Repository navigation
ci: re-pin codeql-action to the true v4.38.0 commit #824
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| # Rust CI — thin wrapper calling the shared estate reusable in | ||
| # hyperpolymath/standards. Configure once, propagate everywhere. | ||
| # See: docs/CI-REUSABLE-WORKFLOWS.adoc in standards. | ||
| # | ||
| # DO NOT reintroduce a job-level `if: hashFiles('Cargo.toml') != ''` guard here. | ||
| # Job-level `if:` is evaluated server-side before any checkout, so hashFiles() | ||
| # has no workspace to hash. This workflow carried that guard on both local jobs | ||
| # and, as a result, failed 60/60 runs at 0s with zero jobs and no logs — a | ||
| # startup failure, not a test failure. GitHub reported the workflow's name as | ||
| # `.github/workflows/rust-ci.yml` (the path-fallback used when a file has never | ||
| # been parsed) rather than the declared `Rust CI`, which is how it was found. | ||
| # Net effect: this repo's Rust build/test gate never ran between 2026-06-27 and | ||
| # 2026-07-27. If a Cargo.toml presence check is ever needed, follow the estate | ||
| # reusable and gate on a `detect` job output, not on hashFiles() at job level. | ||
| name: Rust CI | ||
| on: | ||
| push: | ||
| branches: [main, master] | ||
| pull_request: | ||
| permissions: | ||
| actions: read | ||
| contents: read | ||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.ref }} | ||
| cancel-in-progress: true | ||
| jobs: | ||
| rust-ci: | ||
| uses: hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@571cc734cd69fb846032ec77a662aa8ee4fc32cd | ||
| no-default-features: | ||
| name: Cargo build + test (ephapax-cli, --no-default-features) | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 20 | ||
| # Proves ephapax can be built and tested with zero git dep on the | ||
| # sibling `hyperpolymath/typed-wasm` repo. Enforces the estate | ||
| # architectural rule that typed-wasm must be removable from either | ||
| # language with no impact. See `src/ephapax-wasm/src/ownership.rs` | ||
| # for the in-tree codec that makes this possible. | ||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| - name: Install Rust toolchain | ||
| uses: dtolnay/rust-toolchain@v1 | ||
| with: | ||
| toolchain: v1 | ||
| with: | ||
| toolchain: stable # required when SHA-pinned (no rust-toolchain.toml in repo) | ||
| - name: Cache cargo registry and build | ||
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | ||
| with: | ||
| key: no-default-features | ||
| - name: Cargo build -p ephapax-cli --no-default-features | ||
| run: cargo build -p ephapax-cli --no-default-features | ||
| - name: Cargo test -p ephapax-cli --no-default-features | ||
| run: cargo test -p ephapax-cli --no-default-features | ||
| - name: Write summary | ||
| if: always() | ||
| run: | | ||
| { | ||
| echo "## --no-default-features build" | ||
| echo "" | ||
| echo "Proves the typed-wasm-verify feature is genuinely optional:" | ||
| echo "ephapax-cli builds + tests with zero git dep on the" | ||
| echo "hyperpolymath/typed-wasm repo." | ||
| } >> "$GITHUB_STEP_SUMMARY" | ||
| wasm-validate: | ||
| name: wasm-tools validate (emitted modules) | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 20 | ||
| # Structurally validates every module ephapax emits for the fixture | ||
| # corpus (`just validate-wasm`), catching codegen that produces an | ||
| # invalid wasm binary before it can land. Mirrors the in-process | ||
| # wasmparser assertion in the wasm_e2e tests and the CLI's always-on | ||
| # self-validation floor. The recipe pins CARGO_INCREMENTAL=0 to dodge a | ||
| # known rustc-incremental ICE on ephapax-parser. | ||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v7.0.1 | ||
| - name: Install Rust toolchain | ||
| uses: dtolnay/rust-toolchain@v1 | ||
| with: | ||
| toolchain: stable # required when SHA-pinned (no rust-toolchain.toml in repo) | ||
| - name: Cache cargo registry and build | ||
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | ||
| with: | ||
| key: wasm-validate | ||
| - name: Install just + wasm-tools | ||
| run: cargo install just wasm-tools --locked | ||
| - name: Validate emitted wasm (just validate-wasm) | ||
| run: just validate-wasm | ||
| - name: Write summary | ||
| if: always() | ||
| run: | | ||
| { | ||
| echo "## wasm-tools validate" | ||
| echo "" | ||
| echo "Every module ephapax emits for the fixture corpus passes" | ||
| echo "wasm-tools validate (structural validity gate), including" | ||
| echo "the hypatia bridge.eph integration target." | ||
| } >> "$GITHUB_STEP_SUMMARY" | ||