Conversation
Add monolith GitHub Actions workflow with 17 jobs covering build, test, packaging, analysis, and notifications. Disable Azure Pipelines triggers while preserving the file for reference. Jobs: setup (git tag counter), build-backend (cross-compile all RIDs), build-frontend, packages (13 archives), lint, unit/integration tests (native + docker + postgres), Windows installer, Sentry source map upload, SonarCloud analysis (frontend + backend), API docs generation, and Discord notifications.
Update sonarcloud-frontend and sonarcloud-backend jobs to use self-hosted SonarQube at sonar.staros.dev with per-project tokens. Remove sonar.organization parameter (not used in SonarQube).
Use DISCORD_WEBHOOK_ID for constructing the webhook URL and DISCORD_CHANNEL_ID for the actual channel reference.
Fix env context not available at job-level env (use literal values for MAJORVERSION and INNOVERSION). Pass github.head_ref through env var to prevent script injection risk.
Replace blanket .github/** paths-ignore with specific exclusions for labeler, label-actions, and lock workflows. The CI workflow itself must be able to trigger runs when updated.
- Fix SA1513 StyleCop error in VideoFileInfoReader.cs (missing blank line after closing brace) - Bump Node.js from 20.11.1 to 20.19.0 (jsdom@28.1.0 requires it) - Fix SonarScanner on Windows: Git Bash mangles /k: and /d: flags, switch to pwsh shell for sonarscanner begin/end steps
- Remove dorny/test-reporter (requires git checkout, test jobs only download artifacts). Test results still uploaded as artifacts. - Exclude .test.tsx files from webpack build (TS errors from Vitest matchers like toBeInTheDocument) - Fix SonarScanner pwsh env var syntax (use $env:VAR instead of $VAR)
- Add explicit boolean values for JSX boolean attributes (ESLint react/jsx-boolean-value rule) - Fix prettier formatting in Icon.test.tsx - Add test infrastructure files to .eslintignore (vitest.config.ts, test/setup.ts, test/cssModuleMock.ts are outside tsconfig scope)
…int (#18) - Make PackageWindows() gracefully skip the net8.0-windows overlay when building on Linux (WinForms tray app only builds on Windows) - Add *.test.ts and *.test.tsx to .eslintignore (test files use Vitest types not included in the main tsconfig project)
- Installer job now builds backend on Windows directly (needs net8.0-windows TFM for Radarr.exe WinForms tray app, which only builds on Windows) - Update sentry-cli source map command from deprecated 'releases files upload-sourcemaps' to 'sourcemaps upload'
sentry-cli releases set-commits --auto needs a git repo to associate commits with the release.
Replace upstream Servarr Sentry org and URL with Starosdev's sentry.io instance. Backend and frontend DSNs were already updated; this covers the remaining CI pipeline references in azure-pipelines.yml.
Replace CurrentCultureIgnoreCase and InvariantCultureIgnoreCase with OrdinalIgnoreCase in HTTP middleware and request extensions to prevent startup crashes under Turkish (tr-TR) locale. Also replace ToLower() with ToLowerInvariant() in InitializeJsonController.
Load the full certificate chain from PFX files using X509Certificate2Collection instead of a single X509Certificate2. The leaf certificate and intermediate CAs are separated, then passed to SslStreamCertificateContext.Create() so Kestrel serves the complete chain during TLS handshake. Previously, only the leaf certificate was loaded, which caused SSL validation failures on Linux/Docker where the OS certificate store does not automatically resolve intermediates from the PFX.
The installer job failed because the jrsoftware.org download returned an HTML error page instead of the binary. The curl command silently saved the error page as innosetup.exe. This adds --fail and -L flags to curl so HTTP errors are caught, and bumps the version from 6.2.2 to 6.4.2.
The jrsoftware.org file server is unreliable, causing the installer job to fail when downloading innosetup.exe. Replaced the direct download with Chocolatey installation on Windows CI runners. Also added --ignore-missing to sentry-cli set-commits to handle cases where the previous release SHA is not in the git history.
Inno Setup 6.7.1 is already available on windows-2025 runners. Instead of downloading or installing via Chocolatey, detect the existing ISCC.exe path dynamically and pass it to build.sh via ISCC_PATH.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9407929aee
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| merged_to_develop=$(git branch -r --merged origin/develop | grep -c "origin/$branch" || echo "0") | ||
| merged_to_master=$(git branch -r --merged origin/master | grep -c "origin/$branch" || echo "0") |
There was a problem hiding this comment.
Match merged branches by exact name before deletion
Use an exact match when checking whether a remote branch is merged; grep -c "origin/$branch" treats the branch name as a regex substring, so a branch like feature/a can be misclassified as merged if origin/feature/abc appears in the merged list. In this workflow that can incorrectly trigger git push origin --delete on unmerged branches older than 30 days.
Useful? React with 👍 / 👎.
| zricethezav/gitleaks:v8.30.0 \ | ||
| detect \ | ||
| --source=/repo \ | ||
| --no-git \ |
There was a problem hiding this comment.
Scan git history for secrets instead of filesystem mode
Running gitleaks with --no-git switches to filesystem scanning, which only inspects the current checkout and misses secrets that were committed and later removed (but still exist in repository history). That leaves a significant detection gap for a push-time secret scan because leaked credentials remain exposed in Git history even when not present in HEAD.
Useful? React with 👍 / 👎.
| [allowlist] | ||
| description = "Global allowlist" | ||
| paths = [ | ||
| '''\.github/workflows/''', |
There was a problem hiding this comment.
Do not globally allowlist workflow files in gitleaks
Allowlisting .github/workflows/ disables secret detection for all workflow YAML files, which are a common place for accidental hardcoded tokens or webhook URLs. This creates a permanent blind spot in the new secret-scan pipeline and undermines the protection it is meant to provide.
Useful? React with 👍 / 👎.
MailKit 4.13.0 has GHSA-9j88-vvj5-vhgr; bump to 4.16.0 to unblock CI. Branch cleanup grep used substring match; switch to -cxF to prevent false deletion of unmerged branches. Secret scan lacked full history and skipped workflow files; drop --no-git, fetch full depth, and remove .github/workflows/ from gitleaks allowlist.
Tag push fails with exit 128 when the nightly tag already exists from a prior run. Delete local and remote tag before recreating so re-runs on the same version do not abort.
Summary
Linked Issues
Closes #18
Closes #21
Closes #22
Closes #23
Test plan