14 Commits
Author SHA1 Message Date
LucaZanni f0896d775d feat(ci): aggiungi varianti -github dei reusable e fix audit Python
- crea gemelli X-github.yml per ogni reusable con action da github.com (fallback mirror gitea.com)
- python-dependency-check/outdated: audit in venv isolata (fix falsi positivi da runner ML)
- python-dependency-check/outdated: deduplica issue (commento invece di nuova issue)
- examples: aggiungi ci-github.yml e release-github.yml in tutte le cartelle

Fixes #3 @3h
2026-07-06 19:53:01 +02:00
LucaZanni e5411d9d2d feat(docker-release): aggiungi build-args con vars fallback per versioni Docker
- NODE_VERSION da vars.NODE_DOCKER_VERSION (fallback: 24.16.0-alpine3.22)
- NGINX_VERSION da vars.NGINX_DOCKER_VERSION (fallback: 1.30.2-alpine3.23)
- NPM_VERSION da vars.NPM_VERSION (fallback: 11.16.0)

Fixes #0 @25m
2026-06-06 14:49:45 +02:00
LucaZanni 94767592c5 fix(ci): downgrade upload-artifact v4->v3 gitea.com
github.com/actions/upload-artifact@v4 non supportato su GHES/Gitea self-hosted.
gitea.com/actions/upload-artifact@v3 usa la API artifact compatibile.
2026-06-06 14:43:38 +02:00
LucaZanni 0fc0251233 fix(ci): sostituisce node -e con jq per leggere package.json
node -e con quoting " dentro block scalar YAML causa syntax error nella shell
("require(" interpretato come subshell). jq evita il problema.
2026-06-06 14:37:23 +02:00
LucaZanni b609947f46 chore(examples): aggiorna node-version a 24.16.0 nel commento di esempio 2026-06-06 14:24:38 +02:00
LucaZanni b21c3877c6 chore(ci): aggiorna node-version default a 24.16.0
Node.js 24.16.0 LTS sostituisce 22.17 come versione di default in tutti i workflow.
2026-06-06 14:24:11 +02:00
LucaZanni 392cdf2580 fix(ci): sostituisce gitea.com/actions/cache con github.com in tutti i workflow
gitea.com/actions/cache@v4 restituisce HTTP 500 in modo intermittente.
github.com/actions/cache@v4 già usato dal runner per altri step (setup-java, ecc.).
2026-06-06 14:05:29 +02:00
LucaZanni 0ed7e2b58a fix(ci): sostituisce gitea.com/actions/cache con github.com - HTTP 500
gitea.com/actions/cache@v4 restituisce 500 impedendo l'avvio del job android.
2026-06-06 13:59:52 +02:00
LucaZanni 3b49d18d5b fix(ci): aggiunge input npm-version per compatibilità lockfile npm@11
- quality-gates.yml: nuovo input npm-version con step condizionale upgrade
- docker-release.yml: idem
- examples/documentazione: ci.yml e release.yml passano npm-version: '11'

Fixes #2 @25m
2026-06-06 13:36:22 +02:00
LucaZanni 53b1c7a9c4 feat(examples): aggiungi template documentazione Nuxt 4
- ci.yml: quality-gates condivisi con paths-ignore su content/**
- release.yml: docker-release + auto-release con needs
- maintenance.yml: schedule martedì 02:00 audit, 1° mese 03:00 outdated

refs #1 @25m
2026-06-06 13:28:46 +02:00
LucaZanni 0f7688ac5e chore(ci): aggiorna action versions, fix auto-release e migrazione self-hosted
- Aggiorna checkout v4→v6, setup-python v5→v5.2.0, setup-android v3→v4
- Aggiorna upload-artifact v3→v4, docker/login-action v3→v4
- Aggiunge needs su auto-release in tutti gli esempi (fix esecuzione parallela)
- Aggiunge token esplicito nel checkout come workaround bug Gitea #31900
- Aggiunge job dependency-outdated mancante in libreria-npm/maintenance.yml
- Aggiorna schedule: libreria-npm mercoledì 02:00, microservizio lunedì 02:00
- Migra tutti i riferimenti da gitea.com/Punga78 a gitea.pzetatouch.it/devops

Fixes #1 @3h
2026-06-06 13:21:01 +02:00
LucaZanni 54c74d9c6a feat(ci): aggiungi label OCI per collegare container al repository Gitea
- Aggiunto org.opencontainers.image.source con URL del repository
- Aggiunto org.opencontainers.image.revision con SHA del commit
- Aggiunto org.opencontainers.image.version con versione del pacchetto
- Applicato a docker-release.yml e python-docker-release.yml

@25m
2026-04-11 18:53:05 +02:00
LucaZanni 86a0cd416f 🐛 fix(ci): correggi passaggio NPM_TOKEN come Docker secret e runs-on workaround
- Sostituisce build-args con secrets in docker-release.yml per compatibilità
  con Dockerfile che usa --mount=type=secret,id=npm_token
- Aggiunge runs-on: catthehacker-latest negli esempi (workaround Gitea bug #34986)
2026-04-09 19:54:25 +02:00
LucaZanni 3ee135b020 👷 ci(release): aggiungi workaround per bug runs-on in Gitea
- aggiunta runs-on: catthehacker-latest per aggirare bug #34986
- commento esplicativo sul motivo della modifica
- garantita corretta esecuzione workflow_call su Gitea
2026-04-09 19:46:59 +02:00
49 changed files with 1642 additions and 118 deletions
+51
View File
@@ -0,0 +1,51 @@
name: Auto Release
on:
workflow_call:
jobs:
auto-release:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
with:
fetch-depth: 0
token: ${{ gitea.token }}
- name: Generate changelog
id: changelog
run: |
CURRENT_TAG=${GITHUB_REF#refs/tags/}
PREV_TAG=$(git tag --sort=-version:refname | sed -n '2p')
if [ -z "$PREV_TAG" ]; then
CHANGELOG=$(git log --pretty=format:"- %s (%h)" "$CURRENT_TAG")
else
CHANGELOG=$(git log --pretty=format:"- %s (%h)" "${PREV_TAG}..${CURRENT_TAG}")
fi
echo "$CHANGELOG" > /tmp/changelog.txt
echo "current_tag=$CURRENT_TAG" >> $GITHUB_OUTPUT
- name: Create release
env:
GITEA_TOKEN: ${{ gitea.token }}
SERVER_URL: ${{ gitea.server_url }}
REPOSITORY: ${{ gitea.repository }}
run: |
CURRENT_TAG=${{ steps.changelog.outputs.current_tag }}
APP_NAME=$(jq -r '.name' package.json)
CHANGELOG=$(cat /tmp/changelog.txt)
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/releases" \
-d "{
\"tag_name\": \"$CURRENT_TAG\",
\"name\": \"$APP_NAME $CURRENT_TAG\",
\"body\": $(echo "$CHANGELOG" | jq -Rs .),
\"draft\": false,
\"prerelease\": false
}"
+2 -1
View File
@@ -8,9 +8,10 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
with: with:
fetch-depth: 0 fetch-depth: 0
token: ${{ gitea.token }}
- name: Generate changelog - name: Generate changelog
id: changelog id: changelog
@@ -0,0 +1,169 @@
name: Capacitor Android
on:
workflow_call:
inputs:
node-version:
type: string
default: '24.16.0'
java-version:
type: string
default: '21'
runner:
type: string
default: 'ubuntu-latest'
build-type:
description: 'debug | release'
type: string
default: 'debug'
output-format:
description: 'apk (sideload/test) | aab (Play Store)'
type: string
default: 'apk'
secrets:
NPM_TOKEN:
required: false
KEYSTORE_BASE64:
required: false
KEYSTORE_PASSWORD:
required: false
KEY_ALIAS:
required: false
KEY_PASSWORD:
required: false
GOOGLE_SERVICES_JSON:
required: false
jobs:
android-build:
runs-on: ${{ inputs.runner }}
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Node.js
uses: https://github.com/actions/setup-node@v4
with:
node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Setup Java
uses: https://github.com/actions/setup-java@v4
with:
distribution: temurin
java-version: ${{ inputs.java-version || '17' }}
- name: Setup Android SDK
uses: https://github.com/android-actions/setup-android@v4
- name: Cache npm
uses: https://github.com/actions/cache@v4
with:
path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
restore-keys: |
${{ runner.os }}-node-
- name: Cache Gradle
uses: https://github.com/actions/cache@v4
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: ${{ runner.os }}-gradle-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: |
${{ runner.os }}-gradle-
- name: Configure npm private registry
run: |
echo "@pzeta:registry=https://gitea.pzetatouch.it/api/packages/pzeta_touch/npm/" >> ~/.npmrc
echo "//gitea.pzetatouch.it/api/packages/pzeta_touch/npm/:_authToken=${{ secrets.NPM_TOKEN }}" >> ~/.npmrc
- name: Read app info from package.json
id: app-info
run: |
echo "name=$(jq -r '.name' package.json)" >> $GITHUB_OUTPUT
echo "version=$(jq -r '.version' package.json)" >> $GITHUB_OUTPUT
- name: Install dependencies
run: npm ci
- name: Build web app
run: npm run build
- name: Add Android platform
run: npx cap add android || true
- name: Sync Capacitor
run: npx cap sync android
- name: Setup google-services.json
if: secrets.GOOGLE_SERVICES_JSON != ''
run: echo '${{ secrets.GOOGLE_SERVICES_JSON }}' > android/app/google-services.json
- name: Setup release keystore
if: inputs.build-type == 'release'
run: echo '${{ secrets.KEYSTORE_BASE64 }}' | base64 -d > android/app/keystore.jks
- name: Build Android (APK)
if: inputs.output-format == 'apk'
working-directory: android
env:
KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }}
KEY_ALIAS: ${{ secrets.KEY_ALIAS }}
KEY_PASSWORD: ${{ secrets.KEY_PASSWORD }}
run: |
if [ "${{ inputs.build-type }}" = "release" ]; then
./gradlew assembleRelease
else
./gradlew assembleDebug
fi
- name: Rename APK
if: inputs.output-format == 'apk'
run: |
APP="${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-${{ inputs.build-type }}"
