SBA OHA on protests: naics_code filter, five OHA fields, conformance mapping #9
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| # Lint + typecheck + test gate runs on every PR and push to main. | |
| # | |
| # The SDK filter/shape conformance check needs the canonical manifest from the | |
| # private makegov/tango repo, which requires a TANGO_API_REPO_ACCESS_TOKEN secret | |
| # the public CI does not have. The conformance job SKIPS cleanly when the token | |
| # is absent (rather than failing on an empty token) and becomes a hard gate the | |
| # moment the secret is configured. The lint + test gate below is self-contained | |
| # and blocks the PR on failure. | |
| on: | |
| push: | |
| branches: [ main ] | |
| pull_request: | |
| branches: [ main ] | |
| workflow_dispatch: | |
| jobs: | |
| test: | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest] | |
| node-version: ["18", "20", "22"] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Node.js ${{ matrix.node-version }} | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: ${{ matrix.node-version }} | |
| - name: Install dependencies | |
| # No lockfile is committed (package-lock.json is gitignored), and the | |
| # "prepare" script runs a build that needs tsc — so ignore scripts here | |
| # and build explicitly below. | |
| run: npm install --ignore-scripts --no-audit --no-fund | |
| - name: Lint | |
| run: npm run lint | |
| - name: Typecheck | |
| run: npm run typecheck | |
| - name: Build | |
| run: npm run build | |
| - name: Test | |
| # `vitest run` forces a single non-watch pass in CI. | |
| run: npx vitest run | |
| conformance: | |
| # Requires the canonical filter_shape manifest from the private makegov/tango | |
| # repo. When TANGO_API_REPO_ACCESS_TOKEN is not configured, every real step | |
| # is skipped and the job passes (rather than failing on an empty token). | |
| # Configure the secret to turn this into a hard gate automatically. | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Determine token availability | |
| id: gate | |
| env: | |
| TANGO_API_REPO_ACCESS_TOKEN: ${{ secrets.TANGO_API_REPO_ACCESS_TOKEN }} | |
| run: | | |
| if [ -n "$TANGO_API_REPO_ACCESS_TOKEN" ]; then | |
| echo "ready=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "ready=false" >> "$GITHUB_OUTPUT" | |
| echo "::notice::Skipping SDK conformance check — TANGO_API_REPO_ACCESS_TOKEN not configured." | |
| fi | |
| - uses: actions/checkout@v4 | |
| if: steps.gate.outputs.ready == 'true' | |
| - name: Checkout tango API repo (manifest source) | |
| if: steps.gate.outputs.ready == 'true' | |
| uses: actions/checkout@v4 | |
| with: | |
| repository: makegov/tango | |
| path: tango-api | |
| token: ${{ secrets.TANGO_API_REPO_ACCESS_TOKEN }} | |
| - name: Set up Node.js | |
| if: steps.gate.outputs.ready == 'true' | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| - name: Install dependencies | |
| if: steps.gate.outputs.ready == 'true' | |
| run: npm install --ignore-scripts --no-audit --no-fund | |
| - name: Check SDK filter/shape conformance | |
| if: steps.gate.outputs.ready == 'true' | |
| run: npx tsx scripts/check-filter-shape-conformance.ts --manifest tango-api/contracts/filter_shape_contract.json |