CI/CD Pipeline
Lumio's pipelines live in .github/workflows.
CI pipeline
ci.yml runs on pull requests and on pushes to main and develop:
sensitive-changes- label gate on pull requests (see below)policy-as-code- Conftest policies for the Compose files and workflowsshellcheck,hadolint,trivy-config- shell script, Dockerfile, and config scanninglint- Biome for the backend, Biome + ESLint for the frontendtypecheck- TypeScript checks for both appstests- backend unit + e2e tests against PostgreSQL 16 and Redis 7, with migrations applied twice to check idempotencysonarcloud- static analysis with the backend coverage reportbuild- frontend and backend production buildsdependency-scan- npm audits and license checks for every packagesecrets-scan- Gitleaksdocker- image build with a Trivy scan and SBOM
Frontend Vitest tests are not part of CI.
Sensitive change protection
On pull requests, the sensitive-changes job requires labels:
db-approvedfor migrations, entities, orbackend/src/data-source.tssecurity-approvedfor the auth module,common/guards,common/decorators, or permissions/roles code
CD pipeline
Lumio is self-hosted: cd.yml builds, scans, signs, and publishes images, then stops. There are no deployment
environments and no smoke tests. It runs on v*.*.* tags or manual dispatch:
- Conftest policies
- Waits for CI to succeed on the commit
- Builds multi-arch (amd64, arm64) backend, frontend, and combined images and pushes them to GHCR, tagged
sha-<commit>plus the version andlateston release tags - SLSA provenance attestation and a Trivy scan of the pushed image
- SPDX SBOM with attestation, and a cosign attestation
- On tags, a GitHub release with the SBOM attached
Other workflows
codeql.yml- CodeQL on pushes and pull requests tomain/develop, plus weeklydependency-review.yml- dependency review on pull requestsscorecard.yml- OpenSSF Scorecard, weeklymakefile.yml- checks thatmake buildworksdocs.yml- builds this site and deploys it to GitHub Pages whenwebsite/changes onmainrelease-please.yml- semantic versioning and releaseschangelog.yml- regenerates the in-app changelog data (frontend/public/changelog.json) onmain
Next: Makefile Reference