Repository navigation
83 lines (78 loc) · 3.19 KB
/
Copy pathci.yml
File metadata and controls
83 lines (78 loc) · 3.19 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
name: CI
on:
push:
branches: [main]
# paths-ignore keeps the heavy Cargo job off pull requests that only touch
# prose, which is what `ci-scoped` asks for.
pull_request:
paths-ignore:
- "**.md"
- "notes/**"
# Least privilege. A job that needs to write grants it explicitly.
permissions:
contents: read
jobs:
gate:
name: gate
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
# The toolchain comes from rust-toolchain.toml, which rustup installs on
# first use, so no setup action decides the version.
- run: cargo fmt --all --check
- run: cargo clippy --workspace --all-targets -- -D warnings
- run: cargo test --workspace
# The installer is the first thing a new user runs, and it runs under
# whatever /bin/sh they have.
- run: shellcheck -s sh scripts/install.sh
# A release build must keep working between releases, or the breakage is
# only discovered when a tag is pushed and it is too late to fix quietly.
- run: rustup target add x86_64-unknown-linux-musl
- run: cargo build --release --locked --target x86_64-unknown-linux-musl
# The publish path runs on every change, uploading nothing. Otherwise it
# is first exercised by the tag that publishes, which is the one moment
# a mistake cannot be taken back.
- run: scripts/publish.sh --dry-run
# The action manifest is loaded by GitHub, not by cargo, so nothing above
# would notice a mistake in it. Until this job existed, `action.yml` was
# first exercised by whoever depended on it -- and a manifest that does not
# parse fails their build before a single step of ours runs, with an error
# naming a line in this repository. Same argument as the publish dry run.
#
# It fails on findings, because the release smoke test does, and a finding
# that only surfaces there surfaces after the tag is pushed -- which is
# exactly what happened to v0.1.2. This job is the same scan, run early
# enough to be fixable.
action:
name: action
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: ./
with:
token: ${{ github.token }}
# The site is a Bun package with its own type layer, linter and tests, so it
# is graded the way the workspace is rather than only at deploy time. Named
# steps rather than a loop: ordnung reads a workflow's steps to know which
# tasks a language actually runs, and a loop tells it nothing.
site:
name: site
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: site
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.4.0"
- run: bun install --frozen-lockfile
- run: bun run typecheck
- run: bun run lint
- run: bun run format
- run: bun run build
- run: bun run test