# Does GeoLibre Have CI/CD Pipelines? A Complete Guide to GitHub Actions Workflows

> Discover GeoLibre's CI/CD with GitHub Actions. Explore 10+ workflows for security, testing, Docker builds, and multi-platform releases. Learn how we automate development.

- Repository: [Open Geospatial Solutions/GeoLibre](https://github.com/opengeos/GeoLibre)
- Tags: how-to-guide
- Published: 2026-08-16

---

**Yes, GeoLibre uses GitHub Actions as its CI/CD platform, with 10+ automated workflows covering security audits, end-to-end testing, Docker builds, and multi-platform releases.**

The opengeos/GeoLibre repository maintains a robust continuous integration and continuous delivery system entirely within `.github/workflows/`. These pipelines enforce code quality, validate functionality across the full stack, and automate artifact publishing for npm packages, Python wheels, Docker images, and Tauri desktop installers.

## Main CI Pipeline: The Complete Build-Test Gate

The cornerstone of GeoLibre's CI/CD system is **[`.github/workflows/ci.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/ci.yml)**, which runs a comprehensive gate on every push to `main`, every pull request targeting `main`, and on manual dispatch.

### What the CI Workflow Covers

- **Dependency security audit** — runs `npm run audit:ci` via `scripts/audit-check.mjs` to flag high-severity npm advisories
- **Playwright E2E tests** — smoke tests for browser UI functionality
- **Citation validation** — ensures `CITATION.cff` version matches [`package.json`](https://github.com/opengeos/GeoLibre/blob/main/package.json)
- **Docker collab relay test** — builds and smoke-tests the collaboration relay image
- **Full monorepo build** — frontend, workers, backend, and Rust/Tauri components
- **Lint and type checking** — enforces code standards across TypeScript and Rust
- **Unit tests** — separate suites for frontend (`npm run test:frontend`), workers (`npm run test:worker`), and backend (`npm run test:backend`)

The CI workflow uses cached Rust toolchains and Docker layer caching to keep build times reasonable despite the multi-language codebase.

## Additional CI Workflows for Development

### Test Build Validation

**[`.github/workflows/test-build.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/test-build.yml)** provides a lighter-weight alternative that executes `npm run build` and the test suite without the full audit and E2E overhead. This triggers on pushes and pull requests to any branch, giving faster feedback during active development.

### PR Preview Deployments

Two coordinated workflows handle ephemeral preview environments:

- **[`.github/workflows/pr-preview.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/pr-preview.yml)** — generates a temporary deployment for each pull request
- **[`.github/workflows/pr-preview-deploy.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/pr-preview-deploy.yml)** — handles the actual deployment mechanics

These allow reviewers to interact with live builds of proposed changes before merge.

## Release and Publishing Pipelines

GeoLibre's release automation triggers on Git tag creation, with specialized workflows for each artifact type:

| Workflow | File Path | Purpose |
|----------|-----------|---------|
| **Release** | [`.github/workflows/release.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/release.yml) | Orchestrates all publish workflows on tag push |
| **Publish Python** | [`.github/workflows/publish-python.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/publish-python.yml) | Builds and uploads the `python/` package to PyPI |
| **Publish Embed** | [`.github/workflows/publish-embed.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/publish-embed.yml) | Bundles the Jupyter-embedded web app for npm |
| **Publish Container** | [`.github/workflows/publish-container.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/publish-container.yml) | Builds and pushes the web service Docker image |

The release workflow additionally handles Tauri desktop installers for Windows (MSIX), macOS (MAS Store), Linux, iOS, and Android through platform-specific job matrices.

## Studio and Deployment Workflows

**[`.github/workflows/studio-deploy.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/studio-deploy.yml)** supports manual deployment of the web studio to staging environments, typically via Vercel. This enables pre-release validation of the full application stack in a production-like setting.

## Dependency and Maintenance Automation

### Automated Security Updates

**[`.github/dependabot.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/dependabot.yml)** configures scheduled dependency updates across all package ecosystems used in GeoLibre:

- npm (JavaScript/TypeScript dependencies)
- pip (Python packages)
- Cargo (Rust crates)
- GitHub Actions (workflow dependencies)

### Issue and PR Management

**[`.github/workflows/labels.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/labels.yml)** automatically applies GitHub labels to issues and pull requests based on content patterns, reducing manual triage overhead.

