diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 230eaff..dd0cc61 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -287,6 +287,27 @@ jobs: - name: Run config schema test suite run: node --test tests/config-schema.test.mjs + # E00-S04-T05: the static assertions of tests/env-example.test.mjs gate every + # PR — the suite locks in the committed `.env.example` template: it exists at + # the repo root, is un-ignored in .gitignore (real `.env` files stay ignored + # while the example is tracked), documents every configuration environment + # source (HOST/PORT/DATABASE_URL/EPPP_SESSION_SECRET), and contains + # placeholder values only — no credential URI, no long secret-looking value, + # and no compose default credential — with mutation probes proving the + # assertions are non-vacuous. The test needs no dependencies, so the job + # only installs Node. + env-example: + name: .env.example placeholders only (E00-S04-T05) + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: Install Node.js 24 + uses: actions/setup-node@v4 + with: + node-version: '24' + - name: Run .env.example test suite + run: node --test tests/env-example.test.mjs + # E00-S03-T01: the static assertions of tests/compose-config.test.mjs (db # image pinned to postgres:18.6-bookworm, health gate, volume persistence, # build platforms) gate every PR (the docker-gated real-stack probes inside