Skip to content

feat(ci): GitHub Actions CI/CD, Docker pipeline, and v1.0.0 - #59

Merged
Starosdev merged 43 commits into
masterfrom
develop
May 10, 2026
Merged

Starosdev merged 43 commits into
masterfrom
develop

Conversation

@Starosdev

@Starosdev Starosdev commented May 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

Linked Issues

Closes #18
Closes #21
Closes #22
Closes #23

Test plan

  • CI checks passed on develop
  • Multi-arch Docker images build successfully
  • GitHub Releases created for develop builds
  • Sentry source maps upload correctly
  • Turkish locale crash no longer reproducible
  • Intermediate CA certs served correctly on Linux
  • MailKit vulnerability resolved (NU1902 error gone)

Add monolith GitHub Actions workflow with 17 jobs covering build,
test, packaging, analysis, and notifications. Disable Azure Pipelines
triggers while preserving the file for reference.

Jobs: setup (git tag counter), build-backend (cross-compile all RIDs),
build-frontend, packages (13 archives), lint, unit/integration tests
(native + docker + postgres), Windows installer, Sentry source map
upload, SonarCloud analysis (frontend + backend), API docs generation,
and Discord notifications.
Update sonarcloud-frontend and sonarcloud-backend jobs to use
self-hosted SonarQube at sonar.staros.dev with per-project tokens.
Remove sonar.organization parameter (not used in SonarQube).
Use DISCORD_WEBHOOK_ID for constructing the webhook URL and
DISCORD_CHANNEL_ID for the actual channel reference.
Fix env context not available at job-level env (use literal values
for MAJORVERSION and INNOVERSION). Pass github.head_ref through env
var to prevent script injection risk.
Replace blanket .github/** paths-ignore with specific exclusions for
labeler, label-actions, and lock workflows. The CI workflow itself
must be able to trigger runs when updated.
- Fix SA1513 StyleCop error in VideoFileInfoReader.cs (missing blank
  line after closing brace)
- Bump Node.js from 20.11.1 to 20.19.0 (jsdom@28.1.0 requires it)
- Fix SonarScanner on Windows: Git Bash mangles /k: and /d: flags,
  switch to pwsh shell for sonarscanner begin/end steps
- Remove dorny/test-reporter (requires git checkout, test jobs only
  download artifacts). Test results still uploaded as artifacts.
- Exclude .test.tsx files from webpack build (TS errors from Vitest
  matchers like toBeInTheDocument)
- Fix SonarScanner pwsh env var syntax (use $env:VAR instead of $VAR)
- Add explicit boolean values for JSX boolean attributes (ESLint
  react/jsx-boolean-value rule)
- Fix prettier formatting in Icon.test.tsx
- Add test infrastructure files to .eslintignore (vitest.config.ts,
  test/setup.ts, test/cssModuleMock.ts are outside tsconfig scope)
)

- Exclude *.test.ts/tsx from tsconfig.json so fork-ts-checker-webpack-plugin
  does not type-check Vitest test files during production build
- Fix SonarScanner begin command: use pwsh backtick continuations
  instead of YAML folding, use /v: for project version per scanner
  recommendation
…int (#18)

- Make PackageWindows() gracefully skip the net8.0-windows overlay
  when building on Linux (WinForms tray app only builds on Windows)
- Add *.test.ts and *.test.tsx to .eslintignore (test files use
  Vitest types not included in the main tsconfig project)
- Installer job now builds backend on Windows directly (needs
  net8.0-windows TFM for Radarr.exe WinForms tray app, which only
  builds on Windows)
- Update sentry-cli source map command from deprecated
  'releases files upload-sourcemaps' to 'sourcemaps upload'
sentry-cli releases set-commits --auto needs a git repo to
associate commits with the release.
Replace upstream Servarr Sentry org and URL with Starosdev's sentry.io
instance. Backend and frontend DSNs were already updated; this covers the
remaining CI pipeline references in azure-pipelines.yml.
Replace CurrentCultureIgnoreCase and InvariantCultureIgnoreCase with
OrdinalIgnoreCase in HTTP middleware and request extensions to prevent
startup crashes under Turkish (tr-TR) locale. Also replace ToLower()
with ToLowerInvariant() in InitializeJsonController.
Load the full certificate chain from PFX files using
X509Certificate2Collection instead of a single X509Certificate2.
The leaf certificate and intermediate CAs are separated, then
passed to SslStreamCertificateContext.Create() so Kestrel serves
the complete chain during TLS handshake.