## Running CI Steps Locally

You can replicate the core CI gate locally for debugging or pre-commit validation:

```bash

# Clean install dependencies

npm ci

# Static analysis

npm run lint
npm run typecheck

# Unit test suites

npm run test:frontend
npm run test:worker
npm run test:backend

# Desktop app build (requires Rust toolchain)

npm run tauri:build

```

### Docker Collab Relay Testing

To manually test the collaboration relay container that CI validates:

```bash

# Build the image

docker build -f workers/collab-node/Dockerfile -t geolibre-collab:ci .

# Run with health endpoint exposed

docker run -d --name collab -p 8787:8787 geolibre-collab:ci

# Execute smoke test (mirrors CI validation)

node workers/collab-node/scripts/smoke.mjs http://127.0.0.1:8787

# Inspect logs for errors

docker logs collab

```

## Key CI/CD Configuration Files

| File | Role in Pipeline |
|------|----------------|
| [`.github/workflows/ci.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/ci.yml) | Primary build-test gate with security audit |
| [`.github/workflows/test-build.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/test-build.yml) | Lightweight build verification for all branches |
| [`.github/workflows/release.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/release.yml) | Release orchestration trigger |
| [`.github/workflows/publish-python.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/publish-python.yml) | PyPI publication for the anywidget package |
| [`.github/workflows/publish-embed.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/publish-embed.yml) | npm publication for Jupyter embed build |
| [`.github/workflows/publish-container.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/publish-container.yml) | Docker Hub / GHCR image push |
| [`.github/workflows/pr-preview.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/workflows/pr-preview.yml) | PR environment generation |
| [`.github/dependabot.yml`](https://github.com/opengeos/GeoLibre/blob/main/.github/dependabot.yml) | Automated dependency update scheduling |
| `scripts/audit-check.mjs` | Custom npm audit wrapper for CI |
| `workers/collab-node/Dockerfile` | Collaboration relay container definition |

## Summary

- **GeoLibre's CI/CD system is built entirely on GitHub Actions** with 10+ specialized workflows in `.github/workflows/`
- **The main [`ci.yml`](https://github.com/opengeos/GeoLibre/blob/main/ci.yml) pipeline** provides comprehensive coverage: security audits, E2E tests, citation validation, Docker smoke tests, and full stack builds
- **Release automation** triggers on Git tags, publishing npm packages, Python wheels, Docker images, and Tauri installers across platforms
- **PR previews and test builds** enable rapid iteration with quality gates
- **Dependabot integration** keeps dependencies current across npm, pip, Cargo, and Actions ecosystems

## Frequently Asked Questions

### What triggers the main CI pipeline in GeoLibre?

The [`ci.yml`](https://github.com/opengeos/GeoLibre/blob/main/ci.yml) workflow triggers on three events: pushes to the `main` branch, pull requests targeting `main`, and manual workflow dispatch through the GitHub Actions UI. This ensures all changes entering the primary branch pass the full quality gate.

### How does GeoLibre handle security scanning in CI?

The CI pipeline runs `npm run audit:ci` via `scripts/audit-check.mjs` to detect high-severity npm advisories. Python dependencies are audited with `pip-audit` in non-blocking mode. These checks run on every CI execution before any build or test steps.

### Can I test the collaboration relay Docker image locally?

Yes. Build with `docker build -f workers/collab-node/Dockerfile -t geolibre-collab:ci .`, then run the smoke test using `node workers/collab-node/scripts/smoke.mjs` against the exposed port. This mirrors exactly what the CI pipeline executes in its "Collab relay image" job.

### What platforms does GeoLibre release to?

The release workflows publish to npm (JavaScript packages), PyPI (Python anywidget), Docker Hub / GHCR (container images), and native app stores via Tauri: Microsoft Store (MSIX), Mac App Store (MAS), plus iOS and Android builds.