fix(ci): make edgeone artifact guard read-only #184
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: EdgeOne Artifact Guard | |
| # cloud-functions/[[default]].js 是 EdgeOne Makers 平台在检出仓库时扫描的 | |
| # Node 云函数产物(缺失会报 "No server-handler detected" 并退化为纯静态项目, | |
| # 详见 docs/edgeone.md),因此必须提交进仓库并与后端源码、前端产物保持同步。 | |
| # | |
| # 本工作流按与部署一致的流程重新构建该产物并与已提交版本比对: | |
| # - push 到 main / 手动触发:只校验并失败,不直接修改受保护分支 | |
| # - pull request:只校验并失败,由 PR 作者本地重建后提交(便于审查) | |
| on: | |
| push: | |
| branches: | |
| - main | |
| paths: | |
| - "src/**" | |
| - "api/**" | |
| - "scripts/build-edge.mjs" | |
| - "scripts/fetch-frontend.mjs" | |
| - "cloud-functions/**" | |
| - "package.json" | |
| - "pnpm-lock.yaml" | |
| - ".github/workflows/edgeone-artifact-guard.yml" | |
| pull_request: | |
| paths: | |
| - "src/**" | |
| - "api/**" | |
| - "scripts/build-edge.mjs" | |
| - "scripts/fetch-frontend.mjs" | |
| - "cloud-functions/**" | |
| - "package.json" | |
| - "pnpm-lock.yaml" | |
| - ".github/workflows/edgeone-artifact-guard.yml" | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: edgeone-artifact-guard-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| guard: | |
| runs-on: ubuntu-latest | |
| name: Rebuild and verify cloud-functions artifact | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v4 | |
| - name: Setup Node | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22 | |
| cache: pnpm | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Fetch official frontend dist | |
| run: node scripts/fetch-frontend.mjs | |
| - name: Rebuild EdgeOne artifact | |
| run: node scripts/build-edge.mjs | |
| - name: Check artifact freshness | |
| id: check | |
| run: | | |
| if [ -z "$(git status --porcelain -- cloud-functions)" ]; then | |
| echo "changed=false" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| git status --short -- cloud-functions | |
| git diff --stat -- cloud-functions | |
| git diff --exit-code -- cloud-functions || true | |
| echo "::error::cloud-functions/[[default]].js 与源码不同步。请在本地运行 pnpm run build,并提交更新后的 cloud-functions/[[default]].js。" | |
| exit 1 | |
| fi | |
| - name: Job summary | |
| if: always() | |
| run: | | |
| if [ "${{ steps.check.outputs.changed }}" = "false" ]; then | |
| echo "cloud-functions/[[default]].js 与源码同步,无需更新" >> "$GITHUB_STEP_SUMMARY" | |
| else | |
| echo "cloud-functions/[[default]].js 已过期;请使用任务上传的刷新产物更新提交。" >> "$GITHUB_STEP_SUMMARY" | |
| fi | |
| - name: Upload refreshed artifact on failure | |
| if: failure() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: cloud-functions-refreshed | |
| path: cloud-functions/ | |
| retention-days: 7 |