From 56c22dd4ed94fd7b27ac8084933e75183ccb1a5d Mon Sep 17 00:00:00 2001 From: Jacob Magar Date: Thu, 30 Jul 2026 21:29:53 -0400 Subject: [PATCH 1/4] build(android): enforce x86_64-only Rust targets --- .../src-tauri/gen/android/app/build.gradle.kts | 6 ++---- .../java/tv/tootie/aurora/catalog/kotlin/RustPlugin.kt | 8 ++++---- 2 files changed, 6 insertions(+), 8 deletions(-) diff --git a/apps/device-catalog/src-tauri/gen/android/app/build.gradle.kts b/apps/device-catalog/src-tauri/gen/android/app/build.gradle.kts index 0bfd8b1d..2b69837a 100644 --- a/apps/device-catalog/src-tauri/gen/android/app/build.gradle.kts +++ b/apps/device-catalog/src-tauri/gen/android/app/build.gradle.kts @@ -31,9 +31,7 @@ android { isDebuggable = true isJniDebuggable = true isMinifyEnabled = false - packaging { jniLibs.keepDebugSymbols.add("*/arm64-v8a/*.so") - jniLibs.keepDebugSymbols.add("*/armeabi-v7a/*.so") - jniLibs.keepDebugSymbols.add("*/x86/*.so") + packaging { jniLibs.keepDebugSymbols.add("*/x86_64/*.so") } } @@ -69,4 +67,4 @@ dependencies { androidTestImplementation("androidx.test.espresso:espresso-core:3.5.0") } -apply(from = "tauri.build.gradle.kts") \ No newline at end of file +apply(from = "tauri.build.gradle.kts") diff --git a/apps/device-catalog/src-tauri/gen/android/buildSrc/src/main/java/tv/tootie/aurora/catalog/kotlin/RustPlugin.kt b/apps/device-catalog/src-tauri/gen/android/buildSrc/src/main/java/tv/tootie/aurora/catalog/kotlin/RustPlugin.kt index 4aa7fcaf..413e43ba 100644 --- a/apps/device-catalog/src-tauri/gen/android/buildSrc/src/main/java/tv/tootie/aurora/catalog/kotlin/RustPlugin.kt +++ b/apps/device-catalog/src-tauri/gen/android/buildSrc/src/main/java/tv/tootie/aurora/catalog/kotlin/RustPlugin.kt @@ -17,13 +17,13 @@ open class RustPlugin : Plugin { override fun apply(project: Project) = with(project) { config = extensions.create("rust", Config::class.java) - val defaultAbiList = listOf("arm64-v8a", "armeabi-v7a", "x86", "x86_64"); + val defaultAbiList = listOf("x86_64"); val abiList = (findProperty("abiList") as? String)?.split(',') ?: defaultAbiList - val defaultArchList = listOf("arm64", "arm", "x86", "x86_64"); + val defaultArchList = listOf("x86_64"); val archList = (findProperty("archList") as? String)?.split(',') ?: defaultArchList - val targetsList = (findProperty("targetList") as? String)?.split(',') ?: listOf("aarch64", "armv7", "i686", "x86_64") + val targetsList = (findProperty("targetList") as? String)?.split(',') ?: listOf("x86_64") extensions.configure { @Suppress("UnstableApiUsage") @@ -82,4 +82,4 @@ open class RustPlugin : Plugin { } } } -} \ No newline at end of file +} From b838a5e23a978e272978fc3c2ffcbd68596ad217 Mon Sep 17 00:00:00 2001 From: Jacob Magar Date: Thu, 30 Jul 2026 21:30:01 -0400 Subject: [PATCH 2/4] chore: align repository metadata contracts --- docs/component-kotlin-map.md | 6 ++++++ docs/deployment.md | 6 ++++++ docs/gallery-complaint-matrix.md | 7 ++++++- docs/security.md | 6 ++++++ docs/versioning.md | 6 ++++++ plugin/.claude-plugin/plugin.json | 3 +-- 6 files changed, 31 insertions(+), 3 deletions(-) diff --git a/docs/component-kotlin-map.md b/docs/component-kotlin-map.md index 51917c14..ca96fa51 100644 --- a/docs/component-kotlin-map.md +++ b/docs/component-kotlin-map.md @@ -1,3 +1,9 @@ +--- +title: Aurora Component to Kotlin and Compose Map +created: 2026-07-30 +updated: 2026-07-30 +--- + # Aurora Component → Kotlin/Compose Map Cross-reference of every Aurora (shadcn/React) component and its nearest Jetpack Compose / Material 3 equivalent. diff --git a/docs/deployment.md b/docs/deployment.md index fe41f612..6f4b85d7 100644 --- a/docs/deployment.md +++ b/docs/deployment.md @@ -1,3 +1,9 @@ +--- +title: Immutable deployment and rollback +created: 2026-07-30 +updated: 2026-07-30 +--- + # Immutable deployment and rollback The public Aurora path is an immutable standalone Next.js image. The writable diff --git a/docs/gallery-complaint-matrix.md b/docs/gallery-complaint-matrix.md index 3178a520..5856c601 100644 --- a/docs/gallery-complaint-matrix.md +++ b/docs/gallery-complaint-matrix.md @@ -1,3 +1,9 @@ +--- +title: Aurora Gallery Complaint Matrix +created: 2026-07-30 +updated: 2026-07-30 +--- + # Aurora Gallery Complaint Matrix This file captures each review comment as a chooser