APK_DIR="android/app/build/outputs/apk/${{ inputs.build-type }}"
mv "$APK_DIR"/app-${{ inputs.build-type }}.apk "$APK_DIR/${APP}.apk" 2>/dev/null || \
mv "$APK_DIR"/app-${{ inputs.build-type }}-unsigned.apk "$APK_DIR/${APP}.apk" 2>/dev/null || \
find "$APK_DIR" -name "*.apk" ! -name "${APP}.apk" -exec mv {} "$APK_DIR/${APP}.apk" \;
- name: Build Android (AAB)
if: inputs.output-format == 'aab'
working-directory: android
env:
KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }}
KEY_ALIAS: ${{ secrets.KEY_ALIAS }}
KEY_PASSWORD: ${{ secrets.KEY_PASSWORD }}
run: ./gradlew bundleRelease
- name: Rename AAB
if: inputs.output-format == 'aab'
run: |
APP="${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-release"
AAB_DIR="android/app/build/outputs/bundle/release"
find "$AAB_DIR" -name "*.aab" ! -name "${APP}.aab" -exec mv {} "$AAB_DIR/${APP}.aab" \;
- name: Upload APK artifact
if: inputs.output-format == 'apk'
uses: https://github.com/actions/upload-artifact@v3
with:
name: ${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-${{ inputs.build-type }}-apk
path: android/app/build/outputs/apk/${{ inputs.build-type }}/${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-${{ inputs.build-type }}.apk
retention-days: 14
- name: Upload AAB artifact
if: inputs.output-format == 'aab'
uses: https://github.com/actions/upload-artifact@v3
with:
name: ${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-release-aab
path: android/app/build/outputs/bundle/release/${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-release.aab
retention-days: 14
- name: Upload Gradle build reports
if: always()
uses: https://github.com/actions/upload-artifact@v3
with:
name: gradle-build-reports
path: android/build/reports/
retention-days: 7
if-no-files-found: ignore
+11 -11
View File
@@ -5,7 +5,7 @@ on:
inputs: inputs:
node-version: node-version:
type: string type: string
default: '22.17' default: '24.16.0'
java-version: java-version:
type: string type: string
default: '21' default: '21'
@@ -39,12 +39,12 @@ jobs:
runs-on: ${{ inputs.runner }} runs-on: ${{ inputs.runner }}
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Node.js - name: Setup Node.js
uses: https://gitea.com/actions/setup-node@v4 uses: https://gitea.com/actions/setup-node@v4
with: with:
node-version: ${{ inputs.node-version || '22.17' }} node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Setup Java - name: Setup Java
uses: https://github.com/actions/setup-java@v4 uses: https://github.com/actions/setup-java@v4
@@ -53,10 +53,10 @@ jobs:
java-version: ${{ inputs.java-version || '17' }} java-version: ${{ inputs.java-version || '17' }}
- name: Setup Android SDK - name: Setup Android SDK
uses: https://github.com/android-actions/setup-android@v3 uses: https://github.com/android-actions/setup-android@v4
- name: Cache npm - name: Cache npm
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.npm path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }} key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
@@ -64,7 +64,7 @@ jobs:
${{ runner.os }}-node- ${{ runner.os }}-node-
- name: Cache Gradle - name: Cache Gradle
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: | path: |
~/.gradle/caches ~/.gradle/caches
@@ -81,8 +81,8 @@ jobs:
- name: Read app info from package.json - name: Read app info from package.json
id: app-info id: app-info
run: | run: |
echo "name=$(node -e \"console.log(require('./package.json').name)\")" >> $GITHUB_OUTPUT echo "name=$(jq -r '.name' package.json)" >> $GITHUB_OUTPUT
echo "version=$(node -e \"console.log(require('./package.json').version)\")" >> $GITHUB_OUTPUT echo "version=$(jq -r '.version' package.json)" >> $GITHUB_OUTPUT
- name: Install dependencies - name: Install dependencies
run: npm ci run: npm ci
@@ -145,7 +145,7 @@ jobs:
- name: Upload APK artifact - name: Upload APK artifact
if: inputs.output-format == 'apk' if: inputs.output-format == 'apk'
uses: https://github.com/actions/upload-artifact@v3 uses: https://gitea.com/actions/upload-artifact@v3
with: with:
name: ${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-${{ inputs.build-type }}-apk name: ${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-${{ inputs.build-type }}-apk
path: android/app/build/outputs/apk/${{ inputs.build-type }}/${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-${{ inputs.build-type }}.apk path: android/app/build/outputs/apk/${{ inputs.build-type }}/${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-${{ inputs.build-type }}.apk
@@ -153,7 +153,7 @@ jobs:
- name: Upload AAB artifact - name: Upload AAB artifact
if: inputs.output-format == 'aab' if: inputs.output-format == 'aab'
uses: https://github.com/actions/upload-artifact@v3 uses: https://gitea.com/actions/upload-artifact@v3
with: with:
name: ${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-release-aab name: ${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-release-aab
path: android/app/build/outputs/bundle/release/${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-release.aab path: android/app/build/outputs/bundle/release/${{ steps.app-info.outputs.name }}-${{ steps.app-info.outputs.version }}-release.aab
@@ -161,7 +161,7 @@ jobs:
- name: Upload Gradle build reports - name: Upload Gradle build reports
if: always() if: always()
uses: https://github.com/actions/upload-artifact@v3 uses: https://gitea.com/actions/upload-artifact@v3
with: with:
name: gradle-build-reports name: gradle-build-reports
path: android/build/reports/ path: android/build/reports/
@@ -0,0 +1,68 @@
name: Dependency Audit
on:
workflow_call:
inputs:
node-version:
type: string
default: '24.16.0'
workflow_dispatch:
jobs:
dependency-audit:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Node.js
uses: https://github.com/actions/setup-node@v4
with:
node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Cache npm
uses: https://github.com/actions/cache@v4
with:
path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
restore-keys: |
${{ runner.os }}-node-
- name: Configure npm private registry
run: |
echo "@pzeta:registry=https://gitea.pzetatouch.it/api/packages/pzeta_touch/npm/" >> ~/.npmrc
echo "//gitea.pzetatouch.it/api/packages/pzeta_touch/npm/:_authToken=${{ secrets.NPM_TOKEN }}" >> ~/.npmrc
- name: Install dependencies
run: npm ci
- name: Security audit
id: audit
run: |
npm audit --audit-level=high --json > audit.json 2>/dev/null || true
VULNS=$(jq '(.metadata.vulnerabilities.high // 0) + (.metadata.vulnerabilities.critical // 0)' audit.json 2>/dev/null || echo "0")
echo "vulnerabilities=$VULNS" >> $GITHUB_OUTPUT
- name: Open issue if vulnerabilities found
if: steps.audit.outputs.vulnerabilities != '0'
env:
GITEA_TOKEN: ${{ gitea.token }}
SERVER_URL: ${{ gitea.server_url }}
REPOSITORY: ${{ gitea.repository }}
run: |
VULNS="${{ steps.audit.outputs.vulnerabilities }}"
DATE=$(date '+%Y-%m-%d')
VULN_LIST=$(jq -r '.vulnerabilities | to_entries[] | "- \(.key): \(.value.severity)"' audit.json 2>/dev/null | head -20 || echo "N/A")
printf '## Security Audit — %s\n\n### Vulnerabilità (high/critical): %s\n\n```\n%s\n```\n' \
"$DATE" "$VULNS" "$VULN_LIST" > /tmp/body.md
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues" \
-d "{
\"title\": \"[$DATE] Security: $VULNS vulnerabilità high/critical\",
\"body\": $(jq -Rs . /tmp/body.md)
}"
+4 -4
View File
@@ -5,7 +5,7 @@ on:
inputs: inputs:
node-version: node-version:
type: string type: string
default: '22.17' default: '24.16.0'
workflow_dispatch: workflow_dispatch:
jobs: jobs:
@@ -13,15 +13,15 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Node.js - name: Setup Node.js
uses: https://gitea.com/actions/setup-node@v4 uses: https://gitea.com/actions/setup-node@v4
with: with:
node-version: ${{ inputs.node-version || '22.17' }} node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Cache npm - name: Cache npm
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.npm path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }} key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
@@ -0,0 +1,68 @@
name: Dependency Outdated
on:
workflow_call:
inputs:
node-version:
type: string
default: '24.16.0'
workflow_dispatch:
jobs:
dependency-outdated:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Node.js
uses: https://github.com/actions/setup-node@v4
with:
node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Cache npm
uses: https://github.com/actions/cache@v4
with:
path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
restore-keys: |
${{ runner.os }}-node-
- name: Configure npm private registry
run: |
echo "@pzeta:registry=https://gitea.pzetatouch.it/api/packages/pzeta_touch/npm/" >> ~/.npmrc
echo "//gitea.pzetatouch.it/api/packages/pzeta_touch/npm/:_authToken=${{ secrets.NPM_TOKEN }}" >> ~/.npmrc
- name: Install dependencies
run: npm ci
- name: Check outdated packages
id: outdated
run: |
npm outdated --json > outdated.json 2>/dev/null || true
OUTDATED=$(jq 'keys | length' outdated.json 2>/dev/null || echo "0")
echo "count=$OUTDATED" >> $GITHUB_OUTPUT
- name: Open issue if packages outdated
if: steps.outdated.outputs.count != '0'
env:
GITEA_TOKEN: ${{ gitea.token }}
SERVER_URL: ${{ gitea.server_url }}
REPOSITORY: ${{ gitea.repository }}
run: |
OUTDATED="${{ steps.outdated.outputs.count }}"
DATE=$(date '+%Y-%m-%d')
OUTDATED_LIST=$(jq -r 'to_entries[] | "- \(.key): \(.value.current) → \(.value.latest)"' outdated.json 2>/dev/null | head -20 || echo "N/A")
printf '## Dipendenze Obsolete — %s\n\n### Pacchetti da aggiornare: %s\n\n```\n%s\n```\n' \
"$DATE" "$OUTDATED" "$OUTDATED_LIST" > /tmp/body.md
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues" \
-d "{
\"title\": \"[$DATE] Dipendenze: $OUTDATED pacchetti obsoleti\",
\"body\": $(jq -Rs . /tmp/body.md)
}"
+4 -4
View File
@@ -5,7 +5,7 @@ on:
inputs: inputs:
node-version: node-version:
type: string type: string
default: '22.17' default: '24.16.0'
workflow_dispatch: workflow_dispatch:
jobs: jobs:
@@ -13,15 +13,15 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Node.js - name: Setup Node.js
uses: https://gitea.com/actions/setup-node@v4 uses: https://gitea.com/actions/setup-node@v4
with: with:
node-version: ${{ inputs.node-version || '22.17' }} node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Cache npm - name: Cache npm
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.npm path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }} key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
@@ -0,0 +1,99 @@
name: Docker Release
on:
workflow_call:
inputs:
node-version:
type: string
default: '24.16.0'
npm-version:
type: string
default: ''
runner:
type: string
default: 'catthehacker-latest'
jobs:
docker-release:
runs-on: ${{ inputs.runner }}
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Node.js
uses: https://github.com/actions/setup-node@v4
with:
node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Upgrade npm
if: inputs.npm-version != ''
run: npm install -g npm@${{ inputs.npm-version }}
- name: Cache npm
uses: https://github.com/actions/cache@v4
with:
path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
restore-keys: |
${{ runner.os }}-node-
- name: Configure npm private registry
run: |
echo "@pzeta:registry=https://gitea.pzetatouch.it/api/packages/pzeta_touch/npm/" >> ~/.npmrc
echo "//gitea.pzetatouch.it/api/packages/pzeta_touch/npm/:_authToken=${{ secrets.NPM_TOKEN }}" >> ~/.npmrc
- name: Install dependencies
run: npm ci
- name: Type check
run: npm run typecheck
- name: Lint
run: npm run lint:check
- name: Format check
run: npm run format:check
- name: Build
run: npm run build
- name: Test
run: npm run test
- name: Login to container registry
uses: https://github.com/docker/login-action@v4
with:
registry: gitea.pzetatouch.it
username: ${{ secrets.G_USER }}
password: ${{ secrets.NPM_TOKEN }}
- name: Determine image tags
id: tags
run: |
RAW_NAME=$(jq -r '.name' package.json)
APP_NAME=$(echo "$RAW_NAME" | sed 's|^@[^/]*/||')
VERSION=$(jq -r '.version' package.json)
REGISTRY="gitea.pzetatouch.it/pzeta_touch"
echo "version_tag=${REGISTRY}/${APP_NAME}:${VERSION}" >> $GITHUB_OUTPUT
echo "latest_tag=${REGISTRY}/${APP_NAME}:latest" >> $GITHUB_OUTPUT
echo "version=${VERSION}" >> $GITHUB_OUTPUT
- name: Build and push Docker image
uses: https://github.com/docker/build-push-action@v6
with:
push: true
context: .
file: ./Dockerfile
tags: |
${{ steps.tags.outputs.version_tag }}
${{ steps.tags.outputs.latest_tag }}
labels: |
org.opencontainers.image.source=${{ gitea.server_url }}/${{ gitea.repository }}
org.opencontainers.image.revision=${{ gitea.sha }}
org.opencontainers.image.version=${{ steps.tags.outputs.version }}
build-args: |
NODE_VERSION=${{ vars.NODE_DOCKER_VERSION || '24.16.0-alpine3.22' }}
NGINX_VERSION=${{ vars.NGINX_DOCKER_VERSION || '1.30.2-alpine3.23' }}
NPM_VERSION=${{ vars.NPM_VERSION || '11.16.0' }}
secrets: |
npm_token=${{ secrets.NPM_TOKEN }}
+22 -6
View File
@@ -5,7 +5,10 @@ on:
inputs: inputs:
node-version: node-version:
type: string type: string
default: '22.17' default: '24.16.0'
npm-version:
type: string
default: ''
runner: runner:
type: string type: string
default: 'catthehacker-latest' default: 'catthehacker-latest'
@@ -15,15 +18,19 @@ jobs:
runs-on: ${{ inputs.runner }} runs-on: ${{ inputs.runner }}
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Node.js - name: Setup Node.js
uses: https://gitea.com/actions/setup-node@v4 uses: https://gitea.com/actions/setup-node@v4
with: with:
node-version: ${{ inputs.node-version || '22.17' }} node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Upgrade npm
if: inputs.npm-version != ''
run: npm install -g npm@${{ inputs.npm-version }}
- name: Cache npm - name: Cache npm
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.npm path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }} key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
@@ -54,7 +61,7 @@ jobs:
run: npm run test run: npm run test
- name: Login to container registry - name: Login to container registry
uses: https://gitea.com/docker/login-action@v3 uses: https://gitea.com/docker/login-action@v4
with: with:
registry: gitea.pzetatouch.it registry: gitea.pzetatouch.it
username: ${{ secrets.G_USER }} username: ${{ secrets.G_USER }}
@@ -69,6 +76,7 @@ jobs:
REGISTRY="gitea.pzetatouch.it/pzeta_touch" REGISTRY="gitea.pzetatouch.it/pzeta_touch"
echo "version_tag=${REGISTRY}/${APP_NAME}:${VERSION}" >> $GITHUB_OUTPUT echo "version_tag=${REGISTRY}/${APP_NAME}:${VERSION}" >> $GITHUB_OUTPUT
echo "latest_tag=${REGISTRY}/${APP_NAME}:latest" >> $GITHUB_OUTPUT echo "latest_tag=${REGISTRY}/${APP_NAME}:latest" >> $GITHUB_OUTPUT
echo "version=${VERSION}" >> $GITHUB_OUTPUT
- name: Build and push Docker image - name: Build and push Docker image
uses: https://gitea.com/docker/build-push-action@v6 uses: https://gitea.com/docker/build-push-action@v6
@@ -79,5 +87,13 @@ jobs:
tags: | tags: |
${{ steps.tags.outputs.version_tag }} ${{ steps.tags.outputs.version_tag }}
${{ steps.tags.outputs.latest_tag }} ${{ steps.tags.outputs.latest_tag }}
labels: |
org.opencontainers.image.source=${{ gitea.server_url }}/${{ gitea.repository }}
org.opencontainers.image.revision=${{ gitea.sha }}
org.opencontainers.image.version=${{ steps.tags.outputs.version }}
build-args: | build-args: |
NPM_TOKEN=${{ secrets.NPM_TOKEN }} NODE_VERSION=${{ vars.NODE_DOCKER_VERSION || '24.16.0-alpine3.22' }}
NGINX_VERSION=${{ vars.NGINX_DOCKER_VERSION || '1.30.2-alpine3.23' }}
NPM_VERSION=${{ vars.NPM_VERSION || '11.16.0' }}
secrets: |
npm_token=${{ secrets.NPM_TOKEN }}
+54
View File
@@ -0,0 +1,54 @@
name: Publish npm Package
on:
workflow_call:
inputs:
node-version:
type: string
default: '24.16.0'
jobs:
npm-publish:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Node.js
uses: https://github.com/actions/setup-node@v4
with:
node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Cache npm
uses: https://github.com/actions/cache@v4
with:
path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
restore-keys: |
${{ runner.os }}-node-
- name: Configure npm private registry
run: |
echo "@pzeta:registry=https://gitea.pzetatouch.it/api/packages/pzeta_touch/npm/" >> ~/.npmrc
echo "//gitea.pzetatouch.it/api/packages/pzeta_touch/npm/:_authToken=${{ secrets.NPM_TOKEN }}" >> ~/.npmrc
- name: Install dependencies
run: npm ci
- name: Lint
run: npm run lint:check
- name: Type check
run: npm run typecheck
- name: Format check
run: npm run format:check
- name: Build
run: npm run build
- name: Test
run: npm run test
- name: Publish
run: npm publish
+4 -4
View File
@@ -5,22 +5,22 @@ on:
inputs: inputs:
node-version: node-version:
type: string type: string
default: '22.17' default: '24.16.0'
jobs: jobs:
npm-publish: npm-publish:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Node.js - name: Setup Node.js
uses: https://gitea.com/actions/setup-node@v4 uses: https://gitea.com/actions/setup-node@v4
with: with:
node-version: ${{ inputs.node-version || '22.17' }} node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Cache npm - name: Cache npm
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.npm path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }} key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
@@ -0,0 +1,70 @@
name: Python Auto Release
on:
workflow_call:
inputs:
working-directory:
description: 'Directory di lavoro se il progetto non è in root'
type: string
default: '.'
jobs:
python-auto-release:
runs-on: ubuntu-latest
defaults:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
with:
fetch-depth: 0
token: ${{ gitea.token }}
- name: Generate changelog
id: changelog
run: |
CURRENT_TAG=${GITHUB_REF#refs/tags/}
PREV_TAG=$(git tag --sort=-version:refname | sed -n '2p')
if [ -z "$PREV_TAG" ]; then
CHANGELOG=$(git log --pretty=format:"- %s (%h)" "$CURRENT_TAG")
else
CHANGELOG=$(git log --pretty=format:"- %s (%h)" "${PREV_TAG}..${CURRENT_TAG}")
fi
echo "$CHANGELOG" > /tmp/changelog.txt
echo "current_tag=$CURRENT_TAG" >> $GITHUB_OUTPUT
- name: Read app name from pyproject.toml
id: app-info
run: |
APP_NAME=$(python3 -c "
import re, pathlib
content = pathlib.Path('pyproject.toml').read_text()
m = re.search(r'^name\s*=\s*[\"\'](.*?)[\"\']', content, re.MULTILINE)
print(m.group(1) if m else 'app')
" 2>/dev/null || echo 'app')
echo "name=$APP_NAME" >> $GITHUB_OUTPUT
- name: Create release
env:
GITEA_TOKEN: ${{ gitea.token }}
SERVER_URL: ${{ gitea.server_url }}
REPOSITORY: ${{ gitea.repository }}
run: |
CURRENT_TAG=${{ steps.changelog.outputs.current_tag }}
APP_NAME=${{ steps.app-info.outputs.name }}
CHANGELOG=$(cat /tmp/changelog.txt)
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/releases" \
-d "{
\"tag_name\": \"$CURRENT_TAG\",
\"name\": \"$APP_NAME $CURRENT_TAG\",
\"body\": $(echo "$CHANGELOG" | jq -Rs .),
\"draft\": false,
\"prerelease\": false
}"
+2 -1
View File
@@ -16,9 +16,10 @@ jobs:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
with: with:
fetch-depth: 0 fetch-depth: 0
token: ${{ gitea.token }}
- name: Generate changelog - name: Generate changelog
id: changelog id: changelog
@@ -0,0 +1,120 @@
name: Python Dependency Audit
on:
workflow_call:
inputs:
python-version:
type: string
default: '3.11'
install-extras:
type: string
default: 'dev'
working-directory:
type: string
default: '.'
workflow_dispatch:
jobs:
python-dependency-audit:
runs-on: ubuntu-latest
defaults:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Python
uses: https://github.com/actions/setup-python@v5.2.0
with:
python-version: ${{ inputs.python-version || '3.11' }}
- name: Cache pip
uses: https://github.com/actions/cache@v4
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }}
restore-keys: |
${{ runner.os }}-pip-${{ inputs.python-version }}-
${{ runner.os }}-pip-
- name: Install dependencies (isolated venv)
run: |
# venv pulita: audita SOLO le dipendenze dichiarate dal repo,
# non l'ambiente globale del runner (che su runner ML/GPU è contaminato)
python -m venv .audit-venv
.audit-venv/bin/pip install --upgrade pip pip-audit
if [ -n "${{ inputs.install-extras }}" ]; then
.audit-venv/bin/pip install -e ".[${{ inputs.install-extras }}]"
elif [ -f requirements.txt ]; then
.audit-venv/bin/pip install -r requirements.txt
else
.audit-venv/bin/pip install -e "."
fi
- name: Security audit (pip-audit)
id: audit
run: |
.audit-venv/bin/pip-audit --format=json --output=audit.json 2>/dev/null || true
VULNS=$(python3 -c "
import json, sys
try:
data = json.load(open('audit.json'))
deps = data.get('dependencies', [])
count = sum(len(d.get('vulns', [])) for d in deps)
print(count)
except Exception:
print(0)
")
echo "vulnerabilities=$VULNS" >> $GITHUB_OUTPUT
- name: Open or update issue if vulnerabilities found
if: steps.audit.outputs.vulnerabilities != '0'
env:
GITEA_TOKEN: ${{ gitea.token }}
SERVER_URL: ${{ gitea.server_url }}
REPOSITORY: ${{ gitea.repository }}
run: |
VULNS="${{ steps.audit.outputs.vulnerabilities }}"
DATE=$(date '+%Y-%m-%d')
TITLE_PREFIX="Security Python:"
VULN_LIST=$(python3 -c "
import json
try:
data = json.load(open('audit.json'))
lines = []
for dep in data.get('dependencies', []):
for v in dep.get('vulns', []):
lines.append(f\"- {dep['name']} {dep.get('version','?')}: {v.get('id','?')} ({v.get('description','')[:80]})\")
print('\n'.join(lines[:20]))
except Exception:
print('N/A')
")
printf '## Security Audit Python — %s\n\n### Vulnerabilità trovate: %s\n\n```\n%s\n```\n' \
"$DATE" "$VULNS" "$VULN_LIST" > /tmp/body.md
# Deduplica: se esiste già una issue aperta con lo stesso prefisso,
# aggiungi un commento invece di aprirne una nuova
EXISTING=$(curl -s \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues?state=open&type=issues&limit=50" \
| jq -r --arg p "$TITLE_PREFIX" '[.[] | select(.title | contains($p))] | (first // {}) | .number // empty')
if [ -n "$EXISTING" ]; then
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues/$EXISTING/comments" \
-d "{ \"body\": $(jq -Rs . /tmp/body.md) }"
else
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues" \
-d "{
\"title\": \"[$DATE] Security Python: $VULNS vulnerabilità rilevate\",
\"body\": $(jq -Rs . /tmp/body.md)
}"
fi
+36 -17
View File
@@ -22,15 +22,15 @@ jobs:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Python - name: Setup Python
uses: https://github.com/actions/setup-python@v5 uses: https://github.com/actions/setup-python@v5.2.0
with: with:
python-version: ${{ inputs.python-version || '3.11' }} python-version: ${{ inputs.python-version || '3.11' }}
- name: Cache pip - name: Cache pip
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.cache/pip path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }} key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }}
@@ -38,21 +38,24 @@ jobs:
${{ runner.os }}-pip-${{ inputs.python-version }}- ${{ runner.os }}-pip-${{ inputs.python-version }}-
${{ runner.os }}-pip- ${{ runner.os }}-pip-
- name: Install dependencies - name: Install dependencies (isolated venv)
run: | run: |
python -m pip install --upgrade pip pip-audit # venv pulita: audita SOLO le dipendenze dichiarate dal repo,
# non l'ambiente globale del runner (che su runner ML/GPU è contaminato)
python -m venv .audit-venv
.audit-venv/bin/pip install --upgrade pip pip-audit
if [ -n "${{ inputs.install-extras }}" ]; then if [ -n "${{ inputs.install-extras }}" ]; then
pip install -e ".[${{ inputs.install-extras }}]" .audit-venv/bin/pip install -e ".[${{ inputs.install-extras }}]"
elif [ -f requirements.txt ]; then elif [ -f requirements.txt ]; then
pip install -r requirements.txt .audit-venv/bin/pip install -r requirements.txt
else else
pip install -e "." .audit-venv/bin/pip install -e "."
fi fi
- name: Security audit (pip-audit) - name: Security audit (pip-audit)
id: audit id: audit
run: | run: |
pip-audit --format=json --output=audit.json 2>/dev/null || true .audit-venv/bin/pip-audit --format=json --output=audit.json 2>/dev/null || true
VULNS=$(python3 -c " VULNS=$(python3 -c "
import json, sys import json, sys
try: try:
@@ -65,7 +68,7 @@ jobs:
") ")
echo "vulnerabilities=$VULNS" >> $GITHUB_OUTPUT echo "vulnerabilities=$VULNS" >> $GITHUB_OUTPUT
- name: Open issue if vulnerabilities found - name: Open or update issue if vulnerabilities found
if: steps.audit.outputs.vulnerabilities != '0' if: steps.audit.outputs.vulnerabilities != '0'
env: env:
GITEA_TOKEN: ${{ gitea.token }} GITEA_TOKEN: ${{ gitea.token }}
@@ -74,6 +77,7 @@ jobs:
run: | run: |
VULNS="${{ steps.audit.outputs.vulnerabilities }}" VULNS="${{ steps.audit.outputs.vulnerabilities }}"
DATE=$(date '+%Y-%m-%d') DATE=$(date '+%Y-%m-%d')
TITLE_PREFIX="Security Python:"
VULN_LIST=$(python3 -c " VULN_LIST=$(python3 -c "
import json import json
@@ -91,11 +95,26 @@ jobs:
printf '## Security Audit Python — %s\n\n### Vulnerabilità trovate: %s\n\n```\n%s\n```\n' \ printf '## Security Audit Python — %s\n\n### Vulnerabilità trovate: %s\n\n```\n%s\n```\n' \
"$DATE" "$VULNS" "$VULN_LIST" > /tmp/body.md "$DATE" "$VULNS" "$VULN_LIST" > /tmp/body.md
curl -s -X POST \ # Deduplica: se esiste già una issue aperta con lo stesso prefisso,
-H "Content-Type: application/json" \ # aggiungi un commento invece di aprirne una nuova
EXISTING=$(curl -s \
-H "Authorization: token $GITEA_TOKEN" \ -H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues" \ "$SERVER_URL/api/v1/repos/$REPOSITORY/issues?state=open&type=issues&limit=50" \
-d "{ | jq -r --arg p "$TITLE_PREFIX" '[.[] | select(.title | contains($p))] | (first // {}) | .number // empty')
\"title\": \"[$DATE] Security Python: $VULNS vulnerabilità rilevate\",
\"body\": $(jq -Rs . /tmp/body.md) if [ -n "$EXISTING" ]; then
}" curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues/$EXISTING/comments" \
-d "{ \"body\": $(jq -Rs . /tmp/body.md) }"
else
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues" \
-d "{
\"title\": \"[$DATE] Security Python: $VULNS vulnerabilità rilevate\",
\"body\": $(jq -Rs . /tmp/body.md)
}"
fi
@@ -0,0 +1,108 @@
name: Python Dependency Outdated
on:
workflow_call:
inputs:
python-version:
type: string
default: '3.11'
install-extras:
type: string
default: 'dev'
working-directory:
type: string
default: '.'
