chore(deps): bump tower-http in /bots/echidnabot #532
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # This workflow is managed by gh actions-lock. | |
| name: GitHub Pages | |
| on: | |
| push: | |
| branches: [main, master] | |
| pull_request: | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: "pages-${{ github.event_name }}-${{ github.ref }}" | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| build: | |
| name: Build Pages artifact | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 30 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Checkout casket-ssg | |
| uses: actions/checkout@v7.0.1 | |
| with: | |
| repository: hyperpolymath/casket-ssg | |
| ref: cec3c20d80ea1dc93660b69a4e7b38aa49f2a56b # standalone build; optional liblol bridge | |
| path: .casket-ssg | |
| persist-credentials: false | |
| - name: Cache Cabal | |
| uses: actions/cache@v6.1.0 | |
| with: | |
| path: | | |
| ~/.cabal/packages | |
| ~/.cabal/store | |
| .casket-ssg/dist-newstyle | |
| key: ${{ runner.os }}-casket-${{ hashFiles('.casket-ssg/casket-ssg.cabal') }} | |
| # Explicitly allowed by repository policy; actions.lock pins its commit. | |
| - name: Select tested Haskell toolchain | |
| uses: haskell-actions/setup@v2.12.0 | |
| with: | |
| ghc-version: '9.6.6' | |
| cabal-version: '3.10.3.0' | |
| - name: Prepare runner Haskell toolchain | |
| run: | | |
| set -euo pipefail | |
| ghc --version | |
| cabal --version | |
| cabal update | |
| - name: Build casket-ssg | |
| working-directory: .casket-ssg | |
| run: cabal build --index-state=2026-09-06T00:00:00Z | |
| - name: Prepare site source | |
| shell: bash | |
| env: | |
| CONTENT_REF: ${{ github.event_name == 'pull_request' && github.sha || github.ref_name }} | |
| run: | | |
| set -euo pipefail | |
| rm -rf .site-src _site | |
| if [ -d site ]; then | |
| cp -R site .site-src | |
| else | |
| mkdir -p .site-src | |
| TODAY="$(date +%Y-%m-%d)" | |
| REPO_NAME="${{ github.event.repository.name }}" | |
| REPO_URL="https://github.com/${{ github.repository }}" | |
| README_URL="" | |
| if [ -f README.md ]; then | |
| README_URL="${REPO_URL}/blob/${CONTENT_REF}/README.md" | |
| elif [ -f README.adoc ]; then | |
| README_URL="${REPO_URL}/blob/${CONTENT_REF}/README.adoc" | |
| fi | |
| { | |
| echo "---" | |
| echo "title: ${REPO_NAME}" | |
| echo "date: ${TODAY}" | |
| echo "---" | |
| echo | |
| echo "# ${REPO_NAME}" | |
| echo | |
| echo "Static documentation site for ${REPO_NAME}." | |
| echo | |
| echo "- Source repository: [${{ github.repository }}](${REPO_URL})" | |
| if [ -n "${README_URL}" ]; then | |
| echo "- README: [project README](${README_URL})" | |
| fi | |
| if [ -d docs ]; then | |
| echo "- Docs directory: [docs/](${REPO_URL}/tree/${CONTENT_REF}/docs)" | |
| fi | |
| echo | |
| echo "Project-specific site content can be added later under site/." | |
| } > .site-src/index.md | |
| fi | |
| - name: Build site | |
| run: | | |
| mkdir -p _site | |
| cd .casket-ssg && cabal run --index-state=2026-09-06T00:00:00Z casket-ssg -- build ../.site-src ../_site | |
| touch ../_site/.nojekyll | |
| - name: Setup Pages | |
| uses: actions/configure-pages@v6.0.0 | |
| - name: Upload artifact | |
| uses: actions/upload-pages-artifact@v5.0.0 | |
| with: | |
| path: '_site' | |
| preview: | |
| name: Validate Pages artifact | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-24.04 | |
| needs: build | |
| timeout-minutes: 10 | |
| permissions: | |
| actions: read | |
| contents: read | |
| steps: | |
| - name: Download Pages artifact | |
| uses: actions/download-artifact@v8.0.1 | |
| with: | |
| name: github-pages | |
| path: .pages-preview | |
| - name: Validate deployable artifact | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| artifact=".pages-preview/artifact.tar" | |
| entries_file="${RUNNER_TEMP}/pages-preview-entries.txt" | |
| if [ ! -s "${artifact}" ]; then | |
| echo "::error::Pages artifact is absent or empty" | |
| exit 1 | |
| fi | |
| tar -tf "${artifact}" > "${entries_file}" | |
| entry_count=0 | |
| has_index=0 | |
| while IFS= read -r entry; do | |
| entry_count=$((entry_count + 1)) | |
| case "${entry}" in | |
| /*|../*|*/../*|*/..) | |
| echo "::error::Pages artifact contains an unsafe path: ${entry}" | |
| exit 1 | |
| ;; | |
| index.html|./index.html) | |
| has_index=1 | |
| ;; | |
| esac | |
| done < "${entries_file}" | |
| if [ "${entry_count}" -eq 0 ]; then | |
| echo "::error::Pages artifact contains no files" | |
| exit 1 | |
| fi | |
| if [ "${has_index}" -ne 1 ]; then | |
| echo "::error::Pages artifact contains no index.html" | |
| exit 1 | |
| fi | |
| { | |
| echo "### Pages preview artifact" | |
| echo | |
| echo "- Files: ${entry_count}" | |
| echo "- SHA-256: \`$(sha256sum "${artifact}" | awk '{print $1}')\`" | |
| echo "- Production deployment: intentionally deferred until merge" | |
| } >> "${GITHUB_STEP_SUMMARY}" | |
| deploy: | |
| name: Deploy production Pages site | |
| if: github.event_name != 'pull_request' | |
| environment: | |
| name: github-pages | |
| url: ${{ steps.deployment.outputs.page_url }} | |
| runs-on: ubuntu-24.04 | |
| needs: build | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| pages: write | |
| id-token: write | |
| steps: | |
| - name: Deploy to GitHub Pages | |
| id: deployment | |
| uses: actions/deploy-pages@v5.0.0 |