Skip to content

fix(ci): pin third-party actions to full commit SHAs (#85) #229

fix(ci): pin third-party actions to full commit SHAs (#85)

fix(ci): pin third-party actions to full commit SHAs (#85) #229

Workflow file for this run

# SPDX-License-Identifier: MPL-2.0

Check failure on line 1 in .github/workflows/quality-gates.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/quality-gates.yml

Invalid workflow file

(Line: 40, Col: 9): 'with' is already defined
name: Quality Gates
permissions:
actions: read
contents: read
on:
pull_request:
push:
branches:
- main
jobs:
must-gates:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install system dependencies
run: |
sudo apt-get update
sudo apt-get install -y just gnat gprbuild ripgrep
- name: Run must invariants
run: ./scripts/run-must-gates.sh
- name: Verify trust manifests
run: ./scripts/trust/verify-manifest.sh
test-all:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install Rust toolchain
# v1 tag, not a SHA: dtolnay force-moves toolchain branches, so no
# symbolic ref contains the old pin and lockfile generation refuses it.
# The actions.lock records the resolved SHA; the toolchain must be an
# explicit input because the ref no longer selects it.
uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1
with:
toolchain: v1
with:
toolchain: stable
- name: Install system dependencies
run: |
sudo apt-get update
sudo apt-get install -y just gnat gprbuild
- name: Run unified test gate
run: just test-all