workflow_dispatch:
jobs:
python-dependency-outdated:
runs-on: ubuntu-latest
defaults:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Python
uses: https://github.com/actions/setup-python@v5.2.0
with:
python-version: ${{ inputs.python-version || '3.11' }}
- name: Cache pip
uses: https://github.com/actions/cache@v4
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }}
restore-keys: |
${{ runner.os }}-pip-${{ inputs.python-version }}-
${{ runner.os }}-pip-
- name: Install dependencies (isolated venv)
run: |
# venv pulita: elenca come obsolete SOLO le dipendenze dichiarate dal repo,
# non i pacchetti globali del runner (torch/cuda/nvidia su runner ML/GPU)
python -m venv .audit-venv
.audit-venv/bin/pip install --upgrade pip
if [ -n "${{ inputs.install-extras }}" ]; then
.audit-venv/bin/pip install -e ".[${{ inputs.install-extras }}]"
elif [ -f requirements.txt ]; then
.audit-venv/bin/pip install -r requirements.txt
else
.audit-venv/bin/pip install -e "."
fi
- name: Check outdated packages
id: outdated
run: |
.audit-venv/bin/pip list --outdated --format=json > outdated.json 2>/dev/null || echo '[]' > outdated.json
COUNT=$(python3 -c "import json; print(len(json.load(open('outdated.json'))))")
echo "count=$COUNT" >> $GITHUB_OUTPUT
- name: Open or update issue if packages outdated
if: steps.outdated.outputs.count != '0'
env:
GITEA_TOKEN: ${{ gitea.token }}
SERVER_URL: ${{ gitea.server_url }}
REPOSITORY: ${{ gitea.repository }}
run: |
COUNT="${{ steps.outdated.outputs.count }}"
DATE=$(date '+%Y-%m-%d')
TITLE_PREFIX="Dipendenze Python:"
OUTDATED_LIST=$(python3 -c "
import json
try:
data = json.load(open('outdated.json'))
lines = [f\"- {p['name']}: {p['version']} → {p['latest_version']}\" for p in data[:20]]
print('\n'.join(lines))
except Exception:
print('N/A')
")
printf '## Dipendenze Python Obsolete — %s\n\n### Pacchetti da aggiornare: %s\n\n```\n%s\n```\n' \
"$DATE" "$COUNT" "$OUTDATED_LIST" > /tmp/body.md
# Deduplica: se esiste già una issue aperta con lo stesso prefisso,
# aggiungi un commento invece di aprirne una nuova
EXISTING=$(curl -s \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues?state=open&type=issues&limit=50" \
| jq -r --arg p "$TITLE_PREFIX" '[.[] | select(.title | contains($p))] | (first // {}) | .number // empty')
if [ -n "$EXISTING" ]; then
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues/$EXISTING/comments" \
-d "{ \"body\": $(jq -Rs . /tmp/body.md) }"
else
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues" \
-d "{
\"title\": \"[$DATE] Dipendenze Python: $COUNT pacchetti obsoleti\",
\"body\": $(jq -Rs . /tmp/body.md)
}"
fi
+36 -17
View File
@@ -22,15 +22,15 @@ jobs:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Python - name: Setup Python
uses: https://github.com/actions/setup-python@v5 uses: https://github.com/actions/setup-python@v5.2.0
with: with:
python-version: ${{ inputs.python-version || '3.11' }} python-version: ${{ inputs.python-version || '3.11' }}
- name: Cache pip - name: Cache pip
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.cache/pip path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }} key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }}
@@ -38,25 +38,28 @@ jobs:
${{ runner.os }}-pip-${{ inputs.python-version }}- ${{ runner.os }}-pip-${{ inputs.python-version }}-
${{ runner.os }}-pip- ${{ runner.os }}-pip-
- name: Install dependencies - name: Install dependencies (isolated venv)
run: | run: |
python -m pip install --upgrade pip # venv pulita: elenca come obsolete SOLO le dipendenze dichiarate dal repo,
# non i pacchetti globali del runner (torch/cuda/nvidia su runner ML/GPU)
python -m venv .audit-venv
.audit-venv/bin/pip install --upgrade pip
if [ -n "${{ inputs.install-extras }}" ]; then if [ -n "${{ inputs.install-extras }}" ]; then
pip install -e ".[${{ inputs.install-extras }}]" .audit-venv/bin/pip install -e ".[${{ inputs.install-extras }}]"
elif [ -f requirements.txt ]; then elif [ -f requirements.txt ]; then
pip install -r requirements.txt .audit-venv/bin/pip install -r requirements.txt
else else
pip install -e "." .audit-venv/bin/pip install -e "."
fi fi
- name: Check outdated packages - name: Check outdated packages
id: outdated id: outdated
run: | run: |
pip list --outdated --format=json > outdated.json 2>/dev/null || echo '[]' > outdated.json .audit-venv/bin/pip list --outdated --format=json > outdated.json 2>/dev/null || echo '[]' > outdated.json
COUNT=$(python3 -c "import json; print(len(json.load(open('outdated.json'))))") COUNT=$(python3 -c "import json; print(len(json.load(open('outdated.json'))))")
echo "count=$COUNT" >> $GITHUB_OUTPUT echo "count=$COUNT" >> $GITHUB_OUTPUT
- name: Open issue if packages outdated - name: Open or update issue if packages outdated
if: steps.outdated.outputs.count != '0' if: steps.outdated.outputs.count != '0'
env: env:
GITEA_TOKEN: ${{ gitea.token }} GITEA_TOKEN: ${{ gitea.token }}
@@ -65,6 +68,7 @@ jobs:
run: | run: |
COUNT="${{ steps.outdated.outputs.count }}" COUNT="${{ steps.outdated.outputs.count }}"
DATE=$(date '+%Y-%m-%d') DATE=$(date '+%Y-%m-%d')
TITLE_PREFIX="Dipendenze Python:"
OUTDATED_LIST=$(python3 -c " OUTDATED_LIST=$(python3 -c "
import json import json
@@ -79,11 +83,26 @@ jobs:
printf '## Dipendenze Python Obsolete — %s\n\n### Pacchetti da aggiornare: %s\n\n```\n%s\n```\n' \ printf '## Dipendenze Python Obsolete — %s\n\n### Pacchetti da aggiornare: %s\n\n```\n%s\n```\n' \
"$DATE" "$COUNT" "$OUTDATED_LIST" > /tmp/body.md "$DATE" "$COUNT" "$OUTDATED_LIST" > /tmp/body.md
curl -s -X POST \ # Deduplica: se esiste già una issue aperta con lo stesso prefisso,
-H "Content-Type: application/json" \ # aggiungi un commento invece di aprirne una nuova
EXISTING=$(curl -s \
-H "Authorization: token $GITEA_TOKEN" \ -H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues" \ "$SERVER_URL/api/v1/repos/$REPOSITORY/issues?state=open&type=issues&limit=50" \
-d "{ | jq -r --arg p "$TITLE_PREFIX" '[.[] | select(.title | contains($p))] | (first // {}) | .number // empty')
\"title\": \"[$DATE] Dipendenze Python: $COUNT pacchetti obsoleti\",
\"body\": $(jq -Rs . /tmp/body.md) if [ -n "$EXISTING" ]; then
}" curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues/$EXISTING/comments" \
-d "{ \"body\": $(jq -Rs . /tmp/body.md) }"
else
curl -s -X POST \
-H "Content-Type: application/json" \
-H "Authorization: token $GITEA_TOKEN" \
"$SERVER_URL/api/v1/repos/$REPOSITORY/issues" \
-d "{
\"title\": \"[$DATE] Dipendenze Python: $COUNT pacchetti obsoleti\",
\"body\": $(jq -Rs . /tmp/body.md)
}"
fi
@@ -0,0 +1,121 @@
name: Python Docker Release
on:
workflow_call:
inputs:
python-version:
type: string
default: '3.11'
install-extras:
description: 'Extras pip da installare (es: dev, test)'
type: string
default: 'dev'
runner:
type: string
default: 'catthehacker-latest'
working-directory:
description: 'Directory di lavoro se il progetto non è in root'
type: string
default: '.'
dockerfile:
description: 'Path al Dockerfile'
type: string
default: './Dockerfile'
jobs:
python-docker-release:
runs-on: ${{ inputs.runner }}
defaults:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Python
uses: https://github.com/actions/setup-python@v5.2.0
with:
python-version: ${{ inputs.python-version || '3.11' }}
- name: Cache pip
uses: https://github.com/actions/cache@v4
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }}
restore-keys: |
${{ runner.os }}-pip-${{ inputs.python-version }}-
${{ runner.os }}-pip-
- name: Install dependencies
run: |
python -m pip install --upgrade pip
if [ -n "${{ inputs.install-extras }}" ]; then
pip install -e ".[${{ inputs.install-extras }}]"
elif [ -f requirements-dev.txt ]; then
pip install -r requirements-dev.txt
elif [ -f requirements.txt ]; then
pip install -r requirements.txt
else
pip install -e "."
fi
- name: Lint (ruff)
run: ruff check .
- name: Format check (ruff)
run: ruff format --check .
- name: Type check (mypy)
run: mypy .
