chore: adopt Biome + Stylelint, modernize CI/CD, add security/support docs, minor JS fixes

- Linting/format
  - Replace ESLint/Prettier with Biome; remove old configs; add `biome.json`; update scripts
  - Tailwind-friendly `.stylelintrc.yaml`; Stylelint and Biome pass
  - Enable Biome across `modules/**`; prune legacy JS globals; ignore oversized `devicon.json`

- Code fixes
  - `hb-theme.js`: avoid assignment-in-expressions; clearer dataset updates
  - `hugoblox-slides.js`: fix inner var scope (var → let); apply formatting

- CI/CD
  - Split lint/build workflows; add path filters; Node via Corepack (pnpm from package.json)
  - Hugo pinned to env `HUGO_VERSION`; add consistency check vs `starters/academic-cv/hugoblox.yaml`
  - Nightly starters matrix build (academic-cv, landing-page); CodeQL weekly; resource caches

- Workflows/Community
  - Greeter: switch to `pull_request_target`; add Contributor Guide to PR message
  - PR labeler for path-based labels

- Repo policies/docs
  - `CODEOWNERS` for `@gcushen`
  - `SECURITY.md`, `SUPPORT.md`
  - Documented branch protection in `.github/settings.yml`
  - Move `CODE_OF_CONDUCT.md` to `.github/`

- docs(zh): update `README.zh.md` translation

Notes:
- pnpm is sourced from `package.json: packageManager` via Corepack; no hard-coded pnpm versions in CI.
This commit is contained in:
George Cushen committed 2025-09-17 03:17:38 +01:00
1 parent db8a975a9f
commit d5d2f04c2d
91 files changed
+2957 -1993

