Skip to content

Repair retired descriptile CI references with canonical-file safeguards #600

Repair retired descriptile CI references with canonical-file safeguards

Repair retired descriptile CI references with canonical-file safeguards #600

Workflow file for this run

# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Rust
# Build + test + clippy gate for the three standalone Rust crates.
# Added after a non-compiling crate (robot-repo-automaton) reached `main`
# unnoticed: the only prior Rust CI was CodeQL in build-mode `none`
# (buildless), so nothing actually compiled or tested these crates.
on:
push:
branches: [main]
pull_request:
branches: ['**']
permissions:
actions: read
contents: read
env:
CARGO_TERM_COLOR: always
# reqwest=rustls-tls, git2=vendored-openssl, gix=rust-tls. OPENSSL_NO_VENDOR
# makes openssl-sys link the runner's preinstalled system OpenSSL instead of
# recompiling the vendored copy (matches the documented local build).
OPENSSL_NO_VENDOR: '1'
jobs:
rust:
name: build · test · clippy
runs-on: ubuntu-latest
timeout-minutes: 30
strategy:
fail-fast: false
matrix:
crate: [robot-repo-automaton, shared-context, dashboard]
defaults:
run:
working-directory: ${{ matrix.crate }}
steps:
- uses: actions/checkout@v7.0.1
- name: Ensure clippy + rustfmt components
run: rustup component add clippy rustfmt
- name: Build (all targets)
run: cargo build --locked --all-targets --verbose
- name: Test
run: cargo test --locked --verbose
- name: Clippy (deny warnings)
run: cargo clippy --locked --all-targets -- -D warnings
- name: Rustfmt check (informational)
# Pre-existing formatting drift is not yet gated; surfaced here so it
# stays visible without blocking. Flip to a hard gate after a dedicated
# `cargo fmt` pass lands.
run: cargo fmt --check
continue-on-error: true
dispatch-contracts:
name: Dispatch path and outcome contracts
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
contents: read
steps:
- uses: actions/checkout@v7.0.1
with:
persist-credentials: false
- run: bash scripts/tests/dispatch-paths.sh
gsbot:
name: GSBot build, tests and dependency security
runs-on: ubuntu-24.04
timeout-minutes: 30
defaults:
run:
working-directory: bots/gsbot
steps:
- uses: actions/checkout@v7.0.1
with:
persist-credentials: false
- name: Install native TLS build dependencies
run: sudo apt-get update && sudo apt-get install -y pkg-config libssl-dev
- name: Build and test SQLite services
run: cargo test --locked --all-targets
- name: Install dependency graph auditor
run: cargo install cargo-deny --version 0.20.2 --locked
- name: Audit enabled dependencies (no advisory exclusions)
# Poise's unmaintained derive macro is reported as maintenance debt;
# vulnerabilities, unsoundness and yanked crates remain blocking.
run: cargo deny --locked --config deny.toml check advisories --warn unmaintained