Merge pull request #11 from xinbetween/feature/threat-model #15
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Publishes docs/ to GitHub Pages. | |
| # | |
| # Pages can deploy a branch folder on its own, and did until now. That path runs a workflow GitHub generates | |
| # and we cannot edit, built on actions that are a major version behind — which is where the "Node.js 20 is | |
| # deprecated" warning on every push came from. Doing it here instead means the actions are ours to keep | |
| # current, and the site is only rebuilt when something it serves has changed. | |
| name: Pages | |
| on: | |
| push: | |
| branches: [main] | |
| paths: ["docs/**", ".github/workflows/pages.yml"] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| pages: write | |
| id-token: write | |
| # One deployment at a time, and a newer push wins — but never cancel one midway, because a half-finished | |
| # deployment is a half-updated site. | |
| concurrency: | |
| group: pages | |
| cancel-in-progress: false | |
| jobs: | |
| deploy: | |
| # Pinned rather than `ubuntu-latest`: that label moves to Ubuntu 26 in October 2026, and every run has | |
| # been carrying an annotation saying so. A named image means the move happens when we make it, with a | |
| # green run to prove it, rather than on a date somebody else chose. macOS is already pinned the same way. | |
| runs-on: ubuntu-24.04 | |
| environment: | |
| name: github-pages | |
| url: ${{ steps.deployment.outputs.page_url }} | |
| steps: | |
| - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0 | |
| - uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 | |
| # CI checks this on every pull request, but this workflow is the one that actually puts the site in front | |
| # of people, and a deploy is not something you can take back from a cache. Seconds of Python for the | |
| # guarantee that nothing broken is ever served. | |
| - name: Check the site before serving it | |
| run: python3 scripts/check_site.py --ci | |
| # docs/ is committed and CI already checks it matches a fresh build, so there is nothing to build here. | |
| - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 | |
| with: | |
| path: docs | |
| - id: deployment | |
| uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 |