-
-
Notifications
You must be signed in to change notification settings - Fork 0
107 lines (105 loc) · 4.12 KB
/
Copy pathrust.yml
File metadata and controls
107 lines (105 loc) · 4.12 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Rust
# Build + test + clippy gate for the three standalone Rust crates.
# Added after a non-compiling crate (robot-repo-automaton) reached `main`
# unnoticed: the only prior Rust CI was CodeQL in build-mode `none`
# (buildless), so nothing actually compiled or tested these crates.
on:
push:
branches: [main]
pull_request:
branches: ['**']
permissions:
actions: read
contents: read
env:
CARGO_TERM_COLOR: always
# reqwest=rustls-tls, git2=vendored-openssl, gix=rust-tls. OPENSSL_NO_VENDOR
# makes openssl-sys link the runner's preinstalled system OpenSSL instead of
# recompiling the vendored copy (matches the documented local build).
OPENSSL_NO_VENDOR: '1'
jobs:
rust:
name: build · test · clippy (${{ matrix.module }})
runs-on: ubuntu-latest
timeout-minutes: 30
strategy:
fail-fast: false
matrix:
# `module` is the label used in the job name; `dir` is where the crate
# actually lives. They differ for rhodibot, which sits under bots/ --
# naming it `rhodibot` alone sent the job looking for a top-level
# directory that does not exist.
#
# rhodibot was missing entirely until 2026-09-19, so the crate that
# implements the GitHub App had never been built, tested or linted in
# CI; its verification was whatever a human remembered to run locally.
include:
- module: robot-repo-automaton
dir: robot-repo-automaton
- module: shared-context
dir: shared-context
- module: dashboard
dir: dashboard
- module: rhodibot
dir: bots/rhodibot
defaults:
run:
working-directory: ${{ matrix.dir }}
steps:
- uses: actions/checkout@v7.0.1
- name: Canon pin drift (rhodibot)
# The rule set is copied from hyperpolymath/standards and pinned by
# digest. This fails when the canon has moved since that pin, so a rule
# change arrives as a reviewable commit rather than silently changing
# what every repository is measured against.
if: matrix.module == 'rhodibot'
run: bash "$GITHUB_WORKSPACE/scripts/check-canon-drift.sh"
- name: Ensure clippy + rustfmt components
run: rustup component add clippy rustfmt
- name: Build (all targets)
run: cargo build --locked --all-targets --verbose
- name: Test
run: cargo test --locked --verbose
- name: Clippy (deny warnings)
run: cargo clippy --locked --all-targets -- -D warnings
- name: Rustfmt check (informational)
# Pre-existing formatting drift is not yet gated; surfaced here so it
# stays visible without blocking. Flip to a hard gate after a dedicated
# `cargo fmt` pass lands.
run: cargo fmt --check
continue-on-error: true
dispatch-contracts:
name: Dispatch path and outcome contracts
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
contents: read
steps:
- uses: actions/checkout@v7.0.1
with:
persist-credentials: false
- run: bash scripts/tests/dispatch-paths.sh
gsbot:
name: GSBot build, tests and dependency security
runs-on: ubuntu-24.04
timeout-minutes: 30
defaults:
run:
working-directory: bots/gsbot
steps:
- uses: actions/checkout@v7.0.1
with:
persist-credentials: false
- name: Install native TLS build dependencies
run: sudo apt-get update && sudo apt-get install -y pkg-config libssl-dev
- name: Build and test SQLite services
run: cargo test --locked --all-targets
- name: Install dependency graph auditor
run: cargo install cargo-deny --version 0.20.2 --locked
- name: Audit enabled dependencies (no advisory exclusions)
# Poise's unmaintained derive macro is reported as maintenance debt;
# vulnerabilities, unsoundness and yanked crates remain blocking.
run: cargo deny --locked --config deny.toml check advisories --warn unmaintained