Previously, only the leaf certificate was loaded, which caused
SSL validation failures on Linux/Docker where the OS certificate
store does not automatically resolve intermediates from the PFX.
The installer job failed because the jrsoftware.org download returned an
HTML error page instead of the binary. The curl command silently saved
the error page as innosetup.exe. This adds --fail and -L flags to curl
so HTTP errors are caught, and bumps the version from 6.2.2 to 6.4.2.
The jrsoftware.org file server is unreliable, causing the installer job
to fail when downloading innosetup.exe. Replaced the direct download
with Chocolatey installation on Windows CI runners.

Also added --ignore-missing to sentry-cli set-commits to handle cases
where the previous release SHA is not in the git history.
Inno Setup 6.7.1 is already available on windows-2025 runners. Instead
of downloading or installing via Chocolatey, detect the existing ISCC.exe
path dynamically and pass it to build.sh via ISCC_PATH.
@Starosdev Starosdev added enhancement New feature or request backend Backend related labels May 9, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9407929aee

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/cleanup-branches.yml Outdated
Comment on lines +59 to +60
merged_to_develop=$(git branch -r --merged origin/develop | grep -c "origin/$branch" || echo "0")
merged_to_master=$(git branch -r --merged origin/master | grep -c "origin/$branch" || echo "0")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Match merged branches by exact name before deletion

Use an exact match when checking whether a remote branch is merged; grep -c "origin/$branch" treats the branch name as a regex substring, so a branch like feature/a can be misclassified as merged if origin/feature/abc appears in the merged list. In this workflow that can incorrectly trigger git push origin --delete on unmerged branches older than 30 days.

Useful? React with 👍 / 👎.

Comment thread .github/workflows/secret-scan.yml Outdated
zricethezav/gitleaks:v8.30.0 \
detect \
--source=/repo \
--no-git \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Scan git history for secrets instead of filesystem mode

Running gitleaks with --no-git switches to filesystem scanning, which only inspects the current checkout and misses secrets that were committed and later removed (but still exist in repository history). That leaves a significant detection gap for a push-time secret scan because leaked credentials remain exposed in Git history even when not present in HEAD.

Useful? React with 👍 / 👎.

Comment thread .gitleaks.toml Outdated
[allowlist]
description = "Global allowlist"
paths = [
'''\.github/workflows/''',

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Do not globally allowlist workflow files in gitleaks

Allowlisting .github/workflows/ disables secret detection for all workflow YAML files, which are a common place for accidental hardcoded tokens or webhook URLs. This creates a permanent blind spot in the new secret-scan pipeline and undermines the protection it is meant to provide.

Useful? React with 👍 / 👎.

Starosdev added 3 commits May 9, 2026 19:35
MailKit 4.13.0 has GHSA-9j88-vvj5-vhgr; bump to 4.16.0 to unblock CI.
Branch cleanup grep used substring match; switch to -cxF to prevent
false deletion of unmerged branches. Secret scan lacked full history
and skipped workflow files; drop --no-git, fetch full depth, and remove
.github/workflows/ from gitleaks allowlist.
Tag push fails with exit 128 when the nightly tag already exists from
a prior run. Delete local and remote tag before recreating so re-runs
on the same version do not abort.
@Starosdev
Starosdev merged commit d7c1b0d into master May 10, 2026
38 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend Backend related enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant