Skip to content

chore(deps): bump toml in /bots/cipherbot #533

chore(deps): bump toml in /bots/cipherbot

chore(deps): bump toml in /bots/cipherbot #533

Workflow file for this run

# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: GitHub Pages
on:
push:
branches: [main, master]
pull_request:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: "pages-${{ github.event_name }}-${{ github.ref }}"
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
build:
name: Build Pages artifact
runs-on: ubuntu-24.04
timeout-minutes: 30
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v7.0.1
with:
persist-credentials: false
- name: Checkout casket-ssg
uses: actions/checkout@v7.0.1
with:
repository: hyperpolymath/casket-ssg
ref: cec3c20d80ea1dc93660b69a4e7b38aa49f2a56b # standalone build; optional liblol bridge
path: .casket-ssg
persist-credentials: false
- name: Cache Cabal
uses: actions/cache@v6.1.0
with:
path: |
~/.cabal/packages
~/.cabal/store
.casket-ssg/dist-newstyle
key: ${{ runner.os }}-casket-${{ hashFiles('.casket-ssg/casket-ssg.cabal') }}
# Explicitly allowed by repository policy; actions.lock pins its commit.
- name: Select tested Haskell toolchain
uses: haskell-actions/setup@v2.12.0
with:
ghc-version: '9.6.6'
cabal-version: '3.10.3.0'
- name: Prepare runner Haskell toolchain
run: |
set -euo pipefail
ghc --version
cabal --version
cabal update
- name: Build casket-ssg
working-directory: .casket-ssg
run: cabal build --index-state=2026-09-06T00:00:00Z
- name: Prepare site source
shell: bash
env:
CONTENT_REF: ${{ github.event_name == 'pull_request' && github.sha || github.ref_name }}
run: |
set -euo pipefail
rm -rf .site-src _site
if [ -d site ]; then
cp -R site .site-src
else
mkdir -p .site-src
TODAY="$(date +%Y-%m-%d)"
REPO_NAME="${{ github.event.repository.name }}"
REPO_URL="https://github.com/${{ github.repository }}"
README_URL=""
if [ -f README.md ]; then
README_URL="${REPO_URL}/blob/${CONTENT_REF}/README.md"
elif [ -f README.adoc ]; then
README_URL="${REPO_URL}/blob/${CONTENT_REF}/README.adoc"
fi
{
echo "---"
echo "title: ${REPO_NAME}"
echo "date: ${TODAY}"
echo "---"
echo
echo "# ${REPO_NAME}"
echo
echo "Static documentation site for ${REPO_NAME}."
echo
echo "- Source repository: [${{ github.repository }}](${REPO_URL})"
if [ -n "${README_URL}" ]; then
echo "- README: [project README](${README_URL})"
fi
if [ -d docs ]; then
echo "- Docs directory: [docs/](${REPO_URL}/tree/${CONTENT_REF}/docs)"
fi
echo
echo "Project-specific site content can be added later under site/."
} > .site-src/index.md
fi
- name: Build site
run: |
mkdir -p _site
cd .casket-ssg && cabal run --index-state=2026-09-06T00:00:00Z casket-ssg -- build ../.site-src ../_site
touch ../_site/.nojekyll
- name: Setup Pages
uses: actions/configure-pages@v6.0.0
- name: Upload artifact
uses: actions/upload-pages-artifact@v5.0.0
with:
path: '_site'
preview:
name: Validate Pages artifact
if: github.event_name == 'pull_request'
runs-on: ubuntu-24.04
needs: build
timeout-minutes: 10
permissions:
actions: read
contents: read
steps:
- name: Download Pages artifact
uses: actions/download-artifact@v8.0.1
with:
name: github-pages
path: .pages-preview
- name: Validate deployable artifact
shell: bash
run: |
set -euo pipefail
artifact=".pages-preview/artifact.tar"
entries_file="${RUNNER_TEMP}/pages-preview-entries.txt"
if [ ! -s "${artifact}" ]; then
echo "::error::Pages artifact is absent or empty"
exit 1
fi
tar -tf "${artifact}" > "${entries_file}"
entry_count=0
has_index=0
while IFS= read -r entry; do
entry_count=$((entry_count + 1))
case "${entry}" in
/*|../*|*/../*|*/..)
echo "::error::Pages artifact contains an unsafe path: ${entry}"
exit 1
;;
index.html|./index.html)
has_index=1
;;
esac
done < "${entries_file}"
if [ "${entry_count}" -eq 0 ]; then
echo "::error::Pages artifact contains no files"
exit 1
fi
if [ "${has_index}" -ne 1 ]; then
echo "::error::Pages artifact contains no index.html"
exit 1
fi
{
echo "### Pages preview artifact"
echo
echo "- Files: ${entry_count}"
echo "- SHA-256: \`$(sha256sum "${artifact}" | awk '{print $1}')\`"
echo "- Production deployment: intentionally deferred until merge"
} >> "${GITHUB_STEP_SUMMARY}"
deploy:
name: Deploy production Pages site
if: github.event_name != 'pull_request'
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
runs-on: ubuntu-24.04
needs: build
timeout-minutes: 10
permissions:
contents: read
pages: write
id-token: write
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@v5.0.0