diff --git a/.github/workflows/gh-pages.yml b/.github/workflows/gh-pages.yml index 8f8649b9de..cf88becacc 100644 --- a/.github/workflows/gh-pages.yml +++ b/.github/workflows/gh-pages.yml @@ -9,6 +9,9 @@ on: branches: - main +permissions: + contents: read + jobs: check-typo: runs-on: ubuntu-latest @@ -57,6 +60,13 @@ jobs: # Checkout the repository to access the lychee config file - uses: actions/checkout@v7 + # Keep mise.toml as the single source of truth for the lychee version + - name: Read lychee version from mise.toml + id: lychee-version + run: | + version="$(python3 -c 'import tomllib; print(tomllib.load(open("mise.toml", "rb"))["tools"]["lychee"])')" + echo "version=v${version}" >> "$GITHUB_OUTPUT" + - name: Download Build Artifact uses: actions/download-artifact@v8 with: @@ -68,13 +78,15 @@ jobs: uses: lycheeverse/lychee-action@v2 with: fail: true - lycheeVersion: v0.21.0 - # --root-dir is required to resolve root-relative links (e.g. /talk/...) - # in the built HTML; without it lychee silently skips them. + lycheeVersion: ${{ steps.lychee-version.outputs.version }} + # --root-dir is required since lychee v0.24 to resolve root-relative + # links (e.g. /talk/...) in the built HTML; without it lychee errors + # out instead of silently skipping them like v0.21 did. args: "${{ vars.ARTIFACT_PATH }} --root-dir ${{ github.workspace }}/${{ vars.ARTIFACT_PATH }} --config .lychee/config.toml --exclude-file .lychee/exclude-temporary.txt --exclude-file .lychee/exclude-permanent.txt" deploy: - needs: build + needs: [build, check-broken-links] + if: (github.event_name == 'push' || github.event_name == 'workflow_dispatch') && github.ref == 'refs/heads/main' runs-on: ubuntu-latest steps: @@ -86,7 +98,6 @@ jobs: - name: Deploy uses: peaceiris/actions-gh-pages@v4 - if: (github.event_name == 'push' || github.event_name == 'workflow_dispatch') && github.ref == 'refs/heads/main' with: deploy_key: ${{ secrets.ACTIONS_DEPLOY_KEY }} publish_dir: ${{ vars.ARTIFACT_PATH }} diff --git a/.github/workflows/lychee-prune.yml b/.github/workflows/lychee-prune.yml index 10ae493f82..8ad4a51a55 100644 --- a/.github/workflows/lychee-prune.yml +++ b/.github/workflows/lychee-prune.yml @@ -43,6 +43,14 @@ jobs: with: token: ${{ steps.app-token.outputs.token }} + # Keep mise.toml as the single source of truth for the lychee version. + # Read it here, before "Prepare prune branch" switches branches. + - name: Read lychee version from mise.toml + id: lychee-version + run: | + version="$(python3 -c 'import tomllib; print(tomllib.load(open("mise.toml", "rb"))["tools"]["lychee"])')" + echo "version=v${version}" >> "$GITHUB_OUTPUT" + - name: Download Build Artifact uses: actions/download-artifact@v8 with: @@ -89,7 +97,7 @@ jobs: uses: lycheeverse/lychee-action@v2 with: fail: false - lycheeVersion: v0.21.0 + lycheeVersion: ${{ steps.lychee-version.outputs.version }} format: json output: lychee-excludes.json args: "--config .lychee/config.toml lychee-input.txt" diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml new file mode 100644 index 0000000000..672cbddb0c --- /dev/null +++ b/.github/workflows/test.yml @@ -0,0 +1,33 @@ +name: Test + +on: + push: + branches: + - main + paths: + - "tests/**" + - "scripts/**" + - ".agents/skills/**" + - ".github/workflows/test.yml" + pull_request: + paths: + - "tests/**" + - "scripts/**" + - ".agents/skills/**" + - ".github/workflows/test.yml" + +permissions: + contents: read + +jobs: + test: + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@v7 + + - name: Setup uv + uses: astral-sh/setup-uv@v8.3.2 + + - name: Run tests + run: uv run --with pytest --with ruamel.yaml pytest tests/ -q diff --git a/.lychee/exclude-temporary.txt b/.lychee/exclude-temporary.txt index 1d461767e5..2d78efcf97 100644 --- a/.lychee/exclude-temporary.txt +++ b/.lychee/exclude-temporary.txt @@ -23,3 +23,8 @@ confit.atlas.jp www.scimagojr.com clustrmaps.com www.meethawaii.com/convention-center/ + +# The page is alive (curl returns 200) but lychee >= v0.24 (rustls) cannot +# complete a TLS handshake because the server only offers legacy TLS cipher +# suites. Re-check regularly in case the server's TLS config is upgraded. +book.impress.co.jp diff --git a/config/_default/hugo.yaml b/config/_default/hugo.yaml index 8fa5b5c1cb..163eb19834 100644 --- a/config/_default/hugo.yaml +++ b/config/_default/hugo.yaml @@ -40,7 +40,7 @@ imaging: resampleFilter: Lanczos quality: 75 anchor: Smart -timeout: 600000 +timeout: "600s" taxonomies: tag: tags category: categories diff --git a/mise.toml b/mise.toml index bc91dcebb8..f2c73d481f 100644 --- a/mise.toml +++ b/mise.toml @@ -1,5 +1,5 @@ [tools] hugo-extended = "0.136.5" -lychee = "latest" +lychee = "0.24.2" "go:github.com/shunk031/tcardgen" = "latest"