chore(deps): bump haskell-actions/setup from 2.12.0 to 2.12.1 in the actions group #763
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # This workflow is managed by gh actions-lock. | |
| name: Rust | |
| # Build + test + clippy gate for the three standalone Rust crates. | |
| # Added after a non-compiling crate (robot-repo-automaton) reached `main` | |
| # unnoticed: the only prior Rust CI was CodeQL in build-mode `none` | |
| # (buildless), so nothing actually compiled or tested these crates. | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: ['**'] | |
| permissions: | |
| actions: read | |
| contents: read | |
| env: | |
| CARGO_TERM_COLOR: always | |
| # reqwest=rustls-tls, git2=vendored-openssl, gix=rust-tls. OPENSSL_NO_VENDOR | |
| # makes openssl-sys link the runner's preinstalled system OpenSSL instead of | |
| # recompiling the vendored copy (matches the documented local build). | |
| OPENSSL_NO_VENDOR: '1' | |
| jobs: | |
| rust: | |
| name: build · test · clippy (${{ matrix.module }}) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # `module` is the label used in the job name; `dir` is where the crate | |
| # actually lives. They differ for rhodibot, which sits under bots/ -- | |
| # naming it `rhodibot` alone sent the job looking for a top-level | |
| # directory that does not exist. | |
| # | |
| # rhodibot was missing entirely until 2026-09-19, so the crate that | |
| # implements the GitHub App had never been built, tested or linted in | |
| # CI; its verification was whatever a human remembered to run locally. | |
| include: | |
| - module: robot-repo-automaton | |
| dir: robot-repo-automaton | |
| - module: shared-context | |
| dir: shared-context | |
| - module: dashboard | |
| dir: dashboard | |
| - module: rhodibot | |
| dir: bots/rhodibot | |
| defaults: | |
| run: | |
| working-directory: ${{ matrix.dir }} | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - name: Canon pin drift (rhodibot) | |
| # The rule set is copied from hyperpolymath/standards and pinned by | |
| # digest. This fails when the canon has moved since that pin, so a rule | |
| # change arrives as a reviewable commit rather than silently changing | |
| # what every repository is measured against. | |
| if: matrix.module == 'rhodibot' | |
| run: bash "$GITHUB_WORKSPACE/scripts/check-canon-drift.sh" | |
| - name: Ensure clippy + rustfmt components | |
| run: rustup component add clippy rustfmt | |
| - name: Build (all targets) | |
| run: cargo build --locked --all-targets --verbose | |
| - name: Test | |
| run: cargo test --locked --verbose | |
| - name: Clippy (deny warnings) | |
| run: cargo clippy --locked --all-targets -- -D warnings | |
| - name: Rustfmt check (informational) | |
| # Pre-existing formatting drift is not yet gated; surfaced here so it | |
| # stays visible without blocking. Flip to a hard gate after a dedicated | |
| # `cargo fmt` pass lands. | |
| run: cargo fmt --check | |
| continue-on-error: true | |
| dispatch-contracts: | |
| name: Dispatch path and outcome contracts | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - run: bash scripts/tests/dispatch-paths.sh | |
| gsbot: | |
| name: GSBot build, tests and dependency security | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 30 | |
| defaults: | |
| run: | |
| working-directory: bots/gsbot | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install native TLS build dependencies | |
| run: sudo apt-get update && sudo apt-get install -y pkg-config libssl-dev | |
| - name: Build and test SQLite services | |
| run: cargo test --locked --all-targets | |
| - name: Install dependency graph auditor | |
| run: cargo install cargo-deny --version 0.20.2 --locked | |
| - name: Audit enabled dependencies (no advisory exclusions) | |
| # Poise's unmaintained derive macro is reported as maintenance debt; | |
| # vulnerabilities, unsoundness and yanked crates remain blocking. | |
| run: cargo deny --locked --config deny.toml check advisories --warn unmaintained |