Commit Graph

21 Commits

Author SHA1 Message Date
40b4dc50f1 Replace anchore/sbom-action with direct Syft CLI install
All checks were successful
CI/CD Pipeline - Apartment API / Scan Dependencies (pull_request) Successful in 13s
CI/CD Pipeline - Apartment API / Lint & Test (pull_request) Successful in 43s
CI/CD Pipeline - Apartment API / Send Webhook Notification (pull_request) Successful in 2s
CI/CD Pipeline - Apartment API / Build & Push Image (pull_request) Has been skipped
CI/CD Pipeline - Apartment API / Deploy to Production (pull_request) Has been skipped
The anchore/sbom-action GitHub Action uses upload-artifact@v4 internally,
which is not supported on GHES. Install Syft directly via CLI and run it
as a shell command to generate the SBOM without the artifact upload.
2026-02-08 20:23:20 -07:00
6f1651436d Fix webhook notification failure when CI tests produce large output
Truncate lint/test output to 10000 chars at the source (CI job) before
writing to GITHUB_OUTPUT, instead of in the downstream notify job.
Previously the full output was passed as an env var between jobs, which
could exceed Linux's ARG_MAX limit and prevent bash from launching.
2026-02-07 10:51:28 -07:00
d818296eeb Restore --runInBand for test stability in merged CI job
Phase tests share a single MongoMemoryServer database and conflict
when run in parallel. Sequential execution is needed until tests
use isolated databases per file.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-06 10:11:34 -07:00
3509da8185 Speed up CI pipeline: merge lint+test, remove runInBand, drop unused mongo service
- Combine lint and test into a single 'ci' job (eliminates duplicate
  checkout + npm ci, saving ~60-90s)
- Remove --runInBand flag so Jest parallelizes across worker pools
- Remove unused mongo:7 service container (tests use MongoMemoryServer)
- Fix failure detection: check step outcomes instead of job result,
  which was always 'success' due to continue-on-error

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-06 09:54:02 -07:00
0ad4c98abe SCRAPE-11: Create main runScraper() orchestration function (#16)
## Summary

Implements the top-level runScrape() orchestration function that coordinates the entire scraper pipeline end-to-end.

### What it does

- Full pipeline orchestration: Calls fetchPage, parseUnits, convertDataTypes, upsertUnits, insertPrices, markStaleUnits, updateDailySummary in sequence
- dryRun mode: When enabled, parses and validates HTML but skips all database writes
- htmlContent injection: Accepts raw HTML directly, bypassing the fetch step
- New/rented unit calculation: Diffs currently scraped units against previously active units to determine newUnitsCount and rentedUnitsCount for the daily summary
- Run history recording: Every scrape (success or failure) is recorded to the scraper_runs collection via recordScraperRun()
- Structured logging: All pipeline stages log with jobId correlation for traceability
- Error resilience: Catches and handles errors at each stage, ensuring partial failures are logged and recorded

### Test coverage (15 tests)

- Full workflow with mocked dependencies
- Result structure validation and jobId generation
- dryRun mode skips DB writes
- htmlContent bypasses fetch
- Success and failure history recording
- Fetch error handling with retry exhaustion
- Database operation error handling
- New/rented unit count calculation
- Default and scheduled trigger types
- Empty HTML (no units) edge case

Reviewed-on: #16
Co-authored-by: Stephen Minakian <stephenminakian@gmail.com>
Co-committed-by: Stephen Minakian <stephenminakian@gmail.com>
2026-02-06 09:45:32 -07:00
d1f717891a SCRAPE-10: Implement recordScraperRun() for scraper_runs (#15)
Co-authored-by: Stephen Minakian <stephenminakian@gmail.com>
Co-committed-by: Stephen Minakian <stephenminakian@gmail.com>
2026-02-06 02:00:19 -07:00
2993d019c5 SCRAPE-2: Add scraper config constants (#7) 2026-01-31 20:54:43 -07:00
3af5a90c93 Add PR number to webhook payload
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-28 10:54:12 -07:00
6daacf4d12 Add ESLint and n8n webhook notifications to CI/CD
- Add ESLint 9 with flat config for Node.js linting
- Add lint and lint:fix npm scripts
- Add lint job to CI/CD pipeline
- Add notify job to send test/lint results to n8n webhook
- Webhook reports pass/fail status with failure details

