refs #82 #83 #84 #85 #86 #87 #88 #89 #90 #91 #92 - Replace all docker:cli build/tag/push with woodpeckerci/plugin-docker-buildx - Replace all aquasec/trivy shell commands with woodpeckerci/plugin-trivy - Add fhirworx/api image to deploy, infra-ci, and rebuild-all pipelines - Add docs trivy scan + S3 upload (was missing) - Add coverage badge S3 upload and git-push auto-commit - Add PR comment plugin for CI feedback - Create release.yml for tag-triggered Gitea releases - Wire diag failure reporter into all 5 pipelines
43 lines
1.3 KiB
YAML
43 lines
1.3 KiB
YAML
# ── Release ──────────────────────────────────────────────────────
|
|
# Builds the Python package and creates a Gitea release with
|
|
# wheel + sdist artifacts. Triggered on tag pushes (e.g. v0.5.0).
|
|
|
|
when:
|
|
- event: tag
|
|
|
|
steps:
|
|
- name: build-package
|
|
image: ghcr.io/astral-sh/uv:python3.13-bookworm-slim
|
|
commands:
|
|
- uv build --out-dir dist/
|
|
- ls -lh dist/
|
|
|
|
- name: release
|
|
image: woodpeckerci/plugin-gitea-release
|
|
settings:
|
|
api_key:
|
|
from_secret: gitea_token
|
|
base_url:
|
|
from_secret: gitea_url
|
|
files:
|
|
- dist/*.whl
|
|
- dist/*.tar.gz
|
|
title: "${CI_COMMIT_TAG}"
|
|
depends_on:
|
|
- build-package
|
|
|
|
# ── Failure reporter ─────────────────────────────────────────
|
|
- name: report-failure
|
|
image: ghcr.io/astral-sh/uv:python3.13-bookworm-slim
|
|
environment:
|
|
UV_PYTHON_PREFERENCE: only-system
|
|
UV_LINK_MODE: copy
|
|
UV_PROJECT_ENVIRONMENT: .venv
|
|
GITEA_TOKEN:
|
|
from_secret: gitea_token
|
|
commands:
|
|
- uv sync --no-dev
|
|
- uv run python -m api.diag
|
|
when:
|
|
- status: [failure]
|