Stand up the Tanemaki monorepo and the first end-to-end vertical slice of Block 1 (offline, encrypted inventory): add a seed → see it in a categorized, searchable list → it persists → reopen and it's still there. Architecture (state management like G1nkgo, adapted to Tane's reality): - flutter_bloc (Cubit-first), but the encrypted Drift DB is the single source of truth; cubits stream from repositories (no hydrated_bloc/Hive, which would write plaintext at rest). - get_it composition root; go_router; slang i18n (ES/EN, Weblate-friendly JSON). Workspace & core: - pub workspace: packages/commons_core (pure Dart) + apps/app_seeds (Flutter). - commons_core primitives: UUIDv7 IdGen, Hybrid Logical Clock, Quantity value type (+ plant-aware QuantityKind), IdentityService root-seed stub. Data & security: - Drift schemaVersion=1 with all 10 Block-1 tables + common CRDT columns (HLC updated_at, last_author, tombstones); Movement append-only. - SQLCipher via an injectable executor that refuses to open a plaintext DB; DB key + root seed in the OS keystore (separate secrets). - Exported drift_schema_v1.json + migration scaffold. Tests (near-TDD; nothing merges without tests): - commons_core units (24), Drift migration test, "no plaintext at rest" security guard (runs where SQLCipher is present, skips otherwise), repository, widget, full quick-add flow, file-reopen persistence, and a no-hardcoded-strings i18n guard. GitLab CI: format + analyze + test + coverage. Follow-on Block-1 stories (item detail/edit, species catalog, germination UI) and all of Block 2 remain out of scope.
54 lines
1.4 KiB
YAML
54 lines
1.4 KiB
YAML
# CI for Tanemaki. Mirrors the local verification gate (analyze + test +
|
|
# coverage) from docs/design/testing.md. Adapt to GitHub Actions if the
|
|
# canonical remote changes; the commands are the same.
|
|
#
|
|
# Uses the official Flutter Docker image. Pin the version to match the
|
|
# developer toolchain (Flutter 3.41.x / Dart 3.11.x).
|
|
image: ghcr.io/cirruslabs/flutter:3.41.9
|
|
|
|
stages:
|
|
- analyze
|
|
- test
|
|
|
|
variables:
|
|
PUB_CACHE: "$CI_PROJECT_DIR/.pub-cache"
|
|
|
|
cache:
|
|
key: "$CI_COMMIT_REF_SLUG"
|
|
paths:
|
|
- .pub-cache/
|
|
|
|
before_script:
|
|
# SQLCipher runtime lib so the "no plaintext at rest" security test actually
|
|
# runs (it skips where the library is absent).
|
|
- apt-get update -qq && apt-get install -y -qq libsqlcipher0
|
|
- flutter --version
|
|
- flutter pub get
|
|
|
|
analyze:
|
|
stage: analyze
|
|
script:
|
|
- dart format --output=none --set-exit-if-changed .
|
|
- flutter analyze
|
|
|
|
test:commons_core:
|
|
stage: test
|
|
script:
|
|
- cd packages/commons_core
|
|
- dart test
|
|
|
|
test:app_seeds:
|
|
stage: test
|
|
script:
|
|
- cd apps/app_seeds
|
|
# Generated sources (Drift, slang) must exist before analysis/tests.
|
|
- dart run build_runner build --delete-conflicting-outputs
|
|
- flutter test --coverage
|
|
coverage: '/lines\.*: \d+\.\d+\%/'
|
|
artifacts:
|
|
paths:
|
|
- apps/app_seeds/coverage/lcov.info
|
|
reports:
|
|
coverage_report:
|
|
coverage_format: cobertura
|
|
path: apps/app_seeds/coverage/cobertura.xml
|