Bundle budget was warning-only: initial warning 700 kB, error 1.8 MB. Measured today the initial bundle is 1.55 MB raw / 324.58 kB transfer - up from the 1.15 MB measured on 11 August, so it had been growing with nothing to stop it. Lowers maximumError to 1.6 MB. That is a ratchet, not a target: just above today's size so the bundle cannot grow, with the 700 kB warning left in place as the goal. Lower it each time the number comes down. Adds scripts/ci/scan-bundle.sh (npm run scan:bundle), run in CI after the build. Seven patterns: both provider auth headers, the partner ID shape, client_secret, private key blocks, AWS keys, Telegram bot tokens. The legacy payment code that put credentials in the browser is already deleted; this is what stops it coming back. Verified in both directions - clean against the real dist, exit 1 against a planted credential. Measurement also corrected two assumptions recorded in the harvest TODO: admin and editor code is already lazy-loaded, so the initial bundle is main alone rather than a deployable-split problem; and mock gateway fixtures do reach production chunks, which is now filed as FH-E.6 with the cause identified. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
60 lines
1.7 KiB
YAML
60 lines
1.7 KiB
YAML
name: Architecture Governance
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- '**'
|
|
pull_request:
|
|
|
|
jobs:
|
|
architecture:
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup Node
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 24
|
|
cache: npm
|
|
|
|
- name: Install Dependencies
|
|
run: npm ci
|
|
|
|
- name: Enforce Boundaries
|
|
run: npm run arch:check
|
|
|
|
# Was entirely missing before 2026-08-18: this workflow built and
|
|
# checked boundaries but never ran a single test. karma.conf.js's
|
|
# CHROME_BIN fallback is a Windows path, which the ubuntu-latest
|
|
# runner doesn't have - browser-actions/setup-chrome supplies one
|
|
# and CHROME_BIN below points at it explicitly.
|
|
- name: Setup Chrome
|
|
id: setup-chrome
|
|
uses: browser-actions/setup-chrome@v1
|
|
|
|
- name: Unit tests with coverage gate
|
|
env:
|
|
CHROME_BIN: ${{ steps.setup-chrome.outputs.chrome-path }}
|
|
run: npm run test:coverage
|
|
|
|
# The production build is what enforces the bundle budget. The initial
|
|
# bundle sits at ~1.55 MB raw against a 700 kB target, so the error
|
|
# threshold is a ratchet, not the goal: it is set just above today's
|
|
# size so the bundle cannot grow while we work it back down. Lower the
|
|
# ratchet in angular.json every time it comes down.
|
|
- name: Build
|
|
run: npm run build
|
|
|
|
# Stops payment credentials returning to the browser bundle. See
|
|
# scripts/ci/scan-bundle.sh for what it looks for and why.
|
|
- name: Scan bundle for credentials
|
|
run: npm run scan:bundle
|
|
|
|
- name: E2E
|
|
run: |
|
|
npx playwright install --with-deps chromium
|
|
npm run e2e
|