prompt. Each item has a blank `Answer` space for the selected direction after reviewing the gallery alternatives. @@ -420,4 +426,3 @@ Path: `/home/jmagar/workspace/aurora/app/gallery/demos/type-demo.tsx` - [ ] Typography demo needs work; larger examples look better and should guide the scale. Answer: - diff --git a/docs/security.md b/docs/security.md index c8555d83..fb409285 100644 --- a/docs/security.md +++ b/docs/security.md @@ -1,3 +1,9 @@ +--- +title: Security Posture +created: 2026-07-30 +updated: 2026-07-30 +--- + # Security Posture This document describes the known security characteristics and limitations of diff --git a/docs/versioning.md b/docs/versioning.md index 3f565e6f..04c3efb7 100644 --- a/docs/versioning.md +++ b/docs/versioning.md @@ -1,3 +1,9 @@ +--- +title: Versioning and reproducible consumption +created: 2026-07-30 +updated: 2026-07-30 +--- + # Versioning and reproducible consumption Aurora has two deliberately different registry URL contracts. diff --git a/plugin/.claude-plugin/plugin.json b/plugin/.claude-plugin/plugin.json index 55088804..16e47bfe 100644 --- a/plugin/.claude-plugin/plugin.json +++ b/plugin/.claude-plugin/plugin.json @@ -1,13 +1,12 @@ { "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json", "name": "aurora", - "version": "0.1.0", "description": "Aurora design system skill for building dark-first, navy/cyan/rose/Axon-orange operator and agent control-plane UI with the @aurora shadcn registry and var(--aurora-*) tokens.", "author": { "name": "Jacob Magar", "email": "jmagar@users.noreply.github.com" }, - "repository": "https://github.com/jmagar/aurora", + "repository": "https://github.com/dinglebear-ai/aurora", "homepage": "https://aurora.tootie.tv", "license": "MIT", "keywords": [ From 394949bb10802981e3275bf772a0903c7133b3ec Mon Sep 17 00:00:00 2001 From: Jacob Magar Date: Thu, 30 Jul 2026 21:30:09 -0400 Subject: [PATCH 3/4] ci: align workflows with the runner fleet --- .github/actionlint.yaml | 7 +- .github/workflows/ci.yml | 174 ++++++++++----------------- .github/workflows/publish.yml | 156 ++++++++++++------------ .github/workflows/release-please.yml | 32 ++--- .github/workflows/synthetics.yml | 31 ++--- 5 files changed, 164 insertions(+), 236 deletions(-) diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml index 1b712d85..e8481971 100644 --- a/.github/actionlint.yaml +++ b/.github/actionlint.yaml @@ -1,6 +1,5 @@ -# Custom labels for the org's self-hosted runner farm (tootie-ci-runner-1..4), -# so actionlint (run by the Workflow and dependency policy check) accepts -# runs-on entries like [self-hosted, unraid]. self-hosted-runner: labels: - - unraid + - ci-pool-typescript + - ci-pool-ops + - residential-egress diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index bc439358..cfd0331a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -5,132 +5,86 @@ on: push: branches: [main] -permissions: {} +permissions: + contents: read concurrency: group: ci-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: + contract: + uses: dinglebear-ai/workflows/.github/workflows/fleet-contract.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + with: + profile: node + implementation-ref: 542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + policy: - name: Workflow and dependency policy - runs-on: ubuntu-latest - permissions: - contents: read + uses: dinglebear-ai/workflows/.github/workflows/fast-ops.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + with: + shell-globs: "ops/*.sh" + policy-command: >- + ops/check-action-pins.sh && + ops/check-production-topology.sh && + node scripts/sync-agent-skill.mjs --check && + ops/check-skill-sync.sh + + gradle-wrapper: + name: Gradle wrapper + runs-on: [self-hosted, ci-pool-ops] + timeout-minutes: 5 steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - - name: Require immutable action references - run: ops/check-action-pins.sh - - name: Validate workflow syntax - uses: docker://rhysd/actionlint@sha256:ef8299f97635c4c30e2298f48f30763ab782a4ad2c95b744649439a039421e36 # 1.7.10 - - name: Validate Gradle wrapper - uses: gradle/actions/wrapper-validation@3f131e8634966bd73d06cc69884922b02e6faf92 # v6.2.0 - - name: Validate deployment topology - run: ops/check-production-topology.sh - - name: Validate operations shell - run: shellcheck ops/*.sh - - name: Validate generated skill documentation - run: node scripts/sync-agent-skill.mjs --check && ops/check-skill-sync.sh + - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 + with: + persist-credentials: false + - uses: gradle/actions/wrapper-validation@3f131e8634966bd73d06cc69884922b02e6faf92 # v6 - osv: + dependencies: name: OSV dependency scan - runs-on: ubuntu-latest + runs-on: [self-hosted, ci-pool-typescript] + timeout-minutes: 10 permissions: contents: read security-events: write steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - - uses: google/osv-scanner-action/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2.3.8 + - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 + with: + persist-credentials: false + - uses: google/osv-scanner-action/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2 with: - scan-args: |- - --lockfile=pnpm-lock.yaml + scan-args: --lockfile=pnpm-lock.yaml web: - name: Web, registry, and standalone - runs-on: ubuntu-latest - permissions: - contents: read - steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 - with: - version: 10.33.2 - - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 - with: - node-version: 24 - cache: pnpm - - name: Cache Next.js build - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: .next/cache - key: nextjs-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'next.config.*', 'proxy.ts') }} - restore-keys: nextjs-${{ runner.os }}- - - run: pnpm install --frozen-lockfile - - run: pnpm run lint - - run: pnpm run audit:composition - - run: pnpm exec tsc --noEmit - - run: pnpm run test:unit - - run: pnpm run test:coverage - - name: Build the tested revision - env: - AURORA_BUILD_SHA: ${{ github.sha }} - run: pnpm run build - - name: Enforce production client JavaScript budgets - run: pnpm run performance:check - - name: Install Playwright Chromium, Firefox, and WebKit - run: pnpm exec playwright install --with-deps chromium firefox webkit - - name: Cross-browser, mobile, and strict Storybook accessibility contracts - run: pnpm run test:e2e - - run: pnpm run refs:check - - run: pnpm run audit:standalone - - name: Smoke production security and cache headers - env: - AURORA_BUILD_SHA: ${{ github.sha }} - run: ops/smoke-production.sh - - run: pnpm run registry:check - - run: pnpm run registry:validate - - run: pnpm run registry:graph - - run: pnpm run registry:smoke - - run: pnpm run gallery:check - - run: pnpm run catalog:check - - run: pnpm run tokens:generate - - name: Generated artifacts are committed - run: git diff --exit-code + uses: dinglebear-ai/workflows/.github/workflows/fast-pnpm.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + with: + node-version: "24" + pnpm-version: "10.33.2" + audit-command: pnpm audit --audit-level high + lint-command: pnpm run lint + typecheck-command: pnpm exec tsc --noEmit + test-command: pnpm run test:coverage + contract-command: >- + pnpm run audit:composition && + pnpm run refs:check && + pnpm run audit:standalone && + pnpm run registry:check && + pnpm run registry:validate && + pnpm run registry:graph && + pnpm run registry:smoke && + pnpm run gallery:check && + pnpm run catalog:check && + pnpm run tokens:generate && + git diff --exit-code + timeout-minutes: 25 - android: - name: Android app and library variants - runs-on: ubuntu-latest - permissions: - contents: read + gate: + name: CI + if: always() + needs: [contract, policy, gradle-wrapper, dependencies, web] + runs-on: [self-hosted, ci-pool-ops] + timeout-minutes: 2 steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 - with: - version: 10.33.2 - - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 - with: - node-version: 24 - cache: pnpm - - uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4 - with: - distribution: temurin - java-version: "21" - - name: Cache Gradle wrapper and caches - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.gradle/wrapper - ~/.gradle/caches - key: gradle-${{ runner.os }}-${{ hashFiles('android/**/*.gradle*', 'android/gradle/wrapper/gradle-wrapper.properties') }} - restore-keys: gradle-${{ runner.os }}- - - run: pnpm install --frozen-lockfile - - name: Gate all app/library variants, release lint/package, wrapper, and Roborazzi goldens - run: ./gradlew androidCheck --no-daemon - working-directory: android - - name: Run Android managed-device instrumentation smoke - run: | - if [[ -e /dev/kvm ]]; then sudo chmod 666 /dev/kvm; fi - ./gradlew androidManagedDeviceCheck --no-daemon - working-directory: android - - name: Smoke external composite-build consumption - run: ops/smoke-android-composite.sh + - name: Require every fast lane + env: + RESULTS: ${{ join(needs.