -v "process.env" | grep -v "// "; then - echo "⚠️ Warning: Potential hardcoded secrets found!" - echo "Review the results above and ensure no sensitive data is committed." - else - echo "✅ No obvious hardcoded secrets detected." - fi - - docker-security: - name: Docker Image Security - runs-on: ubuntu-latest - if: github.event_name == 'push' - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: Build Docker images - run: docker-compose build - - - name: Scan Docker images for vulnerabilities - run: | - echo "## Docker Security Scan" >> $GITHUB_STEP_SUMMARY - echo "Docker images have been built successfully." >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "Consider using tools like Trivy or Snyk for comprehensive vulnerability scanning." >> $GITHUB_STEP_SUMMARY - - security-summary: - name: Security Summary - runs-on: ubuntu-latest - needs: [dependency-audit, dependency-check, code-scanning] - if: always() - steps: - - name: Generate security summary - run: | - echo "# 🔒 Security Scan Summary" >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "All security scans have been completed." >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "## Scans Performed:" >> $GITHUB_STEP_SUMMARY - echo "- ✅ NPM Dependency Audit" >> $GITHUB_STEP_SUMMARY - echo "- ✅ Dependency License Check" >> $GITHUB_STEP_SUMMARY - echo "- ✅ Code Quality Scanning" >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "Review individual job logs for detailed results." >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "### Recommended Additional Tools:" >> $GITHUB_STEP_SUMMARY - echo "- **Snyk**: For advanced vulnerability scanning" >> $GITHUB_STEP_SUMMARY - echo "- **Trivy**: For Docker image scanning" >> $GITHUB_STEP_SUMMARY - echo "- **SonarQube**: For code quality and security analysis" >> $GITHUB_STEP_SUMMARY - echo "- **Dependabot**: For automated dependency updates" >> $GITHUB_STEP_SUMMARY