# Copyright 2020 Signal Messenger, LLC # SPDX-License-Identifier: AGPL-3.0-only name: CI on: push: branches: - development - main - '[0-9]+.[0-9]+.x' pull_request: permissions: contents: read jobs: dependencies: name: Dependencies runs-on: ubuntu-22.04-8-cores timeout-minutes: 5 steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: filter: blob:none - name: Setup environment uses: ./.github/actions/setup - name: Run pnpmfile tests background: true run: node --test .pnpmfile.mjs - name: Audit dependencies background: true run: pnpm audit --audit-level=high - name: Audit dependency signatures background: true run: pnpm audit signatures - name: Check for duplicate dependencies background: true run: pnpm dedupe --check lint: name: Lint runs-on: ubuntu-22.04-8-cores timeout-minutes: 5 steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: filter: blob:none - name: Setup environment uses: ./.github/actions/setup with: apt-packages: libpulse0 - id: generate name: Run generate background: true run: pnpm run generate - name: Check license comments background: true run: pnpm run lint-license-comments - name: Check prettier background: true run: pnpm run lint-prettier --cache-location=~/.cache/prettier - name: Lint styles background: true run: pnpm run lint-css - name: Lint deps background: true run: pnpm run lint-deps - name: Lint intl background: true run: pnpm run lint-intl - name: Check Knip (All) background: true run: pnpm run lint-knip:all --reporter github-actions - name: Check Knip (Prod) background: true run: pnpm run lint-knip:prod --reporter github-actions - name: Check acknowledgments background: true run: | pnpm run build:acknowledgments git diff --exit-code env: REQUIRE_SIGNAL_LIB_FILES: 1 # wait for only `generate` instead of having two separate parallel groups so # these additional steps can run as soon as generate is done instead of # waiting for all of the tasks of the previous `parallel` group - name: Wait for generate wait: generate - name: Check database schema background: true run: pnpm run build:db-schema --check - name: Check TypeScript background: true run: pnpm run check:types - name: Check Oxlint background: true run: pnpm run oxlint:ci macos: name: MacOS runs-on: macos-26 if: github.ref == 'refs/heads/main' timeout-minutes: 15 steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: filter: blob:none - name: Setup environment uses: ./.github/actions/setup with: cache-electron-builder: true - name: Prepare beta build run: pnpm run prepare-beta-build - name: Run generate run: pnpm run generate - name: Run node tests run: pnpm run test-node - name: Run electron tests run: pnpm run test-electron env: ARTIFACTS_DIR: artifacts/macos WORKER_COUNT: 4 timeout-minutes: 5 - name: Build release run: | touch noop.sh chmod +x noop.sh pnpm run build:release env: DISABLE_INSPECT_FUSE: on SIGN_MACOS_SCRIPT: noop.sh ARTIFACTS_DIR: artifacts/macos - name: Upload installer size if: ${{ github.repository == 'signalapp/Signal-Desktop-Private' && github.ref == 'refs/heads/main' }} run: | node scripts/publish-installer-size.mjs macos-arm64 node scripts/publish-installer-size.mjs macos-x64 node scripts/publish-installer-size.mjs macos-universal - name: Run release tests run: pnpm run test-release env: NODE_ENV: production - name: Upload artifacts on failure if: failure() uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: path: artifacts linux: name: Linux runs-on: ${{ matrix.os }} timeout-minutes: 15 strategy: matrix: include: - os: ubuntu-22.04-8-cores arch: x64 - os: ubuntu-22.04-arm64-4-cores arch: arm64 steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup environment uses: ./.github/actions/setup with: apt-packages: xvfb libpulse0 cache-electron-builder: true - name: Prepare beta builde run: pnpm run prepare-beta-build - name: Run generate run: pnpm run generate - name: Run node tests run: xvfb-run --auto-servernum pnpm run test-node - name: Create preload cache run: xvfb-run --auto-servernum pnpm run build:preload-cache env: ARTIFACTS_DIR: artifacts/linux - name: Set Linux build target architecture run: pnpm run prepare-linux-build deb ${{ matrix.arch }} - name: Build with packaging .deb file run: pnpm run build:release --publish=never if: github.ref == 'refs/heads/main' env: CC: sccache gcc CXX: sccache g++ SCCACHE_GHA_ENABLED: true DISABLE_INSPECT_FUSE: on - name: Build without packaging .deb file run: pnpm run build:release --linux dir if: github.ref != 'refs/heads/main' env: CC: sccache gcc CXX: sccache g++ SCCACHE_GHA_ENABLED: true DISABLE_INSPECT_FUSE: on - name: Upload installer size if: ${{ github.repository == 'signalapp/Signal-Desktop-Private' && github.ref == 'refs/heads/main' }} run: node