*.result, ' ') }} + run: test "$RESULTS" = "success success success success success" diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 13ae6bf9..20db4764 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,92 +1,88 @@ -name: Publish image +name: Release artifacts on: - workflow_run: - workflows: ["CI"] - types: [completed] - branches: [main] + release: + types: [published] permissions: {} concurrency: - group: publish-tested-main + group: aurora-release-${{ github.event.release.tag_name }} cancel-in-progress: false jobs: - publish: - name: Publish tested SHA and promote its verified digest - if: >- - github.event.workflow_run.conclusion == 'success' && - github.event.workflow_run.event == 'push' && - github.event.workflow_run.head_branch == 'main' - runs-on: ubuntu-latest + web: + permissions: + contents: read + uses: dinglebear-ai/workflows/.github/workflows/hosted-web-release.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + with: + checkout-ref: ${{ github.event.release.tag_name }} + node-version: "24" + package-cache: pnpm + pnpm-version: "10.33.2" + cache-dependency-path: pnpm-lock.yaml + install-command: pnpm install --frozen-lockfile + coverage-command: pnpm run test:coverage + build-command: >- + AURORA_BUILD_SHA=${{ github.sha }} + pnpm run build + performance-command: pnpm run performance:check + e2e-command: pnpm run test:e2e + artifact-name: aurora-web-${{ github.event.release.tag_name }} + artifact-path: .next/standalone + diagnostic-path: | + playwright-report/ + test-results/ + timeout-minutes: 60 + + android: + permissions: + contents: read + uses: dinglebear-ai/workflows/.github/workflows/hosted-android-release.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + with: + checkout-ref: ${{ github.event.release.tag_name }} + java-version: "21" + working-directory: android + setup-command: >- + corepack enable && + corepack prepare pnpm@10.33.2 --activate && + pnpm --dir .. install --frozen-lockfile + release-command: ./gradlew androidCheck --no-daemon + device-command: | + if [[ -e /dev/kvm ]]; then sudo chmod 666 /dev/kvm; fi + ./gradlew androidManagedDeviceCheck --no-daemon + ../ops/smoke-android-composite.sh + artifact-name: aurora-android-${{ github.event.release.tag_name }} + artifact-path: android/**/build/outputs/** + report-path: android/**/build/reports/** + timeout-minutes: 90 + + container: permissions: contents: read packages: write - env: - # Derived, not hard-coded: this was left pointing at ghcr.io/jmagar/aurora - # after the repository moved to dinglebear-ai, and GITHUB_TOKEN cannot push - # to a package in another account's namespace. - IMAGE: ghcr.io/${{ github.repository }} - TESTED_SHA: ${{ github.event.workflow_run.head_sha }} - steps: - - name: Check out the exact tested revision - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - with: - ref: ${{ github.event.workflow_run.head_sha }} - persist-credentials: false - - name: Prove checkout identity - run: test "$(git rev-parse HEAD)" = "$TESTED_SHA" - - name: Log in to GHCR - uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0 - with: - registry: ghcr.io - username: ${{ github.actor }} - password: ${{ secrets.GITHUB_TOKEN }} - - name: Set up Buildx - uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 - - name: Build and push immutable SHA tag with provenance and SBOM attestations - id: build - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 - with: - context: . - target: runner - push: true - tags: ${{ env.IMAGE }}:sha-${{ env.TESTED_SHA }} - labels: | - org.opencontainers.image.source=https://github.com/${{ github.repository }} - org.opencontainers.image.revision=${{ env.TESTED_SHA }} - build-args: AURORA_BUILD_SHA=${{ env.TESTED_SHA }} - provenance: false - sbom: false - cache-from: type=gha - cache-to: type=gha,mode=max - - name: Record tested image identity - env: - DIGEST: ${{ steps.build.outputs.digest }} - run: | - test -n "$DIGEST" - printf '%s\n' "$IMAGE@$DIGEST" > image-ref.txt - printf '%s\n' "$TESTED_SHA" > source-sha.txt - - name: Scan the exact digest before promotion - uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 - with: - image-ref: ${{ env.IMAGE }}@${{ steps.build.outputs.digest }} - version: v0.72.0 - format: table - severity: CRITICAL,HIGH - ignore-unfixed: true - exit-code: "1" - - name: Promote only the scanned digest to latest - env: - DIGEST: ${{ steps.build.outputs.digest }} - run: docker buildx imagetools create --tag "$IMAGE:latest" "$IMAGE@$DIGEST" - - name: Upload promotion evidence - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: aurora-image-${{ env.TESTED_SHA }} - path: | - image-ref.txt - source-sha.txt - if-no-files-found: error - retention-days: 90 + attestations: write + id-token: write + uses: dinglebear-ai/workflows/.github/workflows/hosted-container-release.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + with: + checkout-ref: ${{ github.event.release.tag_name }} + image: ghcr.io/${{ github.repository }} + release-tag: ${{ github.event.release.tag_name }} + build-args: AURORA_BUILD_SHA=${{ github.sha }} + smoke-command: | + set -euo pipefail + name="aurora-release-smoke-${GITHUB_RUN_ID}" + trap 'docker rm -f "$name" >/dev/null 2>&1 || true' EXIT + docker run -d --name "$name" -p 127.0.0.1::3000 "$IMAGE_REF" >/dev/null + port="$(docker port "$name" 3000/tcp | awk -F: '{print $NF}')" + for _ in {1..45}; do + curl --fail --silent "http://127.0.0.1:${port}/" >/dev/null && exit 0 + sleep 2 + done + docker logs "$name" + exit 1 + cache-scope: aurora-release + timeout-minutes: 60 + secrets: + REGISTRY_USERNAME: ${{ github.actor }} + REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index a5c00157..468b5806 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -1,34 +1,20 @@ -name: release-please +name: Release Please on: - workflow_run: - workflows: ["CI"] - types: [completed] + push: branches: [main] workflow_dispatch: -permissions: {} +permissions: + contents: write + pull-requests: write concurrency: group: release-please-main cancel-in-progress: false jobs: - release-please: - if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }} - runs-on: ubuntu-latest - permissions: - contents: write - pull-requests: write - issues: write - steps: - - name: Require release-please token - env: - RELEASE_PLEASE_TOKEN: ${{ secrets.RELEASE_PLEASE_TOKEN }} - run: test -n "$RELEASE_PLEASE_TOKEN" - - uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 - id: release - with: - token: ${{ secrets.RELEASE_PLEASE_TOKEN }} - config-file: release-please-config.json - manifest-file: .release-please-manifest.json + release: + uses: dinglebear-ai/workflows/.github/workflows/release-please.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + secrets: + RELEASE_PLEASE_TOKEN: ${{ secrets.RELEASE_PLEASE_TOKEN }} diff --git a/.github/workflows/synthetics.yml b/.github/workflows/synthetics.yml index 9902633b..5797b821 100644 --- a/.github/workflows/synthetics.yml +++ b/.github/workflows/synthetics.yml @@ -5,28 +5,21 @@ on: schedule: - cron: "17,47 * * * *" -permissions: {} +permissions: + contents: read concurrency: group: aurora-public-synthetics - cancel-in-progress: true + cancel-in-progress: false jobs: public-path: - # Self-hosted (tootie runner farm): residential egress is not challenged by - # Cloudflare, unlike GitHub-hosted Azure IPs (see ops/synthetics-cloudflare.md). - runs-on: [self-hosted, unraid] - permissions: - contents: read - steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - - name: Check landing, content negotiation, deployed-revision registry checksum, revision, and TLS - env: - AURORA_PUBLIC_URL: ${{ vars.AURORA_PUBLIC_URL || 'https://aurora.tootie.tv' }} - AURORA_TLS_MIN_SECONDS: ${{ vars.AURORA_TLS_MIN_SECONDS || '1209600' }} - run: ops/synthetic-check.sh - - name: Check the co-hosted dinglebear tenant - env: - AURORA_PUBLIC_URL: ${{ vars.AURORA_TENANT_URL || 'https://dinglebear.ai' }} - AURORA_TLS_MIN_SECONDS: ${{ vars.AURORA_TLS_MIN_SECONDS || '1209600' }} - run: ops/synthetic-check.sh + uses: dinglebear-ai/workflows/.github/workflows/synthetic-check.