Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
18 commits
Select commit Hold shift + click to select a range
892c750
ci: main keeps one generation of each cache, not every one it ever wrote
rgdevment Sep 23, 2026
7c463ae
fix: the sweep only touches what a newer key superseded, and the regi…
rgdevment Sep 23, 2026
606d002
fix: one description, one repository name, and a tag stops leaving ca…
rgdevment Sep 23, 2026
17f2430
perf: the suite runs once, and clippy runs where the cache is written
rgdevment Sep 23, 2026
45669d8
fix: the version job stops holding the signing keys, and four channel…
rgdevment Sep 23, 2026
7dc7af5
fix: the Store carries signed binaries, and the tap retires a channel…
rgdevment Sep 23, 2026
919b943
fix: a release without its MSIX stops instead of leaving the Store be…
rgdevment Sep 23, 2026
5ac9cd3
fix: the smaller edges the audits found, from the cask caveat to a gu…
rgdevment Sep 23, 2026
d10f235
fix: a tag on a commit CI never saw is not a release
rgdevment Sep 23, 2026
98697b3
fix: the listing in the repository stops claiming to be a release it …
rgdevment Sep 23, 2026
60fd49e
fix: a third tag no longer cancels the second one's release in silence
rgdevment Sep 23, 2026
f308e7f
fix: a tag with an empty signing secret is stopped, not shipped unsigned
rgdevment Sep 23, 2026
78d36cc
fix: a Store that never answered stops reading as «you are up to date»
rgdevment Sep 23, 2026
0f8c42e
feat: the installer stops carrying binaries nobody signed
rgdevment Sep 23, 2026
ce75829
fix: three guards that were switched off, and the mutants that stoppe…
rgdevment Sep 23, 2026
f636c83
test: the installer is opened and what it carries is read, not assumed
rgdevment Sep 23, 2026
296330a
fix: the wait for CI is wider than the time CI actually takes
rgdevment Sep 23, 2026
ad93d65
fix: the installer check looks for 7-Zip instead of assuming where it…
rgdevment Sep 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/actions/package/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,4 +43,5 @@ runs:
with:
name: cli-${{ inputs.name }}
path: dist/*
if-no-files-found: error
retention-days: 5
4 changes: 2 additions & 2 deletions .github/actions/prepare/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,11 +16,11 @@ inputs:
runs:
using: composite
steps:
- uses: dtolnay/rust-toolchain@stable
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
targets: ${{ inputs.targets }}

- uses: Swatinem/rust-cache@v2
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
key: ${{ inputs.cache-key }}
save-if: false
Expand Down
42 changes: 42 additions & 0 deletions .github/workflows/caches.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,13 +3,25 @@ name: Caches
on:
pull_request_target:
types: [closed]
workflow_run:
workflows: ["CI"]
types: [completed]
schedule:
- cron: "17 6 * * *"
workflow_dispatch:
inputs:
dry_run:
description: "List what would go, delete nothing."
type: boolean
default: true

permissions:
actions: write

jobs:
sweep:
name: a closed pull request takes its caches with it
if: github.event_name == 'pull_request_target'
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
Expand All @@ -19,3 +31,33 @@ jobs:
GH_REPO: ${{ github.repository }}
REF: refs/pull/${{ github.event.pull_request.number }}/merge
run: gh cache delete --all --ref "$REF" --succeed-on-no-caches

generations:
name: one generation of each cache, and nothing a tag left behind
# The branch filter on workflow_run reads the branch of the run that triggered it, and a
# fork's pull request can name its branch main. Only a push to this repository counts.
if: >-
github.event_name == 'workflow_dispatch' || github.event_name == 'schedule'
|| (github.event_name == 'workflow_run'
&& github.event.workflow_run.event == 'push'
&& github.event.workflow_run.head_branch == 'main'
&& github.event.workflow_run.head_repository.full_name == github.repository
&& github.event.workflow_run.conclusion != 'cancelled')
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
actions: write
contents: read
concurrency:
group: cache-generations
cancel-in-progress: false
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- name: What no build will ask for again
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GH_REPO: ${{ github.repository }}
DRY_RUN: ${{ github.event_name == 'workflow_dispatch' && inputs.dry_run }}
run: python3 scripts/generations.py
32 changes: 11 additions & 21 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,41 +27,31 @@ jobs:
os: [windows-latest, macos-latest]
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
components: clippy
- uses: Swatinem/rust-cache@v2
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
shared-key: workspace
save-if: ${{ github.ref == 'refs/heads/main' }}
- uses: ./.github/actions/sidecar
- uses: taiki-e/install-action@nextest
- if: runner.os == 'macOS'
run: cargo clippy --workspace --all-targets
- run: cargo nextest run --workspace --no-tests=pass
# Clippy runs where the cache is written, or the next job pays to rebuild what it needs.
- run: cargo clippy --workspace --all-targets
- run: cargo nextest run --workspace --no-tests=pass
env:
LC_ALL: es_ES.UTF-8
LANG: es_ES.UTF-8
- if: runner.os == 'Windows'
run: cargo test --doc --workspace

lint:
name: fmt + clippy
runs-on: windows-latest
timeout-minutes: 25
name: fmt
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
components: rustfmt, clippy
- uses: Swatinem/rust-cache@v2
with:
shared-key: workspace
save-if: false
- uses: ./.github/actions/sidecar
components: rustfmt
- run: cargo fmt --all --check
- run: cargo clippy --workspace --all-targets

window:
name: frontend
Expand Down Expand Up @@ -111,10 +101,10 @@ jobs:
steps:
- uses: actions/checkout@v7

- uses: dtolnay/rust-toolchain@stable
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
components: llvm-tools-preview
- uses: Swatinem/rust-cache@v2
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
save-if: ${{ github.ref == 'refs/heads/main' }}
- uses: taiki-e/install-action@cargo-llvm-cov
Expand Down
6 changes: 4 additions & 2 deletions .github/workflows/commits.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,13 +34,15 @@ jobs:
subject=$(git log -1 --format=%s "$sha" | sed 's/^[[:space:]]*//;s/[[:space:]]*$//')

if ! printf '%s' "$subject" | grep -qE "$pattern"; then
echo "::error::${sha:0:8} does not follow conventional commits: $subject"
echo "::error::${sha:0:8} does not follow conventional commits"
printf ' %s\n' "$subject"
failed=1
continue
fi

if [ "${#subject}" -gt 90 ]; then
echo "::error::${sha:0:8} subject is ${#subject} characters, keep it under 90: $subject"
echo "::error::${sha:0:8} subject is ${#subject} characters, keep it under 90"
printf ' %s\n' "$subject"
failed=1
fi
done < <(git rev-list --no-merges "$BASE".."$HEAD")
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/feed.yml
Original file line number Diff line number Diff line change
Expand Up @@ -123,7 +123,8 @@ jobs:
if [ -n "$ahead" ]; then
echo "the candidates' channel, announcing $ahead:"
takes candidate.json "$ahead"
elif curl -fsSL -o /dev/null "$feed/candidate.json" 2>/dev/null; then
elif curl -fsSL -H "Cache-Control: no-cache" -o /dev/null \
"$feed/candidate.json" 2>/dev/null; then
echo "::error::candidate.json is still being served and the feed announces no \
candidate. A copy that remembers one would be sent to a version nobody is \
publishing any more."
Expand Down
19 changes: 10 additions & 9 deletions .github/workflows/mutants-sweep.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,8 @@ jobs:
timeout-minutes: 120
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
shared-key: workspace
save-if: false
Expand Down Expand Up @@ -57,8 +57,8 @@ jobs:
timeout-minutes: 180
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
shared-key: workspace
save-if: false
Expand Down Expand Up @@ -96,8 +96,8 @@ jobs:
shard: [1, 2, 3, 4]
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
shared-key: workspace
save-if: false
Expand Down Expand Up @@ -135,8 +135,8 @@ jobs:
shard: [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16]
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
shared-key: workspace
save-if: false
Expand Down Expand Up @@ -247,13 +247,14 @@ jobs:
- name: The report where a survivor can be read one by one
env:
KEY: ${{ secrets.STRYKER_DASHBOARD_API_KEY }}
BRANCH: ${{ github.ref_name }}
run: |
if [ -z "$KEY" ]; then
echo "::warning::no dashboard key: the report goes no further than the artifact"
exit 0
fi
curl -sS --fail-with-body -X PUT \
"https://dashboard.stryker-mutator.io/api/reports/github.com/${{ github.repository }}/${{ github.ref_name }}" \
"https://dashboard.stryker-mutator.io/api/reports/github.com/$GITHUB_REPOSITORY/$BRANCH" \
-H 'Content-Type: application/json' \
-H "X-Api-Key: $KEY" \
-d @window.json
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/mutants.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,9 +38,9 @@ jobs:
git diff "$from" -- crates > branch.diff
if [ -s branch.diff ]; then echo "any=yes" >> "$GITHUB_OUTPUT"; fi

- uses: dtolnay/rust-toolchain@stable
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
if: steps.touched.outputs.any == 'yes'
- uses: Swatinem/rust-cache@v2
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
shared-key: workspace
save-if: false
Expand Down
Loading
Loading