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-28 09:39:55 -07:00
8dfdfdc8bb Fix security vulnerabilities and add early dependency scanning
Some checks failed
CI/CD Pipeline - Apartment API / Scan Dependencies (push) Successful in 18s
CI/CD Pipeline - Apartment API / Run Tests (push) Successful in 10m20s
CI/CD Pipeline - Apartment API / Build & Push Image (push) Failing after 3m8s
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been skipped
- Update to node:20-alpine base image
- Add apk upgrade to fix OS-level vulnerabilities
- Update npm to latest to fix bundled package vulnerabilities
- Add scan-deps job that runs in parallel with tests
- Replace deprecated --only=production with --omit=dev
2026-01-23 16:10:45 -07:00
fa0377f5e3 Fix Trivy action compatibility with Gitea runner
Some checks failed
CI/CD Pipeline - Apartment API / Run Tests (push) Successful in 9m40s
CI/CD Pipeline - Apartment API / Build & Push Image (push) Failing after 38s
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been skipped
Replace aquasecurity/trivy-action with direct Trivy installation
to avoid node24 compatibility issues with act-based runners
2026-01-23 15:22:17 -07:00
2d7b412c1a Add image signing, SBOM generation, and vulnerability scanning to CI/CD
Some checks failed
CI/CD Pipeline - Apartment API / Run Tests (push) Successful in 9m42s
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been cancelled
CI/CD Pipeline - Apartment API / Build & Push Image (push) Has been cancelled
- Add Trivy vulnerability scanning (fails on CRITICAL/HIGH)
- Add Syft SBOM generation in SPDX format
- Add Cosign image signing using digest
- Attach SBOM attestation to image in Harbor
- Add cosign.pub for signature verification
2026-01-23 14:55:01 -07:00
b584dc94d4 Remove inline docker login from deploy script
All checks were successful
CI/CD Pipeline - Apartment API / Run Tests (push) Successful in 9m41s
CI/CD Pipeline - Apartment API / Build & Push Image (push) Successful in 24s
CI/CD Pipeline - Apartment API / Deploy to Production (push) Successful in 14s
Use pre-configured Docker credentials on server instead of passing
Harbor credentials through SSH script, avoiding shell interpolation
issues with special characters in robot account username.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-22 16:43:58 -07:00
62daabc1c3 Remove GitHub Actions cache - not supported by Gitea
Some checks failed
CI/CD Pipeline - Apartment API / Build & Push Image (push) Successful in 24s
CI/CD Pipeline - Apartment API / Run Tests (push) Successful in 9m41s
CI/CD Pipeline - Apartment API / Deploy to Production (push) Failing after 4s
Gitea Actions doesn't support type=gha caching, causing timeout errors.
Removing cache config to get builds working. Can add registry-based
caching later if needed.
2026-01-22 16:10:09 -07:00
cbb5c1ce48 Fix port conflict: use port 27018 for test MongoDB
Some checks failed
CI/CD Pipeline - Apartment API / Run Tests (push) Successful in 9m47s
CI/CD Pipeline - Apartment API / Build & Push Image (push) Failing after 1m24s
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been skipped
Host machine already has MongoDB on 27017, so map the test
container to 27018 instead to avoid port allocation conflict.
2026-01-22 15:43:04 -07:00
47743656e2 Remove git pull - using dedicated deployment directory
Some checks failed
CI/CD Pipeline - Apartment API / Run Tests (push) Failing after 1s
CI/CD Pipeline - Apartment API / Build & Push Image (push) Has been skipped
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been skipped
2026-01-22 15:33:15 -07:00
f0c674d877 Add git pull to deployment to sync docker-compose.yml 2026-01-22 15:29:36 -07:00
d3733dbebe Fix CI/CD best practice violations
Some checks failed
CI/CD Pipeline - Apartment API / Run Tests (push) Failing after 1s
CI/CD Pipeline - Apartment API / Build & Push Image (push) Has been skipped
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been skipped
- Use SHA-based image tags instead of 'latest' for deployments
- Pass exact image tag from build job to deploy job
- Add default for SSH_PORT
- Health check now fails deploy if not passing
- Added script_stop for proper error handling
2026-01-22 15:27:21 -07:00
0c387b1bcc Update CI/CD to build once and push to Harbor
Some checks failed
CI/CD Pipeline - Apartment API / Run Tests (push) Failing after 1s
CI/CD Pipeline - Apartment API / Build & Push Image (push) Has been skipped
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been skipped
- Add image variable substitution to docker-compose.yml
- Build image in CI, push to Harbor registry
- Deploy pulls from Harbor instead of rebuilding
- Supports both local dev (build) and prod (pull from registry)
2026-01-22 14:46:57 -07:00
94bbacb3a2 Add proper CI/CD pipeline with testing
Some checks failed
CI/CD Pipeline - Apartment API / Run Tests (push) Failing after 12s
CI/CD Pipeline - Apartment API / Deploy to Production (push) Has been skipped
- Separate test and deploy jobs
- Tests run first and block deployment on failure
- Uses MongoDB service container for tests
- SSH-based deployment for security and flexibility
- Health check verification after deployment
- Requires secrets: SSH_HOST, SSH_USER, SSH_PRIVATE_KEY, DEPLOY_PATH
2026-01-22 14:33:59 -07:00
9153a2faf8 Initial commit
All checks were successful
Deploy Apartment API / deploy (push) Successful in 9m48s
2025-07-15 17:51:26 -06:00