Skip to content

fix(deps): update dependency js-yaml to v5.2.2 [security] #11531

fix(deps): update dependency js-yaml to v5.2.2 [security]

fix(deps): update dependency js-yaml to v5.2.2 [security] #11531

Workflow file for this run

name: Dev
on:
push:
branches:
- main
- standalone
- "release/*"
pull_request:
branches:
- main
- standalone
- "release/*"
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
GHCR_REGISTRY: ghcr.io
DOCKERHUB_REGISTRY: docker.io
IMAGE_NAME: ${{ github.repository}}
TEST_TAG: ${{ github.repository}}:test
permissions:
pull-requests: write # for PR comments
jobs:
test_dev:
name: Test development
runs-on: ubuntu-latest
steps:
- name: Checkout the repository
uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- name: Set up node & dependencies
uses: actions/setup-node@v7
with:
node-version: 24
cache: "pnpm"
- run: pnpm install --frozen-lockfile
- name: Typecheck
run: pnpm typecheck
- name: Run the client-side tests
run: pnpm run --filter=client test --coverage
- name: Upload client test report
uses: actions/upload-artifact@v7
if: always()
with:
name: client-test-report
path: apps/client/test-output/vitest/html/
retention-days: 30
- name: Run the server-side tests
run: pnpm run --filter=server test --coverage
- name: Upload server test report
uses: actions/upload-artifact@v7
if: always()
with:
name: server-test-report
path: apps/server/test-output/vitest/html/
retention-days: 30
- name: Upload client coverage to Codecov
uses: codecov/codecov-action@v7
if: always()
with:
files: apps/client/test-output/vitest/coverage/lcov.info
flags: client
fail_ci_if_error: false
- name: Upload client test results to Codecov
uses: codecov/test-results-action@v1
if: ${{ !cancelled() }}
with:
token: ${{ secrets.CODECOV_TOKEN }}
files: apps/client/test-output/vitest/junit.xml
flags: client
fail_ci_if_error: false
- name: Upload server coverage to Codecov
uses: codecov/codecov-action@v7
if: always()
with:
files: apps/server/test-output/vitest/coverage/lcov.info
flags: server
fail_ci_if_error: false
- name: Upload server test results to Codecov
uses: codecov/test-results-action@v1
if: ${{ !cancelled() }}
with:
token: ${{ secrets.CODECOV_TOKEN }}
files: apps/server/test-output/vitest/junit.xml
flags: server
fail_ci_if_error: false
- name: Run the standalone tests
# Runs the same trilium-core spec set as the server suite, but in
# happy-dom + sql.js WASM via BrowserSqlProvider (see
# apps/standalone/src/test_setup.ts). Catches differences
# between the Node-side and browser-side runtimes.
run: pnpm run --filter=standalone test --coverage
- name: Upload standalone coverage to Codecov
uses: codecov/codecov-action@v7
if: always()
with:
files: apps/standalone/test-output/vitest/coverage/lcov.info
flags: standalone
fail_ci_if_error: false
- name: Upload standalone test results to Codecov
uses: codecov/test-results-action@v1
if: ${{ !cancelled() }}
with:
token: ${{ secrets.CODECOV_TOKEN }}
files: apps/standalone/test-output/vitest/junit.xml
flags: standalone
fail_ci_if_error: false
- name: Run CKEditor e2e tests
run: |
export CHROMEDRIVER_PATH=$(which chromedriver || find /usr/local/share -name chromedriver -type f 2>/dev/null | head -1)
echo "Using chromedriver at: $CHROMEDRIVER_PATH"
pnpm run --filter=ckeditor5-mermaid test
pnpm run --filter=ckeditor5-math test
- name: Run the CKEditor 5 aggregate tests
run: |
export CHROMEDRIVER_PATH=$(which chromedriver || find /usr/local/share -name chromedriver -type f 2>/dev/null | head -1)
echo "Using chromedriver at: $CHROMEDRIVER_PATH"
pnpm run --filter=ckeditor5 test --coverage
- name: Upload ckeditor5 coverage to Codecov
uses: codecov/codecov-action@v7
if: always()
with:
files: packages/ckeditor5/test-output/vitest/coverage/lcov.info
flags: ckeditor5
fail_ci_if_error: false
- name: Upload ckeditor5 test results to Codecov
uses: codecov/test-results-action@v1
if: ${{ !cancelled() }}
with:
token: ${{ secrets.CODECOV_TOKEN }}
files: packages/ckeditor5/test-output/vitest/junit.xml
flags: ckeditor5
fail_ci_if_error: false
- name: Run the CKEditor 5 utils tests
run: |
export CHROMEDRIVER_PATH=$(which chromedriver || find /usr/local/share -name chromedriver -type f 2>/dev/null | head -1)
echo "Using chromedriver at: $CHROMEDRIVER_PATH"
pnpm run --filter=ckeditor5-utils test --coverage
- name: Upload ckeditor5-utils coverage to Codecov
uses: codecov/codecov-action@v7
if: always()
with:
files: packages/ckeditor5-utils/test-output/vitest/coverage/lcov.info
flags: ckeditor5-utils
fail_ci_if_error: false
- name: Upload ckeditor5-utils test results to Codecov
uses: codecov/test-results-action@v1
if: ${{ !cancelled() }}
with:
token: ${{ secrets.CODECOV_TOKEN }}
files: packages/ckeditor5-utils/test-output/vitest/junit.xml
flags: ckeditor5-utils
fail_ci_if_error: false
- name: Run the desktop tests
run: pnpm run --filter=desktop test --coverage
- name: Upload desktop coverage to Codecov
uses: codecov/codecov-action@v7
if: always()
with:
files: apps/desktop/test-output/vitest/coverage/lcov.info
flags: desktop
fail_ci_if_error: false
- name: Upload desktop test results to Codecov
uses: codecov/test-results-action@v1
if: ${{ !cancelled() }}
with:
token: ${{ secrets.CODECOV_TOKEN }}
files: apps/desktop/test-output/vitest/junit.xml
flags: desktop
fail_ci_if_error: false
- name: Run the commons tests
run: pnpm run --filter=commons test --coverage
- name: Upload commons coverage to Codecov
uses: codecov/codecov-action@v7
if: always()
with:
files: packages/commons/test-output/vitest/coverage/lcov.info
flags: commons
fail_ci_if_error: false
- name: Upload commons test results to Codecov
uses: codecov/test-results-action@v1
if: ${{ !cancelled() }}
with:
token: ${{ secrets.CODECOV_TOKEN }}
files: packages/commons/test-output/vitest/junit.xml
flags: commons
fail_ci_if_error: false
- name: Run the rest of the tests
run: pnpm run --filter=\!client --filter=\!standalone --filter=\!server --filter=\!desktop --filter=\!commons --filter=\!ckeditor5-mermaid --filter=\!ckeditor5-math --filter=\!ckeditor5 --filter=\!ckeditor5-utils test
build_docker:
name: Build Docker image
runs-on: ubuntu-latest
needs:
- test_dev
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- name: Set up node & dependencies
uses: actions/setup-node@v7
with:
node-version: 24
cache: "pnpm"
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Update build info
run: pnpm run chore:update-build-info
- name: Trigger client build
run: pnpm client:build
env:
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
- name: Trigger server build
run: pnpm run server:build
- uses: docker/setup-buildx-action@v4
- uses: docker/build-push-action@v7
with:
context: apps/server
cache-from: type=gha
cache-to: type=gha,mode=max
test_docker:
name: Check Docker build
runs-on: ubuntu-latest
needs:
- build_docker
strategy:
matrix:
include:
- dockerfile: Dockerfile.alpine
- dockerfile: Dockerfile
steps:
- name: Checkout the repository
uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- name: Set up node & dependencies
uses: actions/setup-node@v7
with:
node-version: 24
cache: "pnpm"
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Update build info
run: pnpm run chore:update-build-info
- name: Trigger build
run: pnpm server:build
- name: Set IMAGE_NAME to lowercase
run: echo "IMAGE_NAME=${IMAGE_NAME,,}" >> $GITHUB_ENV
- name: Set TEST_TAG to lowercase
run: echo "TEST_TAG=${TEST_TAG,,}" >> $GITHUB_ENV
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
- name: Build and export to Docker
uses: docker/build-push-action@v7
with:
context: apps/server
file: apps/server/${{ matrix.dockerfile }}
load: true
tags: ${{ env.TEST_TAG }}
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Validate container run output
run: |
CONTAINER_ID=$(docker run -d --log-driver=journald --rm --name trilium_local ${{ env.TEST_TAG }})
echo "Container ID: $CONTAINER_ID"
- name: Wait for the healthchecks to pass
uses: stringbean/docker-healthcheck-action@v3
with:
container: trilium_local
wait-time: 50
require-status: running
require-healthy: true
# Print the entire log of the container thus far, regardless if the healthcheck failed or succeeded
- name: Print entire log
if: always()
run: journalctl -u docker CONTAINER_NAME=trilium_local --no-pager