name: ci

on:
  push:
    paths-ignore:
      - "docs/**"
      - "*.md"
    branches:
      - main
  pull_request:
    paths-ignore:
      - "docs/**"
      - "*.md"
    branches:
      - main
      - "!v[0-9]*"

# https://github.com/vitejs/vite/blob/main/.github/workflows/ci.yml
env:
  # 7 GiB by default on GitHub, setting to 6 GiB
  # https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners#supported-runners-and-hardware-resources
  NODE_OPTIONS: --max-old-space-size=6144

# Remove default permissions of GITHUB_TOKEN for security
# https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs
permissions: {}

concurrency:
  group: ${{ github.workflow }}-${{ github.event.number || github.sha }}
  cancel-in-progress: ${{ github.event_name != 'push' }}

jobs:
  build:
    runs-on: ubuntu-latest
    timeout-minutes: 10

    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
      - run: corepack enable
      - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
        with:
          node-version: 20
          cache: "pnpm"

      - name: Install dependencies
        run: pnpm install

      - name: Build (stub)
        run: pnpm dev:prepare

      - name: Typecheck
        run: pnpm typecheck

      - name: Build
        run: pnpm build

      - name: Cache dist
        uses: actions/upload-artifact@5d5d22a31266ced268874388b861e4b58bb5c2f3 # v4.3.1
        with:
          retention-days: 3
          name: dist
          path: packages/*/dist

  codeql:
    runs-on: ubuntu-latest
    timeout-minutes: 10
    permissions:
      actions: read
      contents: read
      security-events: write
    needs:
      - build

    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
      - run: corepack enable
      - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
        with:
          node-version: 20
          cache: "pnpm"

      - name: Install dependencies
        run: pnpm install

      - name: Initialize CodeQL
        uses: github/codeql-action/init@05963f47d870e2cb19a537396c1f668a348c7d8f # v3.24.8
        with:
          languages: javascript
          queries: +security-and-quality

      - name: Restore dist cache
        uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707a7f8427 # v4.1.4
        with:
          name: dist
          path: packages

      - name: Perform CodeQL Analysis
        uses: github/codeql-action/analyze@05963f47d870e2cb19a537396c1f668a348c7d8f # v3.24.8
        with:
          category: "/language:javascript"

  typecheck:
    runs-on: ${{ matrix.os }}
    timeout-minutes: 10
    needs:
      - build
    strategy:
      fail-fast: false
      matrix:
        os: [ubuntu-latest, windows-latest]
        module: ["bundler", "node"]

    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
      - run: corepack enable
      - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
        with:
          node-version: 20
          cache: "pnpm"

      - name: Install dependencies
        run: pnpm install

      - name: Restore dist cache
        uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707a7f8427 # v4.1.4
        with:
          name: dist
          path: packages

      - name: Test (types)
        run: pnpm test:types
        env:
          MODULE_RESOLUTION: ${{ matrix.module }}

      - name: Typecheck (docs)
        run: pnpm typecheck:docs

  lint:
    # autofix workflow will be triggered instead for PRs
    if: github.event_name == 'push'
    runs-on: ubuntu-latest
    timeout-minutes: 10

    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
      - run: corepack enable
      - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
        with:
          node-version: 20
          cache: "pnpm"

      - name: Install dependencies
        run: pnpm install

      - name: Build (stub)
        run: pnpm dev:prepare

      - name: Lint
        run: pnpm lint

  test-unit:
    # autofix workflow will be triggered instead for PRs
    if: github.event_name == 'push'
    runs-on: ubuntu-latest
    timeout-minutes: 10
    needs:
      - build
    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
      - run: corepack enable
      - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
        with:
          node-version: 20
          cache: "pnpm"

      - name: Install dependencies
        run: pnpm install

      - name: Build (stub)
        run: pnpm dev:prepare

      - name: Test (unit)
        run: pnpm test:unit

      - name: Test (runtime unit)
        run: pnpm test:runtime

  test-fixtures:
    runs-on: ${{ matrix.os }}
    needs:
      - build

    strategy:
      fail-fast: false
      matrix:
        os: [ubuntu-latest, windows-latest]
        env: ["dev", "built"]
        builder: ["vite", "webpack"]
        context: ["async", "default"]
        manifest: ["manifest-on", "manifest-off"]
        node: [18]
        exclude:
          - env: "dev"
            builder: "webpack"
          - manifest: "manifest-off"
            builder: "webpack"

    timeout-minutes: 15

    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
      - run: corepack enable
      - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
        with:
          node-version: ${{ matrix.node }}
          cache: "pnpm"

      - name: Install dependencies
        run: pnpm install

      - name: Install Playwright
        run: pnpm playwright-core install chromium

      - name: Restore dist cache
        uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707a7f8427 # v4.1.4
        with:
          name: dist
          path: packages

      - name: Test (fixtures)
        run: pnpm test:fixtures
        env:
          TEST_ENV: ${{ matrix.env }}
          TEST_BUILDER: ${{ matrix.builder }}
          TEST_MANIFEST: ${{ matrix.manifest }}
          TEST_CONTEXT: ${{ matrix.context }}
          SKIP_BUNDLE_SIZE: ${{ github.event_name != 'push' || matrix.env == 'dev' || matrix.builder == 'webpack' || matrix.context == 'default' || runner.os == 'Windows' }}

      - uses: codecov/codecov-action@54bcd8715eee62d40e33596ef5e8f0f48dbbccab # v4.1.0
        if: github.event_name != 'push' && matrix.env == 'built' && matrix.builder == 'vite' && matrix.context == 'default' && matrix.os == 'ubuntu-latest' && matrix.manifest == 'manifest-on'
        with:
          token: ${{ secrets.CODECOV_TOKEN }}

  build-release:
    permissions:
      id-token: write
    if: |
      github.event_name == 'push' &&
      github.repository == 'nuxt/nuxt' &&
      !contains(github.event.head_commit.message, '[skip-release]') &&
      !startsWith(github.event.head_commit.message, 'chore') &&
      !startsWith(github.event.head_commit.message, 'docs')
    needs:
      - lint
      - build
      - test-fixtures
    runs-on: ubuntu-latest
    timeout-minutes: 20

    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
        with:
          fetch-depth: 0
      - run: corepack enable
      - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
        with:
          node-version: 20
          cache: "pnpm"

      - name: Install dependencies
        run: pnpm install

      - name: Restore dist cache
        uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707a7f8427 # v4.1.4
        with:
          name: dist
          path: packages

      - name: Release Edge
        run: ./scripts/release-edge.sh
        env:
          NODE_AUTH_TOKEN: ${{secrets.NODE_AUTH_TOKEN}}
          NPM_CONFIG_PROVENANCE: true

  release-pr:
    permissions:
      id-token: write
      pull-requests: write
    if: |
      github.event_name == 'pull_request' &&
      contains(github.event.pull_request.labels.*.name, '🧷 edge release')
    needs:
      - lint
      - build
      - test-fixtures
    runs-on: ubuntu-latest
    timeout-minutes: 20

    steps:
      - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
        with:
          fetch-depth: 0
      - run: corepack enable
      - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
        with:
          node-version: 20
          cache: "pnpm"

      - name: Install dependencies
        run: pnpm install

      - name: Restore dist cache
        uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707a7f8427 # v4.1.4
        with:
          name: dist
          path: packages

      - name: Release Edge
        run: ./scripts/release-edge.sh pr-${{ github.event.issue.number }}
        env:
          NODE_AUTH_TOKEN: ${{secrets.NODE_AUTH_TOKEN}}
          NPM_CONFIG_PROVENANCE: true