scripts/publish-installer-size.mjs linux-${{ matrix.arch }} - name: Clone backup integration tests uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: repository: 'signalapp/Signal-Message-Backup-Tests' ref: 'a0f900243210efbedc72f0907c5d2f140385daa4' path: 'backup-integration-tests' - name: Run electron tests run: xvfb-run --auto-servernum pnpm run test-electron timeout-minutes: 5 env: ARTIFACTS_DIR: artifacts/linux LANG: en_US LANGUAGE: en_US BACKUP_INTEGRATION_DIR: 'backup-integration-tests/test-cases' WORKER_COUNT: 8 - name: Run release tests run: xvfb-run --auto-servernum pnpm run test-release env: NODE_ENV: production - name: Upload artifacts on failure if: failure() uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: path: artifacts windows: name: Windows runs-on: windows-latest-8-cores timeout-minutes: 15 steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup environment uses: ./.github/actions/setup with: cache-electron-builder: true - name: Remove certificate fields from package.json run: | copy package.json temp.json del package.json type temp.json | findstr /v certificateSubjectName | findstr /v certificateSha1 > package.json - name: Prepare beta build run: pnpm run prepare-beta-build - name: Run generate run: pnpm run generate - name: Run node tests run: pnpm run test-node - name: Create preload cache run: pnpm run build:preload-cache env: ARTIFACTS_DIR: artifacts/win - name: Build with NSIS run: pnpm run build:release --publish=never if: github.ref == 'refs/heads/main' env: DISABLE_INSPECT_FUSE: on - name: Build without NSIS run: pnpm run build:release --win dir if: github.ref != 'refs/heads/main' env: DISABLE_INSPECT_FUSE: on - name: Upload installer size if: ${{ github.repository == 'signalapp/Signal-Desktop-Private' && github.ref == 'refs/heads/main' }} run: node scripts/publish-installer-size.mjs windows - name: Run electron tests run: pnpm run test-electron env: ARTIFACTS_DIR: artifacts/windows WORKER_COUNT: 4 timeout-minutes: 5 - name: Run release tests run: pnpm run test-release env: SIGNAL_ENV: production - name: Upload artifacts on failure if: failure() uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: path: artifacts sticker-creator: name: Sticker Creator runs-on: ubuntu-22.04-8-cores timeout-minutes: 5 defaults: run: working-directory: sticker-creator steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup environment uses: ./.github/actions/setup - name: Check build background: true run: pnpm run build - name: Check types background: true run: pnpm run check:types - name: Check formatting background: true run: pnpm run prettier:check - name: Check lint background: true run: pnpm run lint mock-tests: name: Mock Tests ${{ matrix.withoutE164.name }} ${{ matrix.workerIndex.name }} strategy: fail-fast: false matrix: withoutE164: - name: "(with e164)" value: false - name: "(without e164)" value: true workerIndex: - name: '[1/4]' value: 0 - name: '[2/4]' value: 1 - name: '[3/4]' value: 2 - name: '[4/4]' value: 3 runs-on: ubuntu-latest-16-cores if: ${{ github.repository == 'signalapp/Signal-Desktop-Private' }} timeout-minutes: 15 steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup environment uses: ./.github/actions/setup with: apt-packages: xvfb libpulse0 install-electron: true - name: Run generate run: pnpm run generate - name: Create preload cache run: xvfb-run --auto-servernum pnpm run build:preload-cache env: ARTIFACTS_DIR: artifacts/linux - name: Run mock server tests run: | set -o pipefail xvfb-run --auto-servernum pnpm run test-mock timeout-minutes: 15 env: NODE_ENV: production DEBUG: mock:test:* ARTIFACTS_DIR: artifacts/mock WORKER_INDEX: ${{ matrix.workerIndex.value }} WORKER_COUNT: 4 MOCK_WITHOUT_E164: ${{ case(matrix.withoutE164.value, 'on', '') }} - name: Run docker mock server tests if: ${{ matrix.workerIndex.value == 0 }} run: | set -o pipefail sudo apt-get install -y pipewire pipewire-pulse wireplumber psmisc pulseaudio-utils systemctl --user start pipewire.service systemctl --user start pipewire-pulse.service xvfb-run --auto-servernum pnpm run test-mock-docker timeout-minutes: 10 env: NODE_ENV: production DEBUG: mock:test:* ARTIFACTS_DIR: artifacts/mock-docker - name: Upload mock server test logs on failure if: failure() uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: logs-${{ matrix.workerIndex.value }} path: artifacts check-min-os-version: name: Check Min OS Version strategy: fail-fast: false matrix: os: - ubuntu-22.04-8-cores - macos-26 - windows-latest-8-cores runs-on: ${{ matrix.os }} timeout-minutes: 5 steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: filter: blob:none - name: Setup environment uses: ./.github/actions/setup - name: Run OS version check run: | node scripts/check-min-os-version.mjs danger: name: Danger runs-on: ubuntu-latest-8-cores timeout-minutes: 5 if: github.event_name == 'pull_request' steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: filter: blob:none - name: Setup danger environment uses: pnpm/setup@84cb39b217b10273981911c288cd62326dc7c6d2 # v2.0.2 with: cache: true package-json-file: danger/package.json cache-dependency-path: danger/pnpm-lock.yaml install: false # skip install to focus on just danger/ package and to run `pnpm install --frozen-lockfile` - name: Install danger dependencies run: pnpm install --frozen-lockfile working-directory: danger - name: Run danger checks run: pnpm run danger:ci working-directory: danger env: DANGER_GITHUB_API_TOKEN: ${{ secrets.AUTOMATED_GITHUB_PAT }} storybook: name: Storybook runs-on: ubuntu-latest-16-cores timeout-minutes: 5 steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup environment uses: ./.github/actions/setup with: install-playwright: true - name: Build storybook run: pnpm run build:storybook - id: storybook-server name: Serve storybook background: true run: pnpm run test:storybook:serve - name: Run storybook tests run: pnpm run test:storybook:test - name: Stop storybook server cancel: storybook-server benchmark: name: Benchmark strategy: matrix: metric: - startup - send - groupSend - largeGroupSendWithBlocks - largeGroupSend - convoOpen - callHistorySearch - backup include: - metric: startup script: ts/test-mock/benchmarks/startup_bench.node.js runCount: 10 - metric: send script: ts/test-mock/benchmarks/send_bench.node.js runCount: 100 - metric: groupSend script: ts/test-mock/benchmarks/group_send_bench.node.js runCount: 100 conversationSize: 500 - metric: largeGroupSendWithBlocks script: ts/test-mock/benchmarks/group_send_bench.node.js runCount: 50 conversationSize: 500 groupSize: 500 contactCount: 500 blockedCount: 10 discardCount: 2 - metric: largeGroupSend script: ts/test-mock/benchmarks/group_send_bench.node.js runCount: 20 conversationSize: 50 groupSize: 500 contactCount: 500 discardCount: 2 - metric: convoOpen script: ts/test-mock/benchmarks/convo_open_bench.node.js runCount: 100 - metric: callHistorySearch script: ts/test-mock/benchmarks/call_history_search_bench.node.js runCount: 100 - metric: backup script: ts/test-mock/benchmarks/backup_bench.node.js runs-on: ubuntu-22.04-8-cores if: ${{ github.repository == 'signalapp/Signal-Desktop-Private' }} timeout-minutes: 15 steps: - name: Checkout code uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup environment uses: ./.github/actions/setup with: apt-packages: xvfb libpulse0 - name: Run generate run: pnpm run generate - name: Create preload cache run: xvfb-run --auto-servernum pnpm run build:preload-cache - name: Set MAX_CYCLES=2 on main if: ${{ github.ref == 'refs/heads/main' }} run: | echo "MAX_CYCLES=2" >> "$GITHUB_ENV" - name: Run ${{ matrix.metric }} run: | set -o pipefail xvfb-run --auto-servernum ./node_modules/.bin/tsx \ ${{ matrix.script }} | tee benchmark.log timeout-minutes: 10 env: NODE_ENV: production ELECTRON_ENABLE_STACK_DUMPING: on DEBUG: 'mock:benchmarks' ARTIFACTS_DIR: artifacts/${{ matrix.metric }} GROUP_SIZE: ${{ matrix.groupSize }} CONTACT_COUNT: ${{ matrix.contactCount }} BLOCKED_COUNT: ${{ matrix.blockedCount }} DISCARD_COUNT: ${{ matrix.discardCount }} RUN_COUNT: ${{ matrix.runCount }} CONVERSATION_SIZE: ${{ matrix.conversationSize }} - name: Upload benchmark logs on failure if: failure() uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 with: name: logs path: artifacts - name: Clone benchmark repo uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 with: repository: 'signalapp/Signal-Desktop-Benchmarks-Private' path: 'benchmark-results' token: ${{ secrets.AUTOMATED_GITHUB_PAT }} - name: Build benchmark repo working-directory: benchmark-results run: | pnpm install pnpm run build - name: Publish working-directory: benchmark-results run: | node ./bin/publish.js ../benchmark.log desktop.ci.performance.${{ matrix.metric }} env: OTEL_EXPORTER_OTLP_ENDPOINT: ${{ secrets.OTEL_EXPORTER_OTLP_ENDPOINT }} OTEL_EXPORTER_OTLP_PROTOCOL: ${{ secrets.OTEL_EXPORTER_OTLP_PROTOCOL }} OTEL_EXPORTER_OTLP_HEADERS: ${{ secrets.OTEL_EXPORTER_OTLP_HEADERS }} auto-merge-ready: if: | always() && github.event_name == 'pull_request' && github.repository == 'signalapp/Signal-Desktop-Private' name: Auto Merge Ready needs: - lint - linux - windows - sticker-creator - mock-tests - check-min-os-version - danger - storybook - benchmark runs-on: ubuntu-latest steps: - name: Check if any jobs failed or were cancelled if: | contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') run: | echo "One or more upstream jobs failed" exit 1