diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml new file mode 100644 index 0000000..175761f --- /dev/null +++ b/.github/workflows/tests.yml @@ -0,0 +1,80 @@ +# The Pester suite, on every push to main and every PR. +# +# This repo is one of the twelve on the fleet board +# (evomedia.net/testsuites.html) and was one of three with no CI at all, so the +# only thing ever running these tests was a workstation at 04:00. That is a +# poor place for the only copy of a check to live. +# +# windows-latest, not ubuntu, even though Pester runs on Linux: these scripts +# deploy from a Windows workstation and the suite reads like it - paths, +# executables, the shell itself. Proving them on Linux would be proving +# something nobody runs. Windows minutes bill at double, which this suite's +# size affords. +name: tests + +on: + push: + branches: [main] + pull_request: + +# Read-only: this job builds nothing and publishes nothing, so the default +# write-capable token is more than it needs. +permissions: + contents: read + +concurrency: + group: tests-${{ github.ref }} + cancel-in-progress: true + +jobs: + test: + runs-on: windows-latest + timeout-minutes: 15 + steps: + # Actions pinned to a commit, not a moving tag: a tag can be repointed + # by whoever owns it, and this token, read-only though it is, still sees + # the repository. + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + + # Pester pinned to 5.x: the suite is written against the v5 configuration + # API (New-PesterConfiguration), and Windows images still carry a v3 in + # the module path that would be picked ahead of it. PSScriptAnalyzer is + # the PowerShell linter; there is no typecheck for PowerShell, so the + # analyzer is the whole of that half. + - name: Install Pester 5 and PSScriptAnalyzer + shell: powershell + run: | + Set-PSRepository -Name PSGallery -InstallationPolicy Trusted + Install-Module Pester -MinimumVersion 5.5.0 -MaximumVersion 5.99.99 ` + -Force -SkipPublisherCheck -Scope CurrentUser + Install-Module PSScriptAnalyzer -Force -Scope CurrentUser + Import-Module Pester -MinimumVersion 5.5.0 + 'Pester ' + (Get-Module Pester).Version + ', PSScriptAnalyzer ' + (Get-Module -ListAvailable PSScriptAnalyzer | Select-Object -First 1).Version + + # Errors fail the job; warnings are printed and do not. The repo was + # written without the analyzer, and turning every style warning into a + # red build on day one would make the gate something to disable rather + # than something to keep. PSAvoidUsingWriteHost is excluded outright: + # these are command-line tools whose Write-Host output IS the interface. + - name: Lint (PSScriptAnalyzer) + shell: powershell + run: | + $r = Invoke-ScriptAnalyzer -Path . -Recurse -ExcludeRule PSAvoidUsingWriteHost + $warn = @($r | Where-Object Severity -eq Warning) + $err = @($r | Where-Object Severity -eq Error) + if ($warn) { + Write-Host ("{0} warning(s), not failing the build:" -f $warn.Count) + $warn | Format-Table RuleName, ScriptName, Line -AutoSize | Out-String | Write-Host + } + if ($err) { + $err | Format-Table RuleName, ScriptName, Line, Message -AutoSize -Wrap | Out-String | Write-Host + throw ("PSScriptAnalyzer: {0} error(s)" -f $err.Count) + } + Write-Host "no errors" + + # -CI sets the exit code from the result, which is the whole point here: + # Invoke-Pester on its own reports failures and still exits 0, so the + # job would go green with a red suite. + - name: Tests + shell: powershell + run: Invoke-Pester -Path tests -CI