Repository navigation
62 lines (59 loc) · 2.68 KB
/
Copy pathdocs.yml
File metadata and controls
62 lines (59 loc) · 2.68 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
name: docs
# The documentation is checked against the scanner, not maintained beside it.
#
# This is a workflow of its own rather than a job in `ci.yml`, because `ci.yml`
# skips pull requests that only touch prose — and a prose-only pull request is
# exactly when the documentation can drift away from the binary.
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
jobs:
rules:
name: rules
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
# The manifest is generated from the binary, so a rule added, renamed or
# withdrawn without regenerating it fails here rather than reaching the
# website.
- name: The exported rule manifest is current
run: scripts/rules-manifest.sh --check
# The site takes the version it documents from Cargo.toml at build time,
# so its pages cannot go stale. The README is rendered by GitHub instead
# of by the generator, so the one tag it hands a reader is written by
# hand -- and checked here.
- name: The README pins the current release
run: |
version=$(grep -m1 '^version = ' Cargo.toml | cut -d'"' -f2)
found=$(grep -o 'straitjacket@v[0-9][0-9a-z.-]*' README.md | sort -u)
if [ "$found" != "straitjacket@v${version}" ]; then
echo "README.md pins ${found:-nothing}; Cargo.toml says v${version}" >&2
exit 1
fi
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
# Pinned: `latest` is a different Bun on different days, and a docs
# gate that fails because a runner picked up a new release is a gate
# nobody can act on. reproducible-toolchain asks for this.
bun-version: "1.4.0"
- run: bun install --frozen-lockfile
working-directory: site
# Checks the other direction: every rule is documented, no page claims a
# rule that does not exist, and no page quotes a stale default.
- run: bun test
working-directory: site
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v6.0.0
with:
python-version: "3.12"
- run: pip install --quiet pillow
# The card a link shows is committed, because nothing should have to draw
# an image to serve a page. Committed means it can go stale, so this
# compares what it was drawn from against what the config says now.
- name: The social card still matches the config
run: bun run social:check
working-directory: site