prepare script in each package.json installs the hooks when you run the install command.
The
docs/CI_AND_HOOKS.md file in each repository describes more pre-push checks than the hooks actually run. The tables below reflect the hook files and workflow files as they are.Hooks
pre-commit
All three runlint-staged.
In the backend, lint-staged lints each staged file directly. Files outside a package’s
src folder, such as prisma.config.ts, are skipped by pnpm lint but are linted here, so the no-direct-process-env rule can fail a commit that touches them.
commit-msg
All three run commitlint on the message. See Branches and commits.pre-push
No pre-push hook runs a type-check or tests. Run those yourself. See Testing.
GitHub Actions
backend
The gitleaks step scans the whole history, so a secret committed once keeps failing CI until the history or the gitleaks config deals with it. Rotate any secret that was ever committed.
pnpm cve:check runs the same CVE checks locally through tools/check-cves.sh. It installs osv-scanner into ~/.local/bin when it is missing.
frontend
.github/dependabot.yml opens grouped weekly npm update pull requests against dev, at most five at a time, and ignores major version bumps.
mobile
Mobile builds and OTA updates are not run by CI. They are run by hand with the EAS CLI. See Mobile builds.
What CI does not cover
- The deploy workflows that run on a push to
devdo not wait forci.yml. In the backend,ci.ymldoes not run on a push todevat all. A direct push todevis deployed without lint, type-check or tests having run in CI. - Playwright end-to-end tests.
- The mobile
node:testscripts. - Any check that the two backend Prisma schemas agree with each other.
dev, or go through a pull request.
Turborepo task graph
- backend
- frontend
DATABASE_URL and CI pass through to every task through globalPassThroughEnv.