Repair retired descriptile CI references with canonical-file safeguards #600
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # This workflow is managed by gh actions-lock. | |
| name: Rust | |
| # Build + test + clippy gate for the three standalone Rust crates. | |
| # Added after a non-compiling crate (robot-repo-automaton) reached `main` | |
| # unnoticed: the only prior Rust CI was CodeQL in build-mode `none` | |
| # (buildless), so nothing actually compiled or tested these crates. | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: ['**'] | |
| permissions: | |
| actions: read | |
| contents: read | |
| env: | |
| CARGO_TERM_COLOR: always | |
| # reqwest=rustls-tls, git2=vendored-openssl, gix=rust-tls. OPENSSL_NO_VENDOR | |
| # makes openssl-sys link the runner's preinstalled system OpenSSL instead of | |
| # recompiling the vendored copy (matches the documented local build). | |
| OPENSSL_NO_VENDOR: '1' | |
| jobs: | |
| rust: | |
| name: build · test · clippy | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| crate: [robot-repo-automaton, shared-context, dashboard] | |
| defaults: | |
| run: | |
| working-directory: ${{ matrix.crate }} | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - name: Ensure clippy + rustfmt components | |
| run: rustup component add clippy rustfmt | |
| - name: Build (all targets) | |
| run: cargo build --locked --all-targets --verbose | |
| - name: Test | |
| run: cargo test --locked --verbose | |
| - name: Clippy (deny warnings) | |
| run: cargo clippy --locked --all-targets -- -D warnings | |
| - name: Rustfmt check (informational) | |
| # Pre-existing formatting drift is not yet gated; surfaced here so it | |
| # stays visible without blocking. Flip to a hard gate after a dedicated | |
| # `cargo fmt` pass lands. | |
| run: cargo fmt --check | |
| continue-on-error: true | |
| dispatch-contracts: | |
| name: Dispatch path and outcome contracts | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - run: bash scripts/tests/dispatch-paths.sh | |
| gsbot: | |
| name: GSBot build, tests and dependency security | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 30 | |
| defaults: | |
| run: | |
| working-directory: bots/gsbot | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install native TLS build dependencies | |
| run: sudo apt-get update && sudo apt-get install -y pkg-config libssl-dev | |
| - name: Build and test SQLite services | |
| run: cargo test --locked --all-targets | |
| - name: Install dependency graph auditor | |
| run: cargo install cargo-deny --version 0.20.2 --locked | |
| - name: Audit enabled dependencies (no advisory exclusions) | |
| # Poise's unmaintained derive macro is reported as maintenance debt; | |
| # vulnerabilities, unsoundness and yanked crates remain blocking. | |
| run: cargo deny --locked --config deny.toml check advisories --warn unmaintained |