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + with: + command: >- + AURORA_PUBLIC_URL="${{ vars.AURORA_PUBLIC_URL || 'https://aurora.tootie.tv' }}" + AURORA_TLS_MIN_SECONDS="${{ vars.AURORA_TLS_MIN_SECONDS || '1209600' }}" + ops/synthetic-check.sh && + AURORA_PUBLIC_URL="${{ vars.AURORA_TENANT_URL || 'https://dinglebear.ai' }}" + AURORA_TLS_MIN_SECONDS="${{ vars.AURORA_TLS_MIN_SECONDS || '1209600' }}" + ops/synthetic-check.sh From 7e6e78fc399096873ff60551e8829f10c0fce362 Mon Sep 17 00:00:00 2001 From: Jacob Magar Date: Thu, 30 Jul 2026 21:58:50 -0400 Subject: [PATCH 4/4] ci: repin reusable workflows --- .github/workflows/ci.yml | 8 ++++---- .github/workflows/publish.yml | 6 +++--- .github/workflows/release-please.yml | 2 +- .github/workflows/synthetics.yml | 2 +- 4 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index cfd0331a..0fa25e86 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -14,13 +14,13 @@ concurrency: jobs: contract: - uses: dinglebear-ai/workflows/.github/workflows/fleet-contract.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + uses: dinglebear-ai/workflows/.github/workflows/fleet-contract.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d with: profile: node - implementation-ref: 542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + implementation-ref: 66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d policy: - uses: dinglebear-ai/workflows/.github/workflows/fast-ops.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + uses: dinglebear-ai/workflows/.github/workflows/fast-ops.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d with: shell-globs: "ops/*.sh" policy-command: >- @@ -55,7 +55,7 @@ jobs: scan-args: --lockfile=pnpm-lock.yaml web: - uses: dinglebear-ai/workflows/.github/workflows/fast-pnpm.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + uses: dinglebear-ai/workflows/.github/workflows/fast-pnpm.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d with: node-version: "24" pnpm-version: "10.33.2" diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 20db4764..01c13765 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -14,7 +14,7 @@ jobs: web: permissions: contents: read - uses: dinglebear-ai/workflows/.github/workflows/hosted-web-release.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + uses: dinglebear-ai/workflows/.github/workflows/hosted-web-release.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d with: checkout-ref: ${{ github.event.release.tag_name }} node-version: "24" @@ -38,7 +38,7 @@ jobs: android: permissions: contents: read - uses: dinglebear-ai/workflows/.github/workflows/hosted-android-release.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + uses: dinglebear-ai/workflows/.github/workflows/hosted-android-release.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d with: checkout-ref: ${{ github.event.release.tag_name }} java-version: "21" @@ -63,7 +63,7 @@ jobs: packages: write attestations: write id-token: write - uses: dinglebear-ai/workflows/.github/workflows/hosted-container-release.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + uses: dinglebear-ai/workflows/.github/workflows/hosted-container-release.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d with: checkout-ref: ${{ github.event.release.tag_name }} image: ghcr.io/${{ github.repository }} diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 468b5806..2d40263e 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -15,6 +15,6 @@ concurrency: jobs: release: - uses: dinglebear-ai/workflows/.github/workflows/release-please.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + uses: dinglebear-ai/workflows/.github/workflows/release-please.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d secrets: RELEASE_PLEASE_TOKEN: ${{ secrets.RELEASE_PLEASE_TOKEN }} diff --git a/.github/workflows/synthetics.yml b/.github/workflows/synthetics.yml index 5797b821..44daf279 100644 --- a/.github/workflows/synthetics.yml +++ b/.github/workflows/synthetics.yml @@ -14,7 +14,7 @@ concurrency: jobs: public-path: - uses: dinglebear-ai/workflows/.github/workflows/synthetic-check.yml@542ea7b7e5ca2d4e21f3277bfcf158584fee90ec + uses: dinglebear-ai/workflows/.github/workflows/synthetic-check.yml@66e64b9f31de7ac1f9aa8c9f87ede9bbec5eae1d with: command: >- AURORA_PUBLIC_URL="${{ vars.AURORA_PUBLIC_URL || 'https://aurora.tootie.tv' }}"