ci: CI全链路加固6项 - 从基础设施到门禁策略的完整补漏 (#742)
CI/CD Pipeline / Validate - Migration (alembic) (push) Successful in 40s
CI/CD Pipeline / Validate - Type Check (mypy) (push) Successful in 45s
CI/CD Pipeline / Frontend Lint (push) Successful in 55s
CI/CD Pipeline / Build Staging Web Image (push) Successful in 57s
CI/CD Pipeline / Frontend Unit Tests (push) Failing after 16s
CI/CD Pipeline / Integration Tests (push) Successful in 59s
CI/CD Pipeline / Unit Tests (push) Successful in 2m42s
CI/CD Pipeline / Validate - Code Quality (push) Successful in 3m25s
CI/CD Pipeline / Build Staging API Image (push) Successful in 5m22s
CI/CD Pipeline / Build Staging Worker Image (push) Failing after 5m22s
CI/CD Pipeline / ACR Image Cleanup (push) Failing after 1337h43m28s
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (push) Failing after 1337h43m29s
CI/CD Pipeline / Production Browser E2E (push) Failing after 1337h48m47s
CI/CD Pipeline / Staging API Integration Tests (push) Failing after 1337h43m29s
CI/CD Pipeline / Build Production Worker Image (push) Failing after 1337h48m49s
CI/CD Pipeline / Build Production Web Image (push) Failing after 1337h48m51s
CI/CD Pipeline / PR Build Worker Image (push) Failing after 1337h48m53s
CI/CD Pipeline / Check if frontend-only change (push) Failing after 1337h48m53s
CI/CD Pipeline / PR Build API Image (push) Failing after 1337h48m54s
CI/CD Pipeline / PR Build Web Image (push) Failing after 1338h21m10s
CI/CD Pipeline / Staging E2E Tests (push) Failing after 1338h15m46s
CI/CD Pipeline / Deploy Production (push) Failing after 1338h21m6s
CI/CD Pipeline / Build Production API Image (push) Failing after 1338h21m8s

This commit was merged in pull request #742.
This commit is contained in:
2026-07-22 21:40:10 +08:00
parent a75f749b39
commit 614a8e95be
5 changed files with 122 additions and 15 deletions
+54 -6
View File
@@ -79,6 +79,25 @@ try:
print(' '.join(py_files))
except Exception:
print('')
")
# 新增文件(added)强制全量检查,防止增量漏检
ADDED_PY_FILES=$(echo "$BODY" | python3 -c "
import json, sys
try:
files = json.load(sys.stdin)
added = [f['filename'] for f in files if f['filename'].endswith('.py') and f['status'] == 'added']
print(' '.join(added))
except Exception:
print('')
")
MODIFIED_PY_FILES=$(echo "$BODY" | python3 -c "
import json, sys
try:
files = json.load(sys.stdin)
modified = [f['filename'] for f in files if f['filename'].endswith('.py') and f['status'] not in ('removed', 'added')]
print(' '.join(modified))
except Exception:
print('')
")
if [ -n "$CHANGED_PY_FILES" ]; then
SCAN_MODE="incremental"
@@ -174,13 +193,42 @@ echo "发现潜在死代码(可能包含框架装饰器注册的函数,为
echo "建议:定期人工审查高置信度(>=90%)条目"
set -e
# --- Release 脚本语法校验 ---
# --- CI脚本语法校验 ---
echo ""
echo "=== [6/6] Release scripts syntax validation ==="
bash -n scripts/backup_postgres.sh
bash -n scripts/restore_postgres_plan.sh
bash -n scripts/init_production_env.sh
echo "✅ Release scripts syntax OK"
echo "=== [6/6] CI & shell scripts syntax validation ==="
SYNTAX_ERROR=0
# 检查所有 CI shell 脚本
for script in scripts/ci/*.sh; do
if [ -f "$script" ]; then
if ! bash -n "$script" 2>&1; then
echo "❌ 语法错误: $script"
SYNTAX_ERROR=1
fi
fi
done
# 检查所有 CI Python 脚本语法
for script in scripts/ci/*.py; do
if [ -f "$script" ]; then
if ! python3 -m py_compile "$script" 2>&1; then
echo "❌ Python语法错误: $script"
SYNTAX_ERROR=1
fi
fi
done
# 检查 .gitea/workflows 下的脚本(如果有)
for script in .gitea/workflows/*.sh; do
if [ -f "$script" ]; then
if ! bash -n "$script" 2>&1; then
echo "❌ 语法错误: $script"
SYNTAX_ERROR=1
fi
fi
done
if [ "$SYNTAX_ERROR" -ne 0 ]; then
echo "❌ CI脚本语法校验失败,见上方错误"
exit 1
fi
echo "✅ All CI scripts syntax OK"
echo ""
echo "=== CI Validate: 代码质量与安全扫描 全部通过 ✅ ==="