- name: Test (pytest)
run: pytest --tb=short -q
- name: Login to container registry
uses: https://github.com/docker/login-action@v4
with:
registry: gitea.pzetatouch.it
username: ${{ secrets.G_USER }}
password: ${{ secrets.NPM_TOKEN }}
- name: Determine image tags
id: tags
run: |
APP_NAME=$(python -c "
import tomllib, pathlib
data = tomllib.loads(pathlib.Path('pyproject.toml').read_text())
print(data['project']['name'])
" 2>/dev/null || python3 -c "
import re, pathlib
content = pathlib.Path('pyproject.toml').read_text()
m = re.search(r'^name\s*=\s*[\"\'](.*?)[\"\']', content, re.MULTILINE)
print(m.group(1) if m else 'unknown')
")
VERSION=$(python -c "
import tomllib, pathlib
data = tomllib.loads(pathlib.Path('pyproject.toml').read_text())
print(data['project']['version'])
" 2>/dev/null || python3 -c "
import re, pathlib
content = pathlib.Path('pyproject.toml').read_text()
m = re.search(r'^version\s*=\s*[\"\'](.*?)[\"\']', content, re.MULTILINE)
print(m.group(1) if m else '0.0.0')
")
REGISTRY="gitea.pzetatouch.it/pzeta_touch"
echo "version_tag=${REGISTRY}/${APP_NAME}:${VERSION}" >> $GITHUB_OUTPUT
echo "latest_tag=${REGISTRY}/${APP_NAME}:latest" >> $GITHUB_OUTPUT
echo "version=${VERSION}" >> $GITHUB_OUTPUT
- name: Build and push Docker image
uses: https://github.com/docker/build-push-action@v6
with:
push: true
context: ${{ inputs.working-directory }}
file: ${{ inputs.dockerfile }}
tags: |
${{ steps.tags.outputs.version_tag }}
${{ steps.tags.outputs.latest_tag }}
labels: |
org.opencontainers.image.source=${{ gitea.server_url }}/${{ gitea.repository }}
org.opencontainers.image.revision=${{ gitea.sha }}
org.opencontainers.image.version=${{ steps.tags.outputs.version }}
+9 -4
View File
@@ -30,15 +30,15 @@ jobs:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Python - name: Setup Python
uses: https://github.com/actions/setup-python@v5 uses: https://github.com/actions/setup-python@v5.2.0
with: with:
python-version: ${{ inputs.python-version || '3.11' }} python-version: ${{ inputs.python-version || '3.11' }}
- name: Cache pip - name: Cache pip
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.cache/pip path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }} key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }}
@@ -72,7 +72,7 @@ jobs:
run: pytest --tb=short -q run: pytest --tb=short -q
- name: Login to container registry - name: Login to container registry
uses: https://gitea.com/docker/login-action@v3 uses: https://gitea.com/docker/login-action@v4
with: with:
registry: gitea.pzetatouch.it registry: gitea.pzetatouch.it
username: ${{ secrets.G_USER }} username: ${{ secrets.G_USER }}
@@ -104,6 +104,7 @@ jobs:
REGISTRY="gitea.pzetatouch.it/pzeta_touch" REGISTRY="gitea.pzetatouch.it/pzeta_touch"
echo "version_tag=${REGISTRY}/${APP_NAME}:${VERSION}" >> $GITHUB_OUTPUT echo "version_tag=${REGISTRY}/${APP_NAME}:${VERSION}" >> $GITHUB_OUTPUT
echo "latest_tag=${REGISTRY}/${APP_NAME}:latest" >> $GITHUB_OUTPUT echo "latest_tag=${REGISTRY}/${APP_NAME}:latest" >> $GITHUB_OUTPUT
echo "version=${VERSION}" >> $GITHUB_OUTPUT
- name: Build and push Docker image - name: Build and push Docker image
uses: https://gitea.com/docker/build-push-action@v6 uses: https://gitea.com/docker/build-push-action@v6
@@ -114,3 +115,7 @@ jobs:
tags: | tags: |
${{ steps.tags.outputs.version_tag }} ${{ steps.tags.outputs.version_tag }}
${{ steps.tags.outputs.latest_tag }} ${{ steps.tags.outputs.latest_tag }}
labels: |
org.opencontainers.image.source=${{ gitea.server_url }}/${{ gitea.repository }}
org.opencontainers.image.revision=${{ gitea.sha }}
org.opencontainers.image.version=${{ steps.tags.outputs.version }}
@@ -0,0 +1,65 @@
name: Python Quality Gates
on:
workflow_call:
inputs:
python-version:
type: string
default: '3.11'
install-extras:
description: 'Extras pip da installare (es: dev, test). Lasciare vuoto per solo requirements.txt'
type: string
default: 'dev'
working-directory:
description: 'Directory di lavoro se il progetto non è in root'
type: string
default: '.'
jobs:
python-quality-gates:
runs-on: ubuntu-latest
defaults:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Python
uses: https://github.com/actions/setup-python@v5.2.0
with:
python-version: ${{ inputs.python-version || '3.11' }}
- name: Cache pip
uses: https://github.com/actions/cache@v4
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }}
restore-keys: |
${{ runner.os }}-pip-${{ inputs.python-version }}-
${{ runner.os }}-pip-
- name: Install dependencies
run: |
python -m pip install --upgrade pip
if [ -n "${{ inputs.install-extras }}" ]; then
pip install -e ".[${{ inputs.install-extras }}]"
elif [ -f requirements-dev.txt ]; then
pip install -r requirements-dev.txt
elif [ -f requirements.txt ]; then
pip install -r requirements.txt
else
pip install -e "."
fi
- name: Lint (ruff)
run: ruff check .
- name: Format check (ruff)
run: ruff format --check .
- name: Type check (mypy)
run: mypy .
- name: Test (pytest)
run: pytest --tb=short -q
+3 -3
View File
@@ -23,15 +23,15 @@ jobs:
working-directory: ${{ inputs.working-directory }} working-directory: ${{ inputs.working-directory }}
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Python - name: Setup Python
uses: https://github.com/actions/setup-python@v5 uses: https://github.com/actions/setup-python@v5.2.0
with: with:
python-version: ${{ inputs.python-version || '3.11' }} python-version: ${{ inputs.python-version || '3.11' }}
- name: Cache pip - name: Cache pip
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.cache/pip path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }} key: ${{ runner.os }}-pip-${{ inputs.python-version }}-${{ hashFiles('**/pyproject.toml', '**/requirements*.txt') }}
+64
View File
@@ -0,0 +1,64 @@
name: Quality Gates
on:
workflow_call:
inputs:
node-version:
type: string
default: '24.16.0'
npm-version:
type: string
default: ''
jobs:
quality-gates:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: https://github.com/actions/checkout@v6
- name: Setup Node.js
uses: https://github.com/actions/setup-node@v4
with:
node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Upgrade npm
if: inputs.npm-version != ''
run: npm install -g npm@${{ inputs.npm-version }}
- name: Cache npm
uses: https://github.com/actions/cache@v4
with:
path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
restore-keys: |
${{ runner.os }}-node-
- name: Configure npm private registry
run: |
echo "@pzeta:registry=https://gitea.pzetatouch.it/api/packages/pzeta_touch/npm/" >> ~/.npmrc
echo "//gitea.pzetatouch.it/api/packages/pzeta_touch/npm/:_authToken=${{ secrets.NPM_TOKEN }}" >> ~/.npmrc
- name: Check outdated packages
run: npm outdated || true
- name: Install dependencies
run: npm ci
- name: Security audit
run: npm audit --audit-level=high || true
- name: Lint
run: npm run lint:check
- name: Type check
run: npm run typecheck
- name: Format check
run: npm run format:check
- name: Build
run: npm run build
- name: Test
run: npm run test
+11 -4
View File
@@ -5,22 +5,29 @@ on:
inputs: inputs:
node-version: node-version:
type: string type: string
default: '22.17' default: '24.16.0'
npm-version:
type: string
default: ''
jobs: jobs:
quality-gates: quality-gates:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: https://gitea.com/actions/checkout@v4 uses: https://gitea.com/actions/checkout@v6
- name: Setup Node.js - name: Setup Node.js
uses: https://gitea.com/actions/setup-node@v4 uses: https://gitea.com/actions/setup-node@v4
with: with:
node-version: ${{ inputs.node-version || '22.17' }} node-version: ${{ inputs.node-version || '24.16.0' }}
- name: Upgrade npm
if: inputs.npm-version != ''
run: npm install -g npm@${{ inputs.npm-version }}
- name: Cache npm - name: Cache npm
uses: https://gitea.com/actions/cache@v4 uses: https://github.com/actions/cache@v4
with: with:
path: ~/.npm path: ~/.npm
key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }} key: ${{ runner.os }}-node-${{ hashFiles('**/package-lock.json') }}
+30
View File
@@ -0,0 +1,30 @@
# Copia in: .gitea/workflows/ci.yml
# Trigger: push su qualsiasi branch → quality gates + build debug Android
#
# Il debug APK viene uplodato come artifact scaricabile dalla PR.
# Non richiede firma: usato per test interni su device fisico o emulatore.
name: CI
on:
push:
branches:
- main
paths-ignore:
- '**.md'
- 'docs/**'
pull_request:
branches:
- main
jobs:
quality-gates:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/quality-gates-github.yml@v1
secrets: inherit
android-debug:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/capacitor-android-github.yml@v1
secrets: inherit
with:
build-type: debug
output-format: apk
+2 -2
View File
@@ -19,11 +19,11 @@ on:
jobs: jobs:
quality-gates: quality-gates:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/quality-gates.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/quality-gates.yml@v1
secrets: inherit secrets: inherit
android-debug: android-debug:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/capacitor-android.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/capacitor-android.yml@v1
secrets: inherit secrets: inherit
with: with:
build-type: debug build-type: debug
+3 -3
View File
@@ -18,19 +18,19 @@ on:
jobs: jobs:
branch-cleanup: branch-cleanup:
if: gitea.event_name == 'pull_request' && gitea.event.pull_request.merged == true if: gitea.event_name == 'pull_request' && gitea.event.pull_request.merged == true
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/branch-cleanup.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/branch-cleanup.yml@v1
secrets: inherit secrets: inherit
dependency-audit: dependency-audit:
if: > if: >
gitea.event_name == 'workflow_dispatch' || gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 * * 1') (gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 * * 1')
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/dependency-check.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/dependency-check.yml@v1
secrets: inherit secrets: inherit
dependency-outdated: dependency-outdated:
if: > if: >
gitea.event_name == 'workflow_dispatch' || gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 1 * *') (gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 1 * *')
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/dependency-outdated.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/dependency-outdated.yml@v1
