name: Code Quality on: push: branches: [main] pull_request: branches: [main] permissions: contents: read concurrency: # Keyed by PR number (not head_ref): two different fork PRs can share a # head branch name (most commonly `main`), and a name-keyed group would let # one contributor's push cancel or queue behind another's unrelated run. group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} # First-party PRs can read the Turbo cache, but only trusted push runs can write it. env: TURBO_TOKEN: ${{ secrets.TURBO_TOKEN }} TURBO_TEAM: ${{ secrets.TURBO_TEAM }} TURBO_CACHE: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && 'local:rw,remote:r' || github.event_name == 'pull_request' && 'local:rw' || 'local:rw,remote:rw' }} jobs: lint: runs-on: ubuntu-latest timeout-minutes: 10 steps: - name: Checkout uses: actions/checkout@v5 with: persist-credentials: false - name: Install pnpm uses: pnpm/action-setup@v5 - name: Setup Node.js uses: actions/setup-node@v5 with: node-version: 22.18.0 cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline - name: Lint run: pnpm lint typecheck: runs-on: ubuntu-latest timeout-minutes: 10 steps: - name: Checkout uses: actions/checkout@v5 with: persist-credentials: false - name: Install pnpm uses: pnpm/action-setup@v5 - name: Setup Node.js uses: actions/setup-node@v5 with: node-version: 22.18.0 cache: pnpm - name: Install dependencies run: pnpm install --frozen-lockfile --prefer-offline - name: Typecheck run: pnpm typecheck