# ObsiGate CI/CD Pipeline # Runs on every push and pull request to main name: CI on: push: branches: [main] pull_request: branches: [main] jobs: # ── Lint ────────────────────────────────────────────────────────── lint: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Setup Python uses: actions/setup-python@v5 with: python-version: "3.11" - name: Install dependencies run: | pip install ruff mypy pip install -r backend/requirements.txt - name: Ruff (linter) run: ruff check backend/ - name: Mypy (type checker) run: mypy backend/ --ignore-missing-imports - name: Frontend validation run: node tests/frontend/validate-imports.mjs - name: Frontend unit tests run: | node tests/frontend/unit.test.mjs node tests/frontend/navfacets.test.mjs node tests/frontend/desktop-roots.test.mjs node tests/frontend/image-viewer.test.mjs node tests/frontend/pdf-viewer.test.mjs node tests/frontend/forge-completion.test.mjs node tests/frontend/config-mobile.test.mjs node tests/frontend/settings-order-avatar.test.mjs node tests/frontend/mobile-toolbar.test.mjs node tests/frontend/pretty.test.mjs node tests/frontend/media-viewer.test.mjs node tests/frontend/mfa-settings.test.mjs - name: Frontend JSDOM tests (PaneManager + Excalidraw + Plugins + AI + SW + Collab + Mobile + Semantic + Desktop + Inline edition + Upload + XLSX) run: | cd tests/frontend if [ -d node_modules ]; then node pane-manager.test.mjs node excalidraw-viewer.test.mjs node plugins.test.mjs node ai.test.mjs node ai-sidebar.test.mjs node sidebar-filters.test.mjs node search-facets.test.mjs node sw.test.mjs node collab.test.mjs node mobile-editor.test.mjs node semantic-search.test.mjs node desktop.test.mjs node toolbar-order.test.mjs node editor-inline.test.mjs node ai-quick-actions.test.mjs node upload.test.mjs node config-ai-keys.test.mjs node xlsx-viewer.test.mjs else echo "tests/frontend/node_modules missing - installing jsdom" npm install --no-audit --no-fund --silent node pane-manager.test.mjs node excalidraw-viewer.test.mjs node plugins.test.mjs node ai.test.mjs node ai-sidebar.test.mjs node sidebar-filters.test.mjs node search-facets.test.mjs node sw.test.mjs node collab.test.mjs node mobile-editor.test.mjs node semantic-search.test.mjs node desktop.test.mjs node toolbar-order.test.mjs node editor-inline.test.mjs node ai-quick-actions.test.mjs node upload.test.mjs node config-ai-keys.test.mjs node xlsx-viewer.test.mjs fi # ── Tests ───────────────────────────────────────────────────────── test: needs: lint runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Setup Python uses: actions/setup-python@v5 with: python-version: "3.11" - name: Install dependencies run: | pip install pytest pytest-cov pytest-asyncio httpx pip install -r backend/requirements.txt pip install -r backend/requirements-test.txt || echo "test deps install failed (non-blocking — PDF tests will skip)" - name: Run tests run: pytest tests/ --cov=backend --cov-report=xml --cov-report=term -q - name: Upload coverage artifact uses: actions/upload-artifact@v3 with: name: coverage-report path: coverage.xml retention-days: 30 # ── Security scan ───────────────────────────────────────────────── security: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Setup Python uses: actions/setup-python@v5 with: python-version: "3.11" - name: Install dependencies # setuptools / pip sont mis à jour : l'image de base peut embarquer # une version couverte par un advisory fraîchement publié # (PYSEC-2026-3447 / PYSEC-2026-3721). # NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`. run: | pip install -U pip setuptools pip install bandit pip-audit pip install -r backend/requirements.txt - name: Bandit (SAST, bloquant — #87) # B105 est exclu (aligné avec [tool.bandit] de pyproject.toml : # faux positifs systématiques sur les noms de variables) ; les rares # vrais positifs restants portent un `# nosec` justifié inline. run: bandit -r backend/ --skip B101,B105,B110,B310 - name: Semgrep (SAST local) — DÉSACTIVÉ (BUG-091) # Les règles locales (semgrep-rules/, 8 règles) ne sont plus exécutées # en CI : semgrep-core est un exécutable natif que le runner actuel ne # peut pas lancer (exit 127, sans message exploitable) — les releases # récentes exigent un CPU x86-64-v2, et la dernière version compatible # (1.157.0, core statique vérifié en baseline v1) échoue aussi. Les # règles restent applicables en local : `semgrep --config semgrep-rules/ # backend/`. À réactiver dès que le runner dispose d'un CPU x86-64-v2 # (ou d'une image de runner plus récente). Bandit et pip-audit, eux, # restent bloquants dans ce job. # NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`. continue-on-error: true run: | echo "::warning::SAST semgrep non exécutée (runner incompatible — BUG-091). Bandit et pip-audit restent bloquants." - name: Pip-audit (bloquant — #87) # Bloquant depuis T6 (#87) : dépendances qualifiées (mistune 3.3.3, # python-multipart 