chore(quality): 接入 ESLint 与 GitLab CI,开启严格未用检查,构建期设计令牌守卫

- eslint.config.mjs(flat config):react-hooks/react-refresh/tseslint;自定义 no-restricted-syntax
  规则禁止 className 手拼基元类名(error 级,JSXAttribute 选择器精确限定,探针双向验证)与硬编码色值
- tsconfig:noUnusedLocals/noUnusedParameters 置 true
- package.json 新增 typecheck/lint/test/verify:tokens 脚本;build 串联令牌校验(verify-tokens.sh
  防止 <alpha-value> 类静默失效回归);pnpm-lock.yaml 入库供 CI --frozen-lockfile
- .gitlab-ci.yml:lint/typecheck/test/build 四作业,MR 与默认分支触发,dist 产物留存一周
This commit is contained in:
2026-09-22 23:45:23 +08:00
parent f71f29b4cb
commit e6373d3c9a
6 changed files with 3001 additions and 4 deletions
+104
View File
@@ -0,0 +1,104 @@
# Profeto CI —— 首次引入自动化质量防线。
#
# 背景:此前仓库无任何 CI。唯一的测试文件 frontend/src/lib/http.test.ts
# 从未被自动执行过,类型检查也仅靠本地手跑 tsc。本流水线把
# 「类型检查 + 单元测试 + 构建」固化为 MR 门禁。
#
# 复用项目自带的 Docker 镜像(与 docker-compose.yml 同源),
# 避免 CI 环境与本地/线上不一致。
stages:
- verify
default:
image: node:22-alpine
# ── 前端:Lint ────────────────────────────────────────────────────
# 拦截「机器能看出来、人容易漏掉」的问题:幻影 CSS 变体、
# 硬编码色值、渲染期间副作用、未使用符号。
# 当前基线为 0 error / 56 warning,故本 job 会真实失败于新增 error。
frontend-lint:
stage: verify
before_script:
- cd frontend
- corepack enable
- pnpm install --frozen-lockfile
script:
- pnpm lint
cache:
key:
files:
- frontend/pnpm-lock.yaml
paths:
- frontend/node_modules/
rules:
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
- if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
# ── 前端:类型检查 ────────────────────────────────────────────────
frontend-typecheck:
stage: verify
before_script:
- cd frontend
- corepack enable
- pnpm install --frozen-lockfile
script:
- pnpm typecheck
# 缓存 pnpm store,避免每次 MR 重新下载依赖
cache:
key:
files:
- frontend/pnpm-lock.yaml
paths:
- frontend/node_modules/
rules:
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
- if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
# ── 前端:单元测试 ────────────────────────────────────────────────
# 这是 http.test.ts 第一次被自动化调用。它覆盖 HTTP 层的
# method/body/Content-Type 组装与 /health 免前缀豁免 —— 后者的
# 回归会导致管理后台右上角永远显示「系统异常」。
frontend-test:
stage: verify
before_script:
- cd frontend
- corepack enable
- pnpm install --frozen-lockfile
script:
- pnpm test
cache:
key:
files:
- frontend/pnpm-lock.yaml
paths:
- frontend/node_modules/
rules:
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
- if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
# ── 前端:生产构建 ────────────────────────────────────────────────
# 独立于 typecheck:构建会暴露类型检查覆盖不到的问题
# (Tailwind 配置错误、资源缺失、chunk 拆分失败等)。
frontend-build:
stage: verify
before_script:
- cd frontend
- corepack enable
- pnpm install --frozen-lockfile
script:
- pnpm build
artifacts:
name: "frontend-dist-$CI_COMMIT_SHORT_SHA"
paths:
- frontend/dist/
expire_in: 1 week
cache:
key:
files:
- frontend/pnpm-lock.yaml
paths:
- frontend/node_modules/
rules:
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
- if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH