// Vitest Snapshot v1, https://vitest.dev/guide/snapshot.html exports[`CI workflow generation > renders the complete workflow deterministically with one final LF 1`] = ` "# GENERATED FILE — edit config/ci/gates.json and run \`corepack pnpm generate:ci-workflow\`. name: frontend-quality-gates on: push: branches: [develop] tags: ["v*"] pull_request: workflow_dispatch: inputs: stage: description: Highest promotion tier to evaluate required: true default: merge type: choice options: - merge - release - production - field - documentation permissions: contents: read env: CI: "true" VITE_BUILD_ID: "gitea-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" VITE_COMMIT_SHA: "\${{ gitea.sha }}" RELEASE_ID: "\${{ gitea.ref }}-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" CI_RUNNER_IMAGE: "\${{ vars.RUNNER_IMAGE_DIGEST }}" jobs: merge_gate: name: "\${{ matrix.gate }} / \${{ matrix.name }}" if: \${{ gitea.event_name != 'workflow_dispatch' || inputs.stage != 'documentation' }} runs-on: ubuntu-latest timeout-minutes: 45 strategy: fail-fast: false matrix: include: - { gate: FE-GATE-001, name: manifest-lockfile, browser: false } - { gate: FE-GATE-002, name: lint, browser: false } - { gate: FE-GATE-003, name: typecheck, browser: false } - { gate: FE-GATE-004, name: runtime-schema, browser: false } - { gate: FE-GATE-005, name: unit, browser: false } - { gate: FE-GATE-006, name: component, browser: false } - { gate: FE-GATE-007, name: integration, browser: false } - { gate: FE-GATE-008, name: e2e, browser: true } - { gate: FE-GATE-009, name: accessibility, browser: true } - { gate: FE-GATE-010, name: architecture, browser: false } - { gate: FE-GATE-011, name: build, browser: false } - { gate: FE-GATE-013, name: security, browser: false } - { gate: FE-GATE-020, name: removability, browser: false } steps: - uses: https://github.com/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: persist-credentials: false - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version-file: .nvmrc - name: Frozen install run: | corepack enable corepack pnpm install --frozen-lockfile --ignore-scripts - name: Install Playwright browsers if: \${{ matrix.browser }} run: corepack pnpm exec playwright install --with-deps chromium firefox webkit - name: Run blocking gate run: corepack pnpm ci:gate -- \${{ matrix.gate }} - name: Upload merge gate evidence if: always() uses: https://github.com/ChristopherHX/gitea-upload-artifact@81f940d004763f986ba3582c007fd842dd5cb0d7 with: name: "\${{ matrix.gate }}-\${{ gitea.run_id }}" path: artifacts/ if-no-files-found: error release_gate: name: "\${{ matrix.gate }} / \${{ matrix.name }}" needs: merge_gate if: \${{ startsWith(gitea.ref, 'refs/tags/v') || (gitea.event_name == 'workflow_dispatch' && (inputs.stage == 'release' || inputs.stage == 'production' || inputs.stage == 'field')) }} runs-on: ubuntu-latest timeout-minutes: 45 env: HOSTING_BASE_URL: "\${{ vars.HOSTING_BASE_URL }}" strategy: fail-fast: false matrix: include: - { gate: FE-GATE-012, name: bundle, browser: false } - { gate: FE-GATE-014, name: config-compatibility, browser: false } - { gate: FE-GATE-019, name: hosting-header, browser: false } - { gate: FE-GATE-026, name: lab-performance, browser: true } steps: - uses: https://github.com/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: persist-credentials: false - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version-file: .nvmrc - name: Frozen install run: | corepack enable corepack pnpm install --frozen-lockfile --ignore-scripts - name: Install Playwright browsers if: \${{ matrix.browser }} run: corepack pnpm exec playwright install --with-deps chromium firefox webkit - name: Run blocking gate run: corepack pnpm ci:gate -- \${{ matrix.gate }} - name: Upload release gate evidence if: always() uses: https://github.com/ChristopherHX/gitea-upload-artifact@81f940d004763f986ba3582c007fd842dd5cb0d7 with: name: "\${{ matrix.gate }}-\${{ gitea.run_id }}" path: artifacts/ if-no-files-found: error immutable_build: name: "FE-GATE-015 / immutable-release-candidate" needs: release_gate if: \${{ startsWith(gitea.ref, 'refs/tags/v') || (gitea.event_name == 'workflow_dispatch' && (inputs.stage == 'release' || inputs.stage == 'production' || inputs.stage == 'field')) }} runs-on: ubuntu-latest timeout-minutes: 45 outputs: dist_sha256: \${{ steps.candidate.outputs.dist_sha256 }} archive_sha256: \${{ steps.candidate.outputs.archive_sha256 }} steps: - uses: https://github.com/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: persist-credentials: false - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version-file: .nvmrc - name: Frozen install run: | corepack enable corepack pnpm install --frozen-lockfile --ignore-scripts - name: Build candidate once and verify local evidence run: corepack pnpm ci:gate -- FE-GATE-015 - name: Archive and validate the exact candidate file set id: candidate run: | mkdir -p .release tar --sort=name --mtime="@0" --owner=0 --group=0 --numeric-owner -czf ".release/release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}.tar.gz" \\ dist \\ pnpm-lock.yaml \\ artifacts/performance/bundle.json \\ artifacts/quality/vite-module-inventory.json \\ artifacts/release/build-manifest.json \\ artifacts/release/checksums.txt \\ artifacts/release/dependency-inventory.json \\ artifacts/release/provenance.json \\ artifacts/release/verification.json \\ artifacts/release/sbom.cdx.json \\ artifacts/security/dependency-diff.json \\ artifacts/security/license-report.json \\ artifacts/security/scan.sarif \\ artifacts/security/supply-chain-coherence.json \\ artifacts/security/supply-chain-verification.json \\ artifacts/security/vulnerability-report.json \\ artifacts/release/release-candidate.json node scripts/verify-ci-candidate-archive.ts --archive ".release/release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}.tar.gz" --github-output "$GITHUB_OUTPUT" - name: Upload release candidate uses: https://github.com/ChristopherHX/gitea-upload-artifact@81f940d004763f986ba3582c007fd842dd5cb0d7 with: name: "release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" path: ".release/release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}.tar.gz" if-no-files-found: error vulnerability_provider: name: external-vulnerability-provider needs: immutable_build runs-on: ubuntu-latest timeout-minutes: 45 env: CANDIDATE_ARCHIVE_SHA256: "\${{ needs.immutable_build.outputs.archive_sha256 }}" CANDIDATE_ARCHIVE_PATH: ".release/vulnerability-candidate/release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}.tar.gz" CANDIDATE_DIST_SHA256: "\${{ needs.immutable_build.outputs.dist_sha256 }}" CANDIDATE_LOCKFILE_PATH: .release/verified-vulnerability/pnpm-lock.yaml VULNERABILITY_PROVIDER_COMMAND: "\${{ vars.VULNERABILITY_PROVIDER_COMMAND }}" VULNERABILITY_REPORT_PATH: provider-evidence/untrusted/vulnerability-report.json VALIDATED_PROVIDER_REPORT_PATH: provider-evidence/vulnerability-report.json steps: - uses: https://github.com/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: persist-credentials: false - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version-file: .nvmrc - name: Frozen install run: | corepack enable corepack pnpm install --frozen-lockfile --ignore-scripts - name: Download release candidate uses: https://github.com/ChristopherHX/gitea-download-artifact@75635f32b4c1c41c4b3d64e8f85210112ed4c9c7 with: name: "release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" path: .release/vulnerability-candidate - name: Verify and extract the candidate through one inode-bound operation run: node scripts/verify-ci-candidate-archive.ts --archive ".release/vulnerability-candidate/release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}.tar.gz" --extract-to ".release/verified-vulnerability" - name: Run and validate external vulnerability provider in one trusted supervisor run: node scripts/run-and-validate-provider.ts --kind vulnerability - name: Confirm sealed vulnerability provider evidence run: test -s "$VALIDATED_PROVIDER_REPORT_PATH" - name: Upload vulnerability provider evidence uses: https://github.com/ChristopherHX/gitea-upload-artifact@81f940d004763f986ba3582c007fd842dd5cb0d7 with: name: "vulnerability-provider-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" path: provider-evidence/vulnerability-report.json if-no-files-found: error provenance_provider: name: external-provenance-provider needs: immutable_build runs-on: ubuntu-latest timeout-minutes: 45 env: CANDIDATE_ARCHIVE_SHA256: "\${{ needs.immutable_build.outputs.archive_sha256 }}" CANDIDATE_ARCHIVE_PATH: ".release/provenance-candidate/release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}.tar.gz" CANDIDATE_DIST_SHA256: "\${{ needs.immutable_build.outputs.dist_sha256 }}" CANDIDATE_LOCKFILE_PATH: .release/verified-provenance/pnpm-lock.yaml PROVENANCE_PROVIDER_COMMAND: "\${{ vars.PROVENANCE_PROVIDER_COMMAND }}" PROVENANCE_ATTESTATION_PATH: provider-evidence/untrusted/provenance-attestation.json VALIDATED_PROVIDER_REPORT_PATH: provider-evidence/provenance-attestation.json steps: - uses: https://github.com/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: persist-credentials: false - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version-file: .nvmrc - name: Frozen install run: | corepack enable corepack pnpm install --frozen-lockfile --ignore-scripts - name: Download release candidate uses: https://github.com/ChristopherHX/gitea-download-artifact@75635f32b4c1c41c4b3d64e8f85210112ed4c9c7 with: name: "release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" path: .release/provenance-candidate - name: Verify and extract the candidate through one inode-bound operation run: node scripts/verify-ci-candidate-archive.ts --archive ".release/provenance-candidate/release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}.tar.gz" --extract-to ".release/verified-provenance" - name: Run and validate external provenance provider in one trusted supervisor run: node scripts/run-and-validate-provider.ts --kind provenance - name: Confirm sealed provenance provider evidence run: test -s "$VALIDATED_PROVIDER_REPORT_PATH" - name: Upload provenance provider evidence uses: https://github.com/ChristopherHX/gitea-upload-artifact@81f940d004763f986ba3582c007fd842dd5cb0d7 with: name: "provenance-provider-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" path: provider-evidence/provenance-attestation.json if-no-files-found: error promotion: name: promote-verified-immutable-candidate needs: [immutable_build, vulnerability_provider, provenance_provider] runs-on: ubuntu-latest timeout-minutes: 45 env: CANDIDATE_ARCHIVE_SHA256: "\${{ needs.immutable_build.outputs.archive_sha256 }}" CANDIDATE_ARCHIVE_PATH: ".release/candidate/release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}.tar.gz" CANDIDATE_ROOT: "\${{ gitea.workspace }}/.release/verified-candidate" VULNERABILITY_REPORT_PATH: "\${{ gitea.workspace }}/.release/vulnerability/vulnerability-report.json" PROVENANCE_ATTESTATION_PATH: "\${{ gitea.workspace }}/.release/provenance/provenance-attestation.json" VULNERABILITY_PUBLIC_KEY_PATH: "\${{ vars.VULNERABILITY_PUBLIC_KEY_PATH }}" VULNERABILITY_KEY_ID: "\${{ vars.VULNERABILITY_KEY_ID }}" PROVENANCE_PUBLIC_KEY_PATH: "\${{ vars.PROVENANCE_PUBLIC_KEY_PATH }}" PROVENANCE_KEY_ID: "\${{ vars.PROVENANCE_KEY_ID }}" steps: - uses: https://github.com/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: persist-credentials: false - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version-file: .nvmrc - name: Frozen install run: | corepack enable corepack pnpm install --frozen-lockfile --ignore-scripts - name: Download release candidate uses: https://github.com/ChristopherHX/gitea-download-artifact@75635f32b4c1c41c4b3d64e8f85210112ed4c9c7 with: name: "release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" path: .release/candidate - name: Download vulnerability provider evidence uses: https://github.com/ChristopherHX/gitea-download-artifact@75635f32b4c1c41c4b3d64e8f85210112ed4c9c7 with: name: "vulnerability-provider-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" path: .release/vulnerability - name: Download provenance provider evidence uses: https://github.com/ChristopherHX/gitea-download-artifact@75635f32b4c1c41c4b3d64e8f85210112ed4c9c7 with: name: "provenance-provider-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" path: .release/provenance - name: Verify and extract the candidate through one inode-bound operation run: node scripts/verify-ci-candidate-archive.ts --archive ".release/candidate/release-candidate-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}.tar.gz" --extract-to ".release/verified-candidate" - name: Finalize verified promotion from inode-bound captured inputs run: node scripts/stage-verified-promotion.ts - name: Upload promoted release uses: https://github.com/ChristopherHX/gitea-upload-artifact@81f940d004763f986ba3582c007fd842dd5cb0d7 with: name: "promoted-release-\${{ gitea.run_id }}-\${{ gitea.run_attempt }}" path: | .release/promoted-staging/release-candidate.tar.gz .release/promoted-staging/vulnerability-report.json .release/promoted-staging/provenance-attestation.json .release/promoted-staging/provider-verification.json .release/promoted-staging/promotion-verification.json if-no-files-found: error production_gate: name: "\${{ matrix.gate }} / \${{ matrix.name }}" needs: promotion if: \${{ gitea.event_name == 'workflow_dispatch' && (inputs.stage == 'production' || inputs.stage == 'field') }} runs-on: ubuntu-latest timeout-minutes: 45 strategy: fail-fast: false matrix: include: - { gate: FE-GATE-016, name: rollback-drill } - { gate: FE-GATE-021, name: runbook-boot-config } - { gate: FE-GATE-022, name: runbook-chunk-mismatch } - { gate: FE-GATE-023, name: runbook-api-degradation } - { gate: FE-GATE-024, name: runbook-telemetry } - { gate: FE-GATE-025, name: runbook-release-rollback } steps: - uses: https://github.com/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: persist-credentials: false - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version-file: .nvmrc - name: Frozen install run: | corepack enable corepack pnpm install --frozen-lockfile --ignore-scripts - name: Run blocking gate run: corepack pnpm ci:gate -- \${{ matrix.gate }} - name: Upload production gate evidence if: always() uses: https://github.com/ChristopherHX/gitea-upload-artifact@81f940d004763f986ba3582c007fd842dd5cb0d7 with: name: "\${{ matrix.gate }}-\${{ gitea.run_id }}" path: artifacts/ if-no-files-found: error field_gate: name: "FE-GATE-018 / field-web-vitals" needs: production_gate if: \${{ gitea.event_name == 'workflow_dispatch' && inputs.stage == 'field' }} runs-on: ubuntu-latest timeout-minutes: 45 env: FIELD_WEB_VITALS_INPUT: "\${{ vars.FIELD_WEB_VITALS_INPUT }}" MIN_ELIGIBLE_SAMPLES: "\${{ vars.MIN_ELIGIBLE_SAMPLES }}" steps: - uses: https://github.com/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: persist-credentials: false - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version-file: .nvmrc - name: Frozen install run: | corepack enable corepack pnpm install --frozen-lockfile --ignore-scripts - name: Run blocking gate run: corepack pnpm ci:gate -- FE-GATE-018 - name: Upload field gate evidence if: always() uses: https://github.com/ChristopherHX/gitea-upload-artifact@81f940d004763f986ba3582c007fd842dd5cb0d7 with: name: "FE-GATE-018-\${{ gitea.run_id }}" path: artifacts/ if-no-files-found: error documentation_gate: name: "FE-GATE-017 / diagram-review" if: \${{ gitea.event_name == 'workflow_dispatch' && inputs.stage == 'documentation' }} runs-on: ubuntu-latest timeout-minutes: 45 steps: - uses: https://github.com/actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 with: persist-credentials: false - uses: https://github.com/actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 with: node-version-file: .nvmrc - name: Frozen install run: | corepack enable corepack pnpm install --frozen-lockfile --ignore-scripts - name: Run documentation gate run: corepack pnpm ci:gate -- FE-GATE-017 - name: Upload documentation gate evidence if: always() uses: https://github.com/ChristopherHX/gitea-upload-artifact@81f940d004763f986ba3582c007fd842dd5cb0d7 with: name: "FE-GATE-017-\${{ gitea.run_id }}" path: artifacts/ if-no-files-found: error " `;