0.0.31, weasyprint 70, mcp 1.28.1, fastapi 0.141.1 # + starlette 1.7.0, setuptools 84 — suite complète verte + 0 vuln). # Seule exception documentée : PYSEC-2026-1325 (ecdsa, Minerva) — # aucun correctif upstream ET ObsiGate ne signe/vérifie qu'en HS256 # (backend/auth/jwt_handler.py), les chemins ECDSA P-256 ne # s'exécutent jamais. Les advisories pyjwt (PYSEC-2026-178 puis # CVE-2026-102274) sont corrigées par le plancher pyjwt>=2.14.0 de # backend/requirements.txt (BUG-091, BUG-095). # PYSEC-2026-3910 / PYSEC-2026-3911 (pypdf, DoS de ressources sur # l'extraction de texte et la lecture d'outlines — donc atteignables # via backend/pdf_reader.py) sont corrigés par le plancher # pypdf>=6.16.1 (BUG-093). # CVE-2026-97687 / CVE-2026-97688 / CVE-2026-97689 (urllib3 2.7.0) # corrigés par le plancher urllib3>=2.8.0. # Ces planchers doivent rester *au-dessus* des versions préinstallées # dans la toolcache de l'image du runner : en dessous, pip répond # « already satisfied » et n'aligne jamais (c'est exactement ce qui a # fait échouer ce job). Le garde-fou tests/test_ci_workflow.py:: # TestDependencySecurityFloors verrouille ces planchers. # NOTE runner Gitea Act (BUG-083) : aucun `#` dans le `run:`. run: pip-audit --ignore-vuln PYSEC-2026-1325 # ── Docker build ────────────────────────────────────────────────── build: needs: test runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Version livrée # VERSION (racine du dépôt) est copié dans l'image par le Dockerfile : # plus aucun numéro généré ni codé en dur dans le pipeline. run: echo "Version livree = $(cat VERSION)" - name: Configure DNS (workaround flaky 127.0.0.11 resolver) # GitHub Actions runners occasionally fail to resolve auth.docker.io via # the embedded Docker DNS (127.0.0.11:53 → "server misbehaving"). # Force the daemon to use public DNS as a fallback. run: | sudo mkdir -p /etc/docker if ! grep -q "dns" /etc/docker/daemon.json 2>/dev/null; then echo '{"dns": ["8.8.8.8", "1.1.1.1", "9.9.9.9"]}' | sudo tee /etc/docker/daemon.json sudo systemctl restart docker || sudo service docker restart || true sleep 3 fi - name: Build Docker image (retry on transient DNS/network errors) run: | for attempt in 1 2 3; do echo "=== docker build attempt $attempt/3 ===" if docker build -t obsigate:ci . ; then echo "✓ Docker build succeeded" exit 0 fi echo "✗ Build failed (attempt $attempt)" if [ $attempt -lt 3 ]; then sleep $((attempt * 10)) fi done echo "✗ Docker build failed after 3 attempts" exit 1 - name: Verify image run: docker images obsigate:ci # ── E2E Tests (Playwright) ───────────────────────────────────────── e2e: needs: build runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Setup Node uses: actions/setup-node@v4 with: node-version: "20" - name: Install Playwright run: | npm ci npx playwright install --with-deps chromium - name: Npm audit (bloquant — #87, 0 dépendance prod hors Playwright) run: npm audit --omit=dev - name: Start ObsiGate run: | docker rm -f obsigate-e2e 2>/dev/null || true docker create --name obsigate-e2e -p 2029:8080 \ -v $(pwd)/test_vault:/vaults/TestVault \ -v $(pwd)/test_dir:/vaults/TestDir \ -e VAULT_1_NAME=TestVault \ -e VAULT_1_PATH=/vaults/TestVault \ -e DIR_1_NAME=TestDir \ -e DIR_1_PATH=/vaults/TestDir \ -e OBSIGATE_AUTH_ENABLED=false \ -e OBSIGATE_ALLOW_INSECURE=true \ obsigate:ci # Docker-in-docker : le bind mount $(pwd)/... pointe sur un chemin # du job container, inexistant sur l'hôte → montage vide. Les -v # créent quand même /vaults/* dans le container ; on y copie les # fixtures avant le démarrage (l'indexeur scanne au démarrage). docker cp test_vault/. obsigate-e2e:/vaults/TestVault docker cp test_dir/. obsigate-e2e:/vaults/TestDir docker start obsigate-e2e # Le port publié est joignable via l'IP de la passerelle (localhost # du job container ne voit pas le port publié sur l'hôte). GW=$(ip route show default | awk '{print $3}' || echo 172.17.0.1) echo "Gateway IP: $GW" # Wait for health check for i in $(seq 1 30); do if curl -sf "http://$GW:2029/api/health"; then echo "Health OK"; break; fi sleep 1 done curl -sf "http://$GW:2029/api/health" >/dev/null || { echo "App not reachable at $GW:2029"; exit 1; } # Les fixtures sont copiées via `docker cp` en root → rendre le vault # inscriptible par l'utilisateur non-root de l'app (UID 1000), sinon # toute création/édition de fichier renvoie 403 « Vault is read-only ». docker exec -u 0 obsigate-e2e chmod -R a+rwX /vaults/TestVault /vaults/TestDir || true - name: Run E2E tests run: | GW=$(ip route show default | awk '{print $3}' || echo 172.17.0.1) echo "Using BASE_URL=http://$GW:2029" BASE_URL="http://$GW:2029" npx playwright test --project=chromium-desktop --reporter=list - name: Upload test results if: always() uses: actions/upload-artifact@v3 with: name: playwright-report path: playwright-report/ retention-days: 7 - name: Cleanup if: always() run: docker rm -f obsigate-e2e