-
Notifications
You must be signed in to change notification settings - Fork 0
128 lines (105 loc) · 4.3 KB
/
Copy pathci.yml
File metadata and controls
128 lines (105 loc) · 4.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
name: CI
on:
pull_request:
push:
branches: [main]
permissions: {}
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
env:
CARGO_TERM_COLOR: always
jobs:
lint:
name: Lint (fmt + clippy)
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Install Rust
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
components: rustfmt, clippy
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
- name: Check formatting
run: cargo fmt --check
- name: Run clippy
run: cargo clippy --all-targets --all-features -- -D warnings
test:
name: Test (${{ matrix.os }})
runs-on: ${{ matrix.os }}
permissions:
contents: read
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Install Rust
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
key: ${{ matrix.os }}
- name: Run tests
run: cargo test --all-features --locked
deny:
name: cargo-deny
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: EmbarkStudios/cargo-deny-action@91bf2b620e09e18d6eb78b92e7861937469acedb # v2
with:
command: check
dist-sync-check:
name: Dist config sync
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Install dist
shell: bash
# nosemgrep -- cargo-dist bootstraps itself: official installer, HTTPS + TLS1.2, pinned v0.32.0
run: "curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.32.0/cargo-dist-installer.sh | sh"
- name: Check dist-workspace.toml and release.yml are in sync
run: dist generate --check
- name: Verify release.yml hand-edits survived regeneration
shell: bash
run: |
errors=0
# Verify nosemgrep risk-acceptance comments are present in release.yml
count=$(grep -c '# nosemgrep' .github/workflows/release.yml || echo 0)
if [ "$count" -lt 3 ]; then
echo "::error::Expected at least 3 '# nosemgrep' comments in release.yml, found $count"
errors=$((errors + 1))
fi
# Verify ci.yml's own nosemgrep is present (curl-pipe-to-shell must be annotated)
ci_count=$(grep -c '# nosemgrep' .github/workflows/ci.yml || echo 0)
if [ "$ci_count" -lt 1 ]; then
echo "::error::Missing '# nosemgrep' in ci.yml — curl-pipe-to-shell must be annotated"
errors=$((errors + 1))
fi
# Verify tightened tag globs (two patterns, no open-ended wildcard)
if ! grep -q "v\[0-9\]+\.\[0-9\]+\.\[0-9\]+'" .github/workflows/release.yml; then
echo "::error::Missing exact-version tag glob (v[0-9]+.[0-9]+.[0-9]+) in release.yml"
errors=$((errors + 1))
fi
if ! grep -q "v\[0-9\]+\.\[0-9\]+\.\[0-9\]+-\*'" .github/workflows/release.yml; then
echo "::error::Missing prerelease tag glob (v[0-9]+.[0-9]+.[0-9]+-*) in release.yml"
errors=$((errors + 1))
fi
# Verify top-level permissions are read-only (anchored to lines before 'jobs:',
# so a job-level 'contents: read' cannot mask a top-level write)
awk '/^jobs:/{exit} {print}' .github/workflows/release.yml | grep -q 'contents: read' || {
echo "::error::Top-level permissions in release.yml must be 'contents: read', not 'write'"
errors=$((errors + 1))
}
if [ "$errors" -gt 0 ]; then
echo "::error::$errors hand-edit guard(s) failed. See dist-workspace.toml for the required edits."
exit 1
fi
echo "All hand-edit guards passed."