No files matched your search

+97
View File
@@ -0,0 +1,97 @@
name: CI - Build Starters Matrix
on:
schedule:
- cron: "0 2 * * *"
workflow_dispatch:
push:
branches: [main]
paths:
- "modules/**"
- "starters/**"
pull_request:
paths:
- "modules/**"
- "starters/**"
permissions:
contents: read
concurrency:
group: starters-${{ github.ref }}
cancel-in-progress: true
env:
NODE_VERSION: "22"
HUGO_VERSION: "0.150.0"
jobs:
build-starters:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
starter:
- name: academic-cv
path: starters/academic-cv
- name: landing-page
path: starters/landing-page
steps:
- name: Checkout
uses: actions/checkout@v5
with:
submodules: true
fetch-depth: 0
- name: Compute resources cache key
id: reskey
run: |
set -euo pipefail
P=${{ matrix.starter.path }}
# Hash tracked files under assets/config and key files for invalidation
HASH=$(git ls-files -s "$P/assets" "$P/config" "$P/hugo.yaml" "$P/package.json" 2>/dev/null | sha256sum | cut -d' ' -f1 || true)
if [ -z "$HASH" ]; then HASH="nohash"; fi
echo "key=${{ runner.os }}-hugo-resources-${{ matrix.starter.name }}-$HASH" >> $GITHUB_OUTPUT
- name: Cache Hugo resources (starter)
uses: actions/cache@v4
with:
path: ${{ matrix.starter.path }}/resources/
key: ${{ steps.reskey.outputs.key }}
restore-keys: |
${{ runner.os }}-hugo-resources-${{ matrix.starter.name }}-
- name: Validate Hugo version consistency
run: |
set -euo pipefail
EXPECTED=$(grep -E "^\s*hugo_version:\s*['\"]?" starters/academic-cv/hugoblox.yaml | sed -E "s/.*hugo_version:\s*['\"]?([^'\"]+)['\"]?.*/\1/")
echo "Expected Hugo from starter: $EXPECTED"
echo "Hugo in CI: $HUGO_VERSION"
if [ "$EXPECTED" != "$HUGO_VERSION" ]; then
echo "::error::HUGO_VERSION ($HUGO_VERSION) does not match starters/academic-cv/hugoblox.yaml ($EXPECTED). Update .github/workflows env or starter version."
exit 1
fi
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "${{ env.NODE_VERSION }}"
cache: "pnpm"
- name: Enable Corepack (use pnpm from package.json)
run: corepack enable
- name: Install starter dependencies
working-directory: ${{ matrix.starter.path }}
run: pnpm install --frozen-lockfile
- name: Setup Hugo
uses: peaceiris/actions-hugo@v3
with:
hugo-version: "${{ env.HUGO_VERSION }}"
extended: true
- name: Build ${{ matrix.starter.name }}
working-directory: ${{ matrix.starter.path }}
run: hugo --minify --panicOnWarning
+62 -36
View File
@@ -1,12 +1,39 @@
name: Continuous Integration
name: CI - Build Test Site
on:
push:
branches:
- main
branches: [main]
paths:
- "modules/**"
- "test/**"
- "scripts/**"
- "package.json"
- "pnpm-lock.yaml"
- "biome.json"
- ".stylelintrc.yaml"
- "vite.config.js"
pull_request:
branches:
- main
branches: [main]
paths:
- "modules/**"
- "test/**"
- "scripts/**"
- "package.json"
- "pnpm-lock.yaml"
- "biome.json"
- ".stylelintrc.yaml"
- "vite.config.js"
permissions:
contents: read
concurrency:
group: build-${{ github.ref }}
cancel-in-progress: true
env:
NODE_VERSION: "22"
HUGO_VERSION: "0.150.0"
jobs:
build:
@@ -15,7 +42,7 @@ jobs:
strategy:
matrix:
os: [ubuntu-latest]
# node-version: [18.x]
# node-version: [22.x]
steps:
- uses: actions/checkout@v5
@@ -23,16 +50,28 @@ jobs:
submodules: true # Fetch any Git submodules (true OR recursive)
fetch-depth: 0 # Fetch all history for .GitInfo and .Lastmod
# - name: Use Node.js ${{ matrix.node-version }}
# uses: actions/setup-node@v3
# with:
# node-version: ${{ matrix.node-version }}
- name: Validate Hugo version consistency
run: |
set -euo pipefail
EXPECTED=$(grep -E "^\s*hugo_version:\s*['\"]?" starters/academic-cv/hugoblox.yaml | sed -E "s/.*hugo_version:\s*['\"]?([^'\"]+)['\"]?.*/\1/")
echo "Expected Hugo from starter: $EXPECTED"
echo "Hugo in CI: $HUGO_VERSION"
if [ "$EXPECTED" != "$HUGO_VERSION" ]; then
echo "::error::HUGO_VERSION ($HUGO_VERSION) does not match starters/academic-cv/hugoblox.yaml ($EXPECTED). Update .github/workflows env or starter version."
exit 1
fi
- uses: pnpm/action-setup@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
run_install: |
- recursive: false
args: [--frozen-lockfile]
node-version: "${{ env.NODE_VERSION }}"
cache: "pnpm"
- name: Enable Corepack (use pnpm from package.json)
run: corepack enable
- name: Install root dependencies
run: pnpm install --frozen-lockfile
- name: Install Tailwind v4 dependencies for test site
run: |
@@ -40,33 +79,20 @@ jobs:
pnpm install --frozen-lockfile
cd ..
- name: Check for linting errors
run: pnpm run lint:js # TODO: also lint styles again once new rule errors resolved
- name: Cache Hugo resources (test)
uses: actions/cache@v4
with:
path: test/resources/
key: ${{ runner.os }}-hugo-resources-test-${{ hashFiles('test/assets/**/*', 'test/config/**/*', 'test/hugo.yaml', 'test/package.json') }}
restore-keys: |
${{ runner.os }}-hugo-resources-test-
- name: Setup Hugo
uses: peaceiris/actions-hugo@v3
with:
hugo-version: '0.148.2'
hugo-version: "${{ env.HUGO_VERSION }}"
extended: true
- name: Build
run: hugo --minify --templateMetrics --templateMetricsHints
run: hugo --minify --panicOnWarning --templateMetrics --templateMetricsHints
working-directory: test
# format:
# runs-on: ubuntu-latest
#
# steps:
# - name: Checkout
# uses: actions/checkout@v2
# with:
# # Make sure the actual branch is checked out when running on pull requests
# ref: ${{ github.head_ref }}
#
# - name: Prettify code
# uses: creyD/prettier_action@v3.1
# with:
# prettier_options: '--write blox-tailwind/*.{css,js,json,md,scss} blox-tailwind/**/*.{css,js,json,md,scss}' # Match package.json
# prettier_version: '2.2.1' # Match package.json
# commit_message: 'refactor: format code'
# env:
# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+50
View File
@@ -0,0 +1,50 @@
name: Security - CodeQL
on:
schedule:
- cron: "0 3 * * 0"
push:
branches: [main]
paths:
- "**/*.js"
- "**/*.jsx"
- "**/*.ts"
- "**/*.tsx"
- "**/*.py"
- ".github/workflows/codeql.yml"
pull_request:
branches: [main]
paths:
- "**/*.js"
- "**/*.jsx"
- "**/*.ts"
- "**/*.tsx"
- "**/*.py"
permissions:
actions: read
contents: read
security-events: write
jobs:
analyze:
name: Analyze (CodeQL)
runs-on: ubuntu-latest
strategy:
fail-fast: false
steps:
- name: Checkout repository
uses: actions/checkout@v5
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: "javascript-typescript,python"
- name: Autobuild
uses: github/codeql-action/autobuild@v3
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
category: "/language:javascript-typescript"
+9 -4
View File
@@ -1,19 +1,21 @@
name: Welcome New Contributor
on:
pull_request:
pull_request_target:
types:
- opened
issues:
types:
- opened
permissions:
contents: read
issues: write
pull-requests: write
jobs:
greeting:
runs-on: ubuntu-latest
permissions:
issues: write
pull-requests: write
steps:
- uses: actions/first-interaction@v3
with:
@@ -33,6 +35,9 @@ jobs:
Thank you for this contribution to open source and open research. It makes a huge impact for the thousands of innovators building with Hugo Blox.
If you're wondering about next steps, please read our [Contributor Guide](https://github.com/HugoBlox/hugo-blox-builder/blob/main/CONTRIBUTING.md) for coding standards, how to run the project locally, and how to get help.
We hope this is just the start of your journey with us. Let's build the future together! Join us on [Discord](https://discord.gg/z8wNYzb) to connect with the team and community.
+18
View File
@@ -0,0 +1,18 @@
name: CI - PR Labeler
on:
pull_request_target:
types: [opened, synchronize]
permissions:
contents: read
pull-requests: write
jobs:
label:
runs-on: ubuntu-latest
steps:
- uses: actions/labeler@v5
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
configuration-path: .github/labeler.yml
+51
View File
@@ -0,0 +1,51 @@
name: CI - Lint
on:
push:
branches: [main]
paths:
- "modules/**"
- "test/**"
- "scripts/**"
- "package.json"
- "pnpm-lock.yaml"
- "biome.json"
- ".stylelintrc.yaml"
- "vite.config.js"
pull_request:
branches: [main]
paths:
- "modules/**"
- "test/**"
- "scripts/**"
- "package.json"
- "pnpm-lock.yaml"
- "biome.json"
- ".stylelintrc.yaml"
- "vite.config.js"
permissions:
contents: read
concurrency:
group: lint-${{ github.ref }}
cancel-in-progress: true
env:
NODE_VERSION: "22"
jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/setup-node@v4
with:
node-version: "${{ env.NODE_VERSION }}"
cache: "pnpm"
- name: Enable Corepack (use pnpm from package.json)
run: corepack enable
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Lint (Biome + Stylelint)
run: pnpm run lint