secrets: inherit secrets: inherit
+49
View File
@@ -0,0 +1,49 @@
# Copia in: .gitea/workflows/release.yml
# Trigger: git tag v* → APK firmato + AAB Play Store + release Gitea
#
# Secrets richiesti nel repository consumer:
# KEYSTORE_BASE64 — keystore codificato in base64
# KEYSTORE_PASSWORD — password del keystore
# KEY_ALIAS — alias della chiave
# KEY_PASSWORD — password della chiave
# GOOGLE_SERVICES_JSON — contenuto del file google-services.json (se Firebase)
#
# Prerequisito build.gradle (android/app/build.gradle):
# signingConfigs {
# release {
# storeFile file("keystore.jks")
# storePassword System.getenv("KEYSTORE_PASSWORD")
# keyAlias System.getenv("KEY_ALIAS")
# keyPassword System.getenv("KEY_PASSWORD")
# }
# }
#
# NOTA: gitea-release attende entrambe le build Android via needs.
# Workaround Gitea bug #31900: token esplicito nel checkout di auto-release.yml.
name: Release
on:
push:
tags:
- 'v*'
jobs:
android-apk:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/capacitor-android-github.yml@v1
secrets: inherit
with:
build-type: release
output-format: apk
android-aab:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/capacitor-android-github.yml@v1
secrets: inherit
with:
build-type: release
output-format: aab
gitea-release:
needs: [android-apk, android-aab]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/auto-release-github.yml@v1
secrets: inherit
+6 -5
View File
@@ -18,8 +18,8 @@
# } # }
# } # }
# #
# NOTA: i job girano in parallelo (no needs). # NOTA: gitea-release attende entrambe le build Android via needs.
# Gitea bug #31900: needs + workflow_call + checkout causa errori di autenticazione. # Workaround Gitea bug #31900: token esplicito nel checkout di auto-release.yml.
name: Release name: Release
@@ -30,19 +30,20 @@ on:
jobs: jobs:
android-apk: android-apk:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/capacitor-android.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/capacitor-android.yml@v1
secrets: inherit secrets: inherit
with: with:
build-type: release build-type: release
output-format: apk output-format: apk
android-aab: android-aab:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/capacitor-android.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/capacitor-android.yml@v1
secrets: inherit secrets: inherit
with: with:
build-type: release build-type: release
output-format: aab output-format: aab
gitea-release: gitea-release:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/auto-release.yml@v1 needs: [android-apk, android-aab]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/auto-release.yml@v1
secrets: inherit secrets: inherit
+26
View File
@@ -0,0 +1,26 @@
# Copia in: .gitea/workflows/ci.yml
# Usato da: siti documentazione Nuxt 4 con SSR e Docker
#
# Prerequisiti:
# - package.json con script: lint:check, typecheck, format:check, build, test
# - Secrets: NPM_TOKEN (accesso registry @pzeta privato)
name: CI
on:
push:
branches:
- main
paths-ignore:
- '**.md'
- 'content/**'
pull_request:
branches:
- main
jobs:
quality-gates:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/quality-gates-github.yml@v1
secrets: inherit
with:
npm-version: '11' # lockfile generato con npm@11, runner usa npm@10 di default
+26
View File
@@ -0,0 +1,26 @@
# Copia in: .gitea/workflows/ci.yml
# Usato da: siti documentazione Nuxt 4 con SSR e Docker
#
# Prerequisiti:
# - package.json con script: lint:check, typecheck, format:check, build, test
# - Secrets: NPM_TOKEN (accesso registry @pzeta privato)
name: CI
on:
push:
branches:
- main
paths-ignore:
- '**.md'
- 'content/**'
pull_request:
branches:
- main
jobs:
quality-gates:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/quality-gates.yml@v1
secrets: inherit
with:
npm-version: '11' # lockfile generato con npm@11, runner usa npm@10 di default
+36
View File
@@ -0,0 +1,36 @@
# Copia in: .gitea/workflows/maintenance.yml
# Trigger:
# - PR merged → cleanup branch sorgente
# - Ogni martedì 02:00 → security audit vulnerabilità (settimanale)
# - Ogni 1° del mese → controllo pacchetti obsoleti (mensile)
# - Manuale → workflow_dispatch (esegue tutti i job di manutenzione)
name: Maintenance
on:
pull_request:
types: [closed]
schedule:
- cron: '0 2 * * 2' # ogni martedì alle 02:00 → security audit
- cron: '0 3 1 * *' # ogni 1° del mese alle 03:00 → outdated check
workflow_dispatch:
jobs:
branch-cleanup:
if: gitea.event_name == 'pull_request' && gitea.event.pull_request.merged == true
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/branch-cleanup.yml@v1
secrets: inherit
dependency-audit:
if: >
gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 2 * * 2')
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/dependency-check.yml@v1
secrets: inherit
dependency-outdated:
if: >
gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 3 1 * *')
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/dependency-outdated.yml@v1
secrets: inherit
@@ -0,0 +1,30 @@
# Copia in: .gitea/workflows/release.yml
# Trigger: git tag v* → build Docker + crea release Gitea
#
# NOTA: auto-release attende docker-release via needs.
# Workaround Gitea bug #31900: token esplicito nel checkout di auto-release.yml.
#
# Secrets richiesti nel repository consumer:
# NPM_TOKEN — accesso registry @pzeta (npm install + Docker secret)
# G_USER — username Docker registry Gitea
name: Release
on:
push:
tags:
- 'v*'
jobs:
docker-release:
runs-on: catthehacker-latest # workaround Gitea bug #34986: runs-on non rispettato in workflow_call
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/docker-release-github.yml@v1
secrets: inherit
with:
runner: catthehacker-latest # runner con Docker pre-installato
npm-version: '11' # lockfile generato con npm@11, runner usa npm@10 di default
auto-release:
needs: [docker-release]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/auto-release-github.yml@v1
secrets: inherit
+30
View File
@@ -0,0 +1,30 @@
# Copia in: .gitea/workflows/release.yml
# Trigger: git tag v* → build Docker + crea release Gitea
#
# NOTA: auto-release attende docker-release via needs.
# Workaround Gitea bug #31900: token esplicito nel checkout di auto-release.yml.
#
# Secrets richiesti nel repository consumer:
# NPM_TOKEN — accesso registry @pzeta (npm install + Docker secret)
# G_USER — username Docker registry Gitea
name: Release
on:
push:
tags:
- 'v*'
jobs:
docker-release:
runs-on: catthehacker-latest # workaround Gitea bug #34986: runs-on non rispettato in workflow_call
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/docker-release.yml@v1
secrets: inherit
with:
runner: catthehacker-latest # runner con Docker pre-installato
npm-version: '11' # lockfile generato con npm@11, runner usa npm@10 di default
auto-release:
needs: [docker-release]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/auto-release.yml@v1
secrets: inherit
+20
View File
@@ -0,0 +1,20 @@
# Copia in: .gitea/workflows/ci.yml
# Usato da: librerie npm pubblicate su registry @pzeta
name: CI
on:
push:
branches:
- main
paths-ignore:
- '**.md'
- 'docs/**'
pull_request:
branches:
- main
jobs:
quality-gates:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/quality-gates-github.yml@v1
secrets: inherit
+1 -1
View File
@@ -16,5 +16,5 @@ on:
jobs: jobs:
quality-gates: quality-gates:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/quality-gates.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/quality-gates.yml@v1
secrets: inherit secrets: inherit
+20 -6
View File
@@ -1,5 +1,9 @@
# Copia in: .gitea/workflows/maintenance.yml # Copia in: .gitea/workflows/maintenance.yml
# Combina branch-cleanup (PR merge) e dependency-check (settimanale) # Trigger:
# - PR merged → cleanup branch sorgente
# - Ogni lunedì 08:00 → security audit vulnerabilità (settimanale)
# - Ogni 1° del mese → controllo pacchetti obsoleti (mensile)
# - Manuale → workflow_dispatch (esegue tutti i job di manutenzione)
name: Maintenance name: Maintenance
@@ -7,16 +11,26 @@ on:
pull_request: pull_request:
types: [closed] types: [closed]
schedule: schedule:
- cron: '0 8 * * 1' - cron: '0 2 * * 3' # ogni mercoledì alle 02:00 → security audit
- cron: '0 2 1 * *' # ogni 1° del mese alle 02:00 → outdated check
workflow_dispatch: workflow_dispatch:
jobs: jobs:
branch-cleanup: branch-cleanup:
if: gitea.event_name == 'pull_request' && gitea.event.pull_request.merged == true if: gitea.event_name == 'pull_request' && gitea.event.pull_request.merged == true
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/branch-cleanup.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/branch-cleanup.yml@v1
secrets: inherit secrets: inherit
dependency-check: dependency-audit:
if: gitea.event_name == 'schedule' || gitea.event_name == 'workflow_dispatch' if: >
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/dependency-check.yml@v1 gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 2 * * 3')
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/dependency-check.yml@v1
secrets: inherit
dependency-outdated:
if: >
gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 2 1 * *')
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/dependency-outdated.yml@v1
secrets: inherit secrets: inherit
+22
View File
@@ -0,0 +1,22 @@
# Copia in: .gitea/workflows/release.yml
# Trigger: git tag v* → pubblica su npm + crea release Gitea
#
# NOTA: auto-release attende npm-publish via needs.
# Workaround Gitea bug #31900: token esplicito nel checkout di auto-release.yml.
name: Release
on:
push:
tags:
- 'v*'
jobs:
npm-publish:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/npm-publish-github.yml@v1
secrets: inherit
auto-release:
needs: [npm-publish]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/auto-release-github.yml@v1
secrets: inherit
+5 -4
View File
@@ -1,8 +1,8 @@
# Copia in: .gitea/workflows/release.yml # Copia in: .gitea/workflows/release.yml
# Trigger: git tag v* → pubblica su npm + crea release Gitea # Trigger: git tag v* → pubblica su npm + crea release Gitea
# #
# NOTA: i job girano in parallelo (non sequenziali con needs). # NOTA: auto-release attende npm-publish via needs.
# Gitea bug #31900: needs + workflow_call + checkout causa errori di autenticazione. # Workaround Gitea bug #31900: token esplicito nel checkout di auto-release.yml.
name: Release name: Release
@@ -13,9 +13,10 @@ on:
jobs: jobs:
npm-publish: npm-publish:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/npm-publish.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/npm-publish.yml@v1
secrets: inherit secrets: inherit
auto-release: auto-release:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/auto-release.yml@v1 needs: [npm-publish]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/auto-release.yml@v1
secrets: inherit secrets: inherit
+22
View File
@@ -0,0 +1,22 @@
# Copia in: .gitea/workflows/ci.yml
# Usato da: microservizi Node.js con deploy Docker
name: CI
on:
push:
branches:
- main
paths-ignore:
- '**.md'
- 'docs/**'
pull_request:
branches:
- main
jobs:
quality-gates:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/quality-gates-github.yml@v1
secrets: inherit
# with:
# node-version: '24.16.0' # opzionale, default già impostato
+2 -2
View File
@@ -16,7 +16,7 @@ on:
jobs: jobs:
quality-gates: quality-gates:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/quality-gates.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/quality-gates.yml@v1
secrets: inherit secrets: inherit
# with: # with:
# node-version: '22.17' # opzionale, default già impostato # node-version: '24.16.0' # opzionale, default già impostato
+7 -7
View File
@@ -11,26 +11,26 @@ on:
pull_request: pull_request:
types: [closed] types: [closed]
schedule: schedule:
- cron: '0 8 * * 1' # ogni lunedì alle 08:00 → security audit - cron: '0 2 * * 1' # ogni lunedì alle 02:00 → security audit
- cron: '0 8 1 * *' # ogni 1° del mese alle 08:00 → outdated check - cron: '0 4 1 * *' # ogni 1° del mese alle 04:00 → outdated check
workflow_dispatch: workflow_dispatch:
jobs: jobs:
branch-cleanup: branch-cleanup:
if: gitea.event_name == 'pull_request' && gitea.event.pull_request.merged == true if: gitea.event_name == 'pull_request' && gitea.event.pull_request.merged == true
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/branch-cleanup.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/branch-cleanup.yml@v1
secrets: inherit secrets: inherit
dependency-audit: dependency-audit:
if: > if: >
gitea.event_name == 'workflow_dispatch' || gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 * * 1') (gitea.event_name == 'schedule' && gitea.event.schedule == '0 2 * * 1')
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/dependency-check.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/dependency-check.yml@v1
secrets: inherit secrets: inherit
dependency-outdated: dependency-outdated:
if: > if: >
gitea.event_name == 'workflow_dispatch' || gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 1 * *') (gitea.event_name == 'schedule' && gitea.event.schedule == '0 4 1 * *')
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/dependency-outdated.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/dependency-outdated.yml@v1
secrets: inherit secrets: inherit
+25
View File
@@ -0,0 +1,25 @@
# Copia in: .gitea/workflows/release.yml
# Trigger: git tag v* → build Docker + crea release Gitea
#
# NOTA: auto-release attende docker-release via needs.
# Workaround Gitea bug #31900: token esplicito nel checkout di auto-release.yml.
name: Release
on:
push:
tags:
- 'v*'
jobs:
docker-release:
runs-on: catthehacker-latest # workaround Gitea bug #34986: runs-on non rispettato in workflow_call
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/docker-release-github.yml@v1
secrets: inherit
with:
runner: catthehacker-latest # runner con Docker pre-installato
auto-release:
needs: [docker-release]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/auto-release-github.yml@v1
secrets: inherit
+6 -4
View File
@@ -1,8 +1,8 @@
# Copia in: .gitea/workflows/release.yml # Copia in: .gitea/workflows/release.yml
# Trigger: git tag v* → build Docker + crea release Gitea # Trigger: git tag v* → build Docker + crea release Gitea
# #
# NOTA: i job girano in parallelo (non sequenziali con needs). # NOTA: auto-release attende docker-release via needs.
# Gitea bug #31900: needs + workflow_call + checkout causa errori di autenticazione. # Workaround Gitea bug #31900: token esplicito nel checkout di auto-release.yml.
name: Release name: Release
@@ -13,11 +13,13 @@ on:
jobs: jobs:
docker-release: docker-release:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/docker-release.yml@v1 runs-on: catthehacker-latest # workaround Gitea bug #34986: runs-on non rispettato in workflow_call
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/docker-release.yml@v1
secrets: inherit secrets: inherit
with: with:
runner: catthehacker-latest # runner con Docker pre-installato runner: catthehacker-latest # runner con Docker pre-installato
auto-release: auto-release:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/auto-release.yml@v1 needs: [docker-release]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/auto-release.yml@v1
secrets: inherit secrets: inherit
+31
View File
@@ -0,0 +1,31 @@
# Copia in: .gitea/workflows/ci.yml
# Usato da: microservizi Python con FastAPI / pyproject.toml
#
# Requisiti pyproject.toml:
# [project.optional-dependencies]
# dev = ["ruff", "mypy", "pytest", ...]
#
# Input opzionali:
# python-version: '3.11' # default già impostato
# install-extras: 'dev' # default già impostato
name: CI
on:
push:
branches:
- main
paths-ignore:
- '**.md'
- 'docs/**'
pull_request:
branches:
- main
jobs:
quality-gates:
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/python-quality-gates-github.yml@v1
secrets: inherit
# with:
# python-version: '3.11' # opzionale, default già impostato
# install-extras: 'dev' # opzionale, default già impostato
+1 -1
View File
@@ -24,7 +24,7 @@ on:
jobs: jobs:
quality-gates: quality-gates:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/python-quality-gates.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/python-quality-gates.yml@v1
secrets: inherit secrets: inherit
# with: # with:
# python-version: '3.11' # opzionale, default già impostato # python-version: '3.11' # opzionale, default già impostato
+3 -3
View File
@@ -18,14 +18,14 @@ on:
jobs: jobs:
branch-cleanup: branch-cleanup:
if: gitea.event_name == 'pull_request' && gitea.event.pull_request.merged == true if: gitea.event_name == 'pull_request' && gitea.event.pull_request.merged == true
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/branch-cleanup.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/branch-cleanup.yml@v1
secrets: inherit secrets: inherit
dependency-audit: dependency-audit:
if: > if: >
gitea.event_name == 'workflow_dispatch' || gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 * * 1') (gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 * * 1')
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/python-dependency-check.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/python-dependency-check.yml@v1
secrets: inherit secrets: inherit
# with: # with:
# python-version: '3.11' # python-version: '3.11'
@@ -35,7 +35,7 @@ jobs:
if: > if: >
gitea.event_name == 'workflow_dispatch' || gitea.event_name == 'workflow_dispatch' ||
(gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 1 * *') (gitea.event_name == 'schedule' && gitea.event.schedule == '0 8 1 * *')
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/python-dependency-outdated.yml@v1 uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/python-dependency-outdated.yml@v1
secrets: inherit secrets: inherit
# with: # with:
# python-version: '3.11' # python-version: '3.11'
+32
View File
@@ -0,0 +1,32 @@
# Copia in: .gitea/workflows/release.yml
# Trigger: git tag v* → build Docker + crea release Gitea
#
# NOTA: auto-release attende docker-release via needs.
# Workaround Gitea bug #31900: token esplicito nel checkout di python-auto-release.yml.
#
# Prerequisiti:
# - Dockerfile presente nella root del progetto
# - pyproject.toml con [project] name e version
# - Secrets: G_USER (docker login), NPM_TOKEN (usato come password registry)
name: Release
on:
push:
tags:
- 'v*'
jobs:
docker-release:
runs-on: catthehacker-latest # workaround Gitea bug #34986: runs-on non rispettato in workflow_call
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/python-docker-release-github.yml@v1
secrets: inherit
with:
runner: catthehacker-latest # runner con Docker pre-installato
# python-version: '3.11' # opzionale
# install-extras: 'dev' # opzionale
auto-release:
needs: [docker-release]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/python-auto-release-github.yml@v1
secrets: inherit
+6 -4
View File
@@ -1,8 +1,8 @@
# Copia in: .gitea/workflows/release.yml # Copia in: .gitea/workflows/release.yml
# Trigger: git tag v* → build Docker + crea release Gitea # Trigger: git tag v* → build Docker + crea release Gitea
# #
# NOTA: i job girano in parallelo (non sequenziali con needs). # NOTA: auto-release attende docker-release via needs.
# Gitea bug #31900: needs + workflow_call + checkout causa errori di autenticazione. # Workaround Gitea bug #31900: token esplicito nel checkout di python-auto-release.yml.
# #
# Prerequisiti: # Prerequisiti:
# - Dockerfile presente nella root del progetto # - Dockerfile presente nella root del progetto
@@ -18,7 +18,8 @@ on:
jobs: jobs:
docker-release: docker-release:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/python-docker-release.yml@v1 runs-on: catthehacker-latest # workaround Gitea bug #34986: runs-on non rispettato in workflow_call
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/python-docker-release.yml@v1
secrets: inherit secrets: inherit
with: with:
runner: catthehacker-latest # runner con Docker pre-installato runner: catthehacker-latest # runner con Docker pre-installato
@@ -26,5 +27,6 @@ jobs:
# install-extras: 'dev' # opzionale # install-extras: 'dev' # opzionale
auto-release: auto-release:
uses: https://gitea.com/Punga78/shared-actions/.gitea/workflows/python-auto-release.yml@v1 needs: [docker-release]
uses: https://gitea.pzetatouch.it/devops/shared-actions/.gitea/workflows/python-auto-release.yml@v1
secrets: inherit secrets: inherit