mirror of
https://github.com/opensourcepos/opensourcepos.git
synced 2026-07-26 14:47:06 -04:00
Security fixes: - Use jq for JSON payload construction (prevents script injection) - Add HMAC-SHA256 signature verification for webhook security - Move untrusted inputs to env: blocks instead of inline interpolation Robustness fixes: - Add curl timeouts (--connect-timeout 10, --max-time 120) - Fail when DEPLOY_WEBHOOK_URL is missing (was incorrectly succeeding) - Add set -euo pipefail for error handling - Fix required_contexts JSON array syntax (-F required_contexts[]) - Add deployment: false to prevent duplicate deployment records Workflow improvements: - Add concurrency groups to serialize same-environment deployments - Remove unused skip_approval input - Fix workflow_call inputs (removed required: true where default exists) - Use vars.DEPLOY_URL for configurable environment URLs
GitHub Actions
This document describes the CI/CD workflows for OSPOS.
Build and Release Workflow (.github/workflows/build-release.yml)
Build Process
- Setup PHP 8.2 with required extensions
- Setup Node.js 20
- Install composer dependencies
- Install npm dependencies
- Build frontend assets with Gulp
Docker Images
- Build and push
opensourceposDocker image for multiple architectures (linux/amd64, linux/arm64) - On master: tagged with version and
latest - On other branches: tagged with version only
- Pushed to Docker Hub
Releases
- Create distribution archives (tar.gz, zip)
- Create/update GitHub "unstable" release on master branch only
Required Secrets
To use this workflow, you need to add the following secrets to your repository:
- DOCKER_USERNAME - Docker Hub username for pushing images
- DOCKER_PASSWORD - Docker Hub password/token for pushing images
How to add secrets
- Go to your repository on GitHub
- Click Settings → Secrets and variables → Actions
- Click New repository secret
- Add
DOCKER_USERNAMEandDOCKER_PASSWORD
The GITHUB_TOKEN is automatically provided by GitHub Actions.
Workflow Triggers
- Push to master - Runs build, Docker push (with
latesttag), and release - Push to other branches - Runs build and Docker push (version tag only)
- Push tags - Runs build and Docker push (version tag only)
- Pull requests - Runs build only (PHPUnit tests run in parallel via phpunit.yml)
Existing Workflows
This repository also has these workflows:
.github/workflows/main.yml- PHP linting with PHP-CS-Fixer.github/workflows/phpunit.yml- PHPUnit tests (runs on all PHP versions 8.1-8.4).github/workflows/php-linter.yml- PHP linting
Testing
PHPUnit tests are run separately via .github/workflows/phpunit.yml on every push and pull request, testing against PHP 8.1, 8.2, 8.3, and 8.4.
To test the build workflow:
- Add the required secrets
- Push to master or create a PR
- Monitor the Actions tab in GitHub