-
Notifications
You must be signed in to change notification settings - Fork 2.4k
Description
Would be nice if each PR triggered a build and test of the branch. That way it would be a bit more robust, and less likely to let through bugs that crash the site. Especially useful for dependency updates.
As referenced here:
@Panquesito7 did you test it locally? Also, did you see the changelog?
I haven't tested it locally (we could use Gitpod to deploy the page, though). The changelog or commits seem to be to fix a security issue. https://github.com/devicons/devicon/security/dependabot/6
No need to deploy imo. Just a simple build and run would suffice. If it runs, and the code checks are all green, it probably should work.
We could add a build step to the CodeQL workflow though. Maybe just add npm ci, npm build and npm test?
Can probably just be added as a replacement of these lines:
devicon/.github/workflows/codeql-analysis.yml
Lines 45 to 55 in 1119b9f
| # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). | |
| # If this step fails, then you should remove it and run the build manually (see below) | |
| - name: Autobuild | |
| uses: github/codeql-action/autobuild@v1 | |
| # ℹ️ Command-line programs to run using the OS shell. | |
| # 📚 https://git.io/JvXDl | |
| # ✏️ If the Autobuild fails above, remove it and uncomment the following three lines | |
| # and modify them (or add more) to build your code if your project | |
| # uses a compiled language |
Originally posted by @Snailedlt in #1385 (comment)