Reusable GitHub Actions workflows for the DaVinciBot SvelteKit applications.
Application repositories should call reusable workflows by release tag:
jobs:
ci:
uses: DaVinciBot/shared-workflows/.github/workflows/ci.yml@v6.0.0Available workflows:
.github/workflows/ci.yml: shared quality gates. By default runspnpm check,pnpm lint,pnpm test:unit,pnpm buildat the repository root. Inputs:pnpm_version,node_version_file,working_directory(directory the gate commands run in — dependencies are still installed from the repo root so pnpm workspaces link correctly),commands(JSON array of{name, command}to run only the scripts a package defines; overrides the default gates). Theworking_directory/commandsinputs let a monorepo call the workflow once per package (see DaVinciBot/packages)..github/workflows/container.yml: build and publish application containers. Gates the image withhadolint(before the build), thendive --cianddockleon the image itself, then Trivy on the published image. On a pull request the build usesloadinstead ofpush, sodiveanddocklestill have an image to inspect. Inputs pin each tool and point at its config:hadolint_version/hadolint_config,dive_version/dive_config,dockle_version/dockle_exit_level..github/workflows/deploy.yml: deploy applications through Dokploy..github/workflows/e2e.yml: run Playwright end-to-end tests..github/workflows/security-scan.yml: run security scans — dependency review, Trivy on the filesystem, andcheckovon the Dockerfile and the workflows. Inputs:checkov_version,checkov_config..github/workflows/publish-npm.yml: publish an npm package to GitHub Packages (npm.pkg.github.com). Idempotent (skips already-published versions). Inputs:package_dir,build_command,pnpm_version,node_version_file. No npm provenance: attestation is npmjs-only.
Each application repository carries the container tooling configs at its root. They are read from the checkout, so a repository tunes its own thresholds without touching this repository:
| File | Tool | Holds |
|---|---|---|
.hadolint.yaml |
hadolint | failure threshold, ignored rules, trusted registries |
.dive-ci |
dive | efficiency, wasted bytes and wasted-percent thresholds |
.dockleignore |
dockle | waived CIS checkpoints |
.checkov.yaml |
checkov | frameworks, skipped paths, waived checks |
Required repository or organization setup:
- Allow application repositories to use reusable workflows from
DaVinciBot/shared-workflows. - Create and maintain version tags such as
v6.0.0after changes are reviewed. - Grant GitHub Actions
packages: writefor workflows that publish to GHCR. - Grant GitHub Actions
id-token: writefor workflows that create keyless Cosign and npm signatures. - Configure deployment environments
dev,staging, andprodin application repositories, with a required reviewer onprod. - Configure repository secrets (shared across environments):
DOKPLOY_URLDOKPLOY_API_KEYGHCR_TOKEN(PAT withread:packages, used by Dokploy to pull from GHCR)
- Configure the organization secret
PACKAGES_READ_TOKEN(PAT withread:packagesfrom a bot account): used byci.yml/e2e.ymlinstalls and mounted as a Docker build secret bycontainer.ymlso builds can install the private@davincibot/*packages from GitHub Packages.container.ymltreats it as required. - Configure environment secrets (one per environment:
dev,staging,prod):DOKPLOY_APP_ID
The shared npm packages live in DaVinciBot/packages:
@davincibot/config, @davincibot/lib and @davincibot/components, published to GitHub Packages (private) via
publish-npm.yml. @davincibot/database-types is published the same way
from DaVinciBot/Supabased.
The first-generation packages (@davincibot/eslint-config,
@davincibot/prettier-config, @davincibot/tsconfig, on public npmjs) are frozen and deprecated in favour of
@davincibot/config v2+.