Does GeoLibre Have CI/CD Pipelines? A Complete Guide to GitHub Actions Workflows

Yes, GeoLibre uses GitHub Actions as its CI/CD platform, with 10+ automated workflows covering security audits, end-to-end testing, Docker builds, and multi-platform releases.

The opengeos/GeoLibre repository maintains a robust continuous integration and continuous delivery system entirely within .github/workflows/. These pipelines enforce code quality, validate functionality across the full stack, and automate artifact publishing for npm packages, Python wheels, Docker images, and Tauri desktop installers.

Main CI Pipeline: The Complete Build-Test Gate

The cornerstone of GeoLibre's CI/CD system is .github/workflows/ci.yml, which runs a comprehensive gate on every push to main, every pull request targeting main, and on manual dispatch.

What the CI Workflow Covers

  • Dependency security audit — runs npm run audit:ci via scripts/audit-check.mjs to flag high-severity npm advisories
  • Playwright E2E tests — smoke tests for browser UI functionality
  • Citation validation — ensures CITATION.cff version matches package.json
  • Docker collab relay test — builds and smoke-tests the collaboration relay image
  • Full monorepo build — frontend, workers, backend, and Rust/Tauri components
  • Lint and type checking — enforces code standards across TypeScript and Rust
  • Unit tests — separate suites for frontend (npm run test:frontend), workers (npm run test:worker), and backend (npm run test:backend)

The CI workflow uses cached Rust toolchains and Docker layer caching to keep build times reasonable despite the multi-language codebase.

Additional CI Workflows for Development

Test Build Validation

.github/workflows/test-build.yml provides a lighter-weight alternative that executes npm run build and the test suite without the full audit and E2E overhead. This triggers on pushes and pull requests to any branch, giving faster feedback during active development.

PR Preview Deployments

Two coordinated workflows handle ephemeral preview environments:

These allow reviewers to interact with live builds of proposed changes before merge.

Release and Publishing Pipelines

GeoLibre's release automation triggers on Git tag creation, with specialized workflows for each artifact type:

Workflow File Path Purpose
Release .github/workflows/release.yml Orchestrates all publish workflows on tag push
Publish Python .github/workflows/publish-python.yml Builds and uploads the python/ package to PyPI
Publish Embed .github/workflows/publish-embed.yml Bundles the Jupyter-embedded web app for npm
Publish Container .github/workflows/publish-container.yml Builds and pushes the web service Docker image

The release workflow additionally handles Tauri desktop installers for Windows (MSIX), macOS (MAS Store), Linux, iOS, and Android through platform-specific job matrices.

Studio and Deployment Workflows

.github/workflows/studio-deploy.yml supports manual deployment of the web studio to staging environments, typically via Vercel. This enables pre-release validation of the full application stack in a production-like setting.

Dependency and Maintenance Automation

Automated Security Updates

.github/dependabot.yml configures scheduled dependency updates across all package ecosystems used in GeoLibre:

  • npm (JavaScript/TypeScript dependencies)
  • pip (Python packages)
  • Cargo (Rust crates)
  • GitHub Actions (workflow dependencies)

Issue and PR Management

.github/workflows/labels.yml automatically applies GitHub labels to issues and pull requests based on content patterns, reducing manual triage overhead.

Running CI Steps Locally

You can replicate the core CI gate locally for debugging or pre-commit validation:


# Clean install dependencies

npm ci

# Static analysis

npm run lint
npm run typecheck

# Unit test suites

npm run test:frontend
npm run test:worker
npm run test:backend

# Desktop app build (requires Rust toolchain)

npm run tauri:build

Docker Collab Relay Testing

To manually test the collaboration relay container that CI validates:


# Build the image

docker build -f workers/collab-node/Dockerfile -t geolibre-collab:ci .

# Run with health endpoint exposed

docker run -d --name collab -p 8787:8787 geolibre-collab:ci

# Execute smoke test (mirrors CI validation)

node workers/collab-node/scripts/smoke.mjs http://127.0.0.1:8787

# Inspect logs for errors

docker logs collab

Key CI/CD Configuration Files

File Role in Pipeline
.github/workflows/ci.yml Primary build-test gate with security audit
.github/workflows/test-build.yml Lightweight build verification for all branches
.github/workflows/release.yml Release orchestration trigger
.github/workflows/publish-python.yml PyPI publication for the anywidget package
.github/workflows/publish-embed.yml npm publication for Jupyter embed build
.github/workflows/publish-container.yml Docker Hub / GHCR image push
.github/workflows/pr-preview.yml PR environment generation
.github/dependabot.yml Automated dependency update scheduling
scripts/audit-check.mjs Custom npm audit wrapper for CI
workers/collab-node/Dockerfile Collaboration relay container definition

Summary

  • GeoLibre's CI/CD system is built entirely on GitHub Actions with 10+ specialized workflows in .github/workflows/
  • The main ci.yml pipeline provides comprehensive coverage: security audits, E2E tests, citation validation, Docker smoke tests, and full stack builds
  • Release automation triggers on Git tags, publishing npm packages, Python wheels, Docker images, and Tauri installers across platforms
  • PR previews and test builds enable rapid iteration with quality gates
  • Dependabot integration keeps dependencies current across npm, pip, Cargo, and Actions ecosystems

Frequently Asked Questions

What triggers the main CI pipeline in GeoLibre?

The ci.yml workflow triggers on three events: pushes to the main branch, pull requests targeting main, and manual workflow dispatch through the GitHub Actions UI. This ensures all changes entering the primary branch pass the full quality gate.

How does GeoLibre handle security scanning in CI?

The CI pipeline runs npm run audit:ci via scripts/audit-check.mjs to detect high-severity npm advisories. Python dependencies are audited with pip-audit in non-blocking mode. These checks run on every CI execution before any build or test steps.

Can I test the collaboration relay Docker image locally?

Yes. Build with docker build -f workers/collab-node/Dockerfile -t geolibre-collab:ci ., then run the smoke test using node workers/collab-node/scripts/smoke.mjs against the exposed port. This mirrors exactly what the CI pipeline executes in its "Collab relay image" job.

What platforms does GeoLibre release to?

The release workflows publish to npm (JavaScript packages), PyPI (Python anywidget), Docker Hub / GHCR (container images), and native app stores via Tauri: Microsoft Store (MSIX), Mac App Store (MAS), plus iOS and Android builds.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →