Does GeoLibre Have CI/CD Pipelines? A Complete Guide to GitHub Actions Workflows
Yes, GeoLibre uses GitHub Actions as its CI/CD platform, with 10+ automated workflows covering security audits, end-to-end testing, Docker builds, and multi-platform releases.
The opengeos/GeoLibre repository maintains a robust continuous integration and continuous delivery system entirely within .github/workflows/. These pipelines enforce code quality, validate functionality across the full stack, and automate artifact publishing for npm packages, Python wheels, Docker images, and Tauri desktop installers.
Main CI Pipeline: The Complete Build-Test Gate
The cornerstone of GeoLibre's CI/CD system is .github/workflows/ci.yml, which runs a comprehensive gate on every push to main, every pull request targeting main, and on manual dispatch.
What the CI Workflow Covers
- Dependency security audit — runs
npm run audit:civiascripts/audit-check.mjsto flag high-severity npm advisories - Playwright E2E tests — smoke tests for browser UI functionality
- Citation validation — ensures
CITATION.cffversion matchespackage.json - Docker collab relay test — builds and smoke-tests the collaboration relay image
- Full monorepo build — frontend, workers, backend, and Rust/Tauri components
- Lint and type checking — enforces code standards across TypeScript and Rust
- Unit tests — separate suites for frontend (
npm run test:frontend), workers (npm run test:worker), and backend (npm run test:backend)
The CI workflow uses cached Rust toolchains and Docker layer caching to keep build times reasonable despite the multi-language codebase.
Additional CI Workflows for Development
Test Build Validation
.github/workflows/test-build.yml provides a lighter-weight alternative that executes npm run build and the test suite without the full audit and E2E overhead. This triggers on pushes and pull requests to any branch, giving faster feedback during active development.
PR Preview Deployments
Two coordinated workflows handle ephemeral preview environments:
.github/workflows/pr-preview.yml— generates a temporary deployment for each pull request.github/workflows/pr-preview-deploy.yml— handles the actual deployment mechanics
These allow reviewers to interact with live builds of proposed changes before merge.
Release and Publishing Pipelines
GeoLibre's release automation triggers on Git tag creation, with specialized workflows for each artifact type:
| Workflow | File Path | Purpose |
|---|---|---|
| Release | .github/workflows/release.yml |
Orchestrates all publish workflows on tag push |
| Publish Python | .github/workflows/publish-python.yml |
Builds and uploads the python/ package to PyPI |
| Publish Embed | .github/workflows/publish-embed.yml |
Bundles the Jupyter-embedded web app for npm |
| Publish Container | .github/workflows/publish-container.yml |
Builds and pushes the web service Docker image |
The release workflow additionally handles Tauri desktop installers for Windows (MSIX), macOS (MAS Store), Linux, iOS, and Android through platform-specific job matrices.
Studio and Deployment Workflows
.github/workflows/studio-deploy.yml supports manual deployment of the web studio to staging environments, typically via Vercel. This enables pre-release validation of the full application stack in a production-like setting.
Dependency and Maintenance Automation
Automated Security Updates
.github/dependabot.yml configures scheduled dependency updates across all package ecosystems used in GeoLibre:
- npm (JavaScript/TypeScript dependencies)
- pip (Python packages)
- Cargo (Rust crates)
- GitHub Actions (workflow dependencies)
Issue and PR Management
.github/workflows/labels.yml automatically applies GitHub labels to issues and pull requests based on content patterns, reducing manual triage overhead.
Running CI Steps Locally
You can replicate the core CI gate locally for debugging or pre-commit validation:
# Clean install dependencies
npm ci
# Static analysis
npm run lint
npm run typecheck
# Unit test suites
npm run test:frontend
npm run test:worker
npm run test:backend
# Desktop app build (requires Rust toolchain)
npm run tauri:build
Docker Collab Relay Testing
To manually test the collaboration relay container that CI validates:
# Build the image
docker build -f workers/collab-node/Dockerfile -t geolibre-collab:ci .
# Run with health endpoint exposed
docker run -d --name collab -p 8787:8787 geolibre-collab:ci
# Execute smoke test (mirrors CI validation)
node workers/collab-node/scripts/smoke.mjs http://127.0.0.1:8787
# Inspect logs for errors
docker logs collab
Key CI/CD Configuration Files
| File | Role in Pipeline |
|---|---|
.github/workflows/ci.yml |
Primary build-test gate with security audit |
.github/workflows/test-build.yml |
Lightweight build verification for all branches |
.github/workflows/release.yml |
Release orchestration trigger |
.github/workflows/publish-python.yml |
PyPI publication for the anywidget package |
.github/workflows/publish-embed.yml |
npm publication for Jupyter embed build |
.github/workflows/publish-container.yml |
Docker Hub / GHCR image push |
.github/workflows/pr-preview.yml |
PR environment generation |
.github/dependabot.yml |
Automated dependency update scheduling |
scripts/audit-check.mjs |
Custom npm audit wrapper for CI |
workers/collab-node/Dockerfile |
Collaboration relay container definition |
Summary
- GeoLibre's CI/CD system is built entirely on GitHub Actions with 10+ specialized workflows in
.github/workflows/ - The main
ci.ymlpipeline provides comprehensive coverage: security audits, E2E tests, citation validation, Docker smoke tests, and full stack builds - Release automation triggers on Git tags, publishing npm packages, Python wheels, Docker images, and Tauri installers across platforms
- PR previews and test builds enable rapid iteration with quality gates
- Dependabot integration keeps dependencies current across npm, pip, Cargo, and Actions ecosystems
Frequently Asked Questions
What triggers the main CI pipeline in GeoLibre?
The ci.yml workflow triggers on three events: pushes to the main branch, pull requests targeting main, and manual workflow dispatch through the GitHub Actions UI. This ensures all changes entering the primary branch pass the full quality gate.
How does GeoLibre handle security scanning in CI?
The CI pipeline runs npm run audit:ci via scripts/audit-check.mjs to detect high-severity npm advisories. Python dependencies are audited with pip-audit in non-blocking mode. These checks run on every CI execution before any build or test steps.
Can I test the collaboration relay Docker image locally?
Yes. Build with docker build -f workers/collab-node/Dockerfile -t geolibre-collab:ci ., then run the smoke test using node workers/collab-node/scripts/smoke.mjs against the exposed port. This mirrors exactly what the CI pipeline executes in its "Collab relay image" job.
What platforms does GeoLibre release to?
The release workflows publish to npm (JavaScript packages), PyPI (Python anywidget), Docker Hub / GHCR (container images), and native app stores via Tauri: Microsoft Store (MSIX), Mac App Store (MAS), plus iOS and Android builds.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →