Skip to content

ci: re-pin codeql-action to the true v4.38.0 commit #824

ci: re-pin codeql-action to the true v4.38.0 commit

ci: re-pin codeql-action to the true v4.38.0 commit #824

Workflow file for this run

# This workflow is managed by gh actions-lock.

Check failure on line 1 in .github/workflows/rust-ci.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/rust-ci.yml

Invalid workflow file

(Line: 55, Col: 9): 'with' is already defined
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Rust CI — thin wrapper calling the shared estate reusable in
# hyperpolymath/standards. Configure once, propagate everywhere.
# See: docs/CI-REUSABLE-WORKFLOWS.adoc in standards.
#
# DO NOT reintroduce a job-level `if: hashFiles('Cargo.toml') != ''` guard here.
# Job-level `if:` is evaluated server-side before any checkout, so hashFiles()
# has no workspace to hash. This workflow carried that guard on both local jobs
# and, as a result, failed 60/60 runs at 0s with zero jobs and no logs — a
# startup failure, not a test failure. GitHub reported the workflow's name as
# `.github/workflows/rust-ci.yml` (the path-fallback used when a file has never
# been parsed) rather than the declared `Rust CI`, which is how it was found.
# Net effect: this repo's Rust build/test gate never ran between 2026-06-27 and
# 2026-07-27. If a Cargo.toml presence check is ever needed, follow the estate
# reusable and gate on a `detect` job output, not on hashFiles() at job level.
name: Rust CI
on:
push:
branches: [main, master]
pull_request:
permissions:
actions: read
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
rust-ci:
uses: hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@571cc734cd69fb846032ec77a662aa8ee4fc32cd
no-default-features:
name: Cargo build + test (ephapax-cli, --no-default-features)
runs-on: ubuntu-latest
timeout-minutes: 20
# Proves ephapax can be built and tested with zero git dep on the
# sibling `hyperpolymath/typed-wasm` repo. Enforces the estate
# architectural rule that typed-wasm must be removable from either
# language with no impact. See `src/ephapax-wasm/src/ownership.rs`
# for the in-tree codec that makes this possible.
steps:
- name: Checkout repository
uses: actions/checkout@v7.0.1
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@v1
with:
toolchain: v1
with:
toolchain: stable # required when SHA-pinned (no rust-toolchain.toml in repo)
- name: Cache cargo registry and build
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
key: no-default-features
- name: Cargo build -p ephapax-cli --no-default-features
run: cargo build -p ephapax-cli --no-default-features
- name: Cargo test -p ephapax-cli --no-default-features
run: cargo test -p ephapax-cli --no-default-features
- name: Write summary
if: always()
run: |
{
echo "## --no-default-features build"
echo ""
echo "Proves the typed-wasm-verify feature is genuinely optional:"
echo "ephapax-cli builds + tests with zero git dep on the"
echo "hyperpolymath/typed-wasm repo."
} >> "$GITHUB_STEP_SUMMARY"
wasm-validate:
name: wasm-tools validate (emitted modules)
runs-on: ubuntu-latest
timeout-minutes: 20
# Structurally validates every module ephapax emits for the fixture
# corpus (`just validate-wasm`), catching codegen that produces an
# invalid wasm binary before it can land. Mirrors the in-process
# wasmparser assertion in the wasm_e2e tests and the CLI's always-on
# self-validation floor. The recipe pins CARGO_INCREMENTAL=0 to dodge a
# known rustc-incremental ICE on ephapax-parser.
steps:
- name: Checkout repository
uses: actions/checkout@v7.0.1
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@v1
with:
toolchain: stable # required when SHA-pinned (no rust-toolchain.toml in repo)
- name: Cache cargo registry and build
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
key: wasm-validate
- name: Install just + wasm-tools
run: cargo install just wasm-tools --locked
- name: Validate emitted wasm (just validate-wasm)
run: just validate-wasm
- name: Write summary
if: always()
run: |
{
echo "## wasm-tools validate"
echo ""
echo "Every module ephapax emits for the fixture corpus passes"
echo "wasm-tools validate (structural validity gate), including"
echo "the hypatia bridge.eph integration target."
} >> "$GITHUB_STEP_SUMMARY"