• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

safe-global / safe-client-gateway / 36101772735
65%

Build:
DEFAULT BRANCH: main
Ran 25 Sep 2026 06:15AM UTC
Jobs 2
Files 1015
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

25 Sep 2026 06:11AM UTC coverage: 89.231% (-0.01%) from 89.243%
36101772735

push

github

web-flow
ci: build an immutable staging image and deploy it via GitOps (#3474)

* ci: build an immutable staging image and deploy it via GitOps

Second of four PRs splitting ci.yml into reusable workflows plus thin callers. PR A moved the quality gate; this one moves the trunk event.

staging.yml now owns `push: main`. It re-runs the gate, builds an image tagged main-<short-sha> through the new _build-image.yml reusable, and hands the tag to _deploy.yml, which bumps .client.imageTag in safe-client-gateway-infra-tf as a signed, squash-merged PR and then polls
the service until it reports the tag it just deployed.

The gain over the old job is the immutable tag. ci.yml only ever pushed the moving `:staging` tag with VERSION=main, so /about reported version "main" for every build ever made — nothing could be pinned, diffed, or rolled back. Every build now has a durable coordinate.

Staging is still deployed by the legacy path, deliberately. argocd-image-updater on the devstaging Application watches ghcr.io/safe-global/safe-client-gateway:staging with digest strategy, and the new ArgoCD Application that reads the infra repo is not applied yet (pending infrasec review). So `moving_tag: staging` keeps that tag alive and the autodeploy webhook is carried over as `notify-legacy-deploy` rather than deleted. Both paths converge on the same image, so the version gate is honest either way; the coupling disappears in P4, which removes the moving tag and the nudge job together.

scripts/autodeploy.sh is kept for that reason — it is still the webhook payload the legacy controller expects.

ci.yml keeps only the release build until PR D retires it. Its `push` trigger is dropped so the gate does not run twice on every merge.

Verification: yarn format, yarn lint and yarn test all clean (371 iles, 6638 passed, 18 skipped). Environments staging/production exist with noprotection rules; CI_APP_ID, CI_APP_PRIVATE_KEY, GPG_PRIVATE_KEY, GPG_PASSPHRASE, DOCKER_USER, DOCKER_PASSWORD, ... (continued)

4365 of 5135 branches covered (85.0%)

Branch coverage included in aggregate %.

11122 of 12221 relevant lines covered (91.01%)

543.76 hits per line

Coverage Regressions

Lines Coverage ∆ File
1
86.67
-5.0% src/modules/notifications/routes/v1/notifications.controller.ts
Jobs
ID Job ID Ran Files Coverage
1 run-unit-tests - 36101772735.1 25 Sep 2026 06:15AM UTC 1015
66.12
GitHub Action Run
2 run-integration-tests - 36101772735.2 25 Sep 2026 06:16AM UTC 1015
64.11
GitHub Action Run
Source Files on build 36101772735
  • Tree
  • List 1015
  • Changed 5
  • Source Changed 0
  • Coverage Changed 5
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #36101772735
  • 83a8bae2 on github
  • Prev Build on main (#36000373198)
  • Next Build on main (#36110233399)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc