Skip to content

chore(deps): update rust crate jsonschema (0.49.9 → 0.50.0) #1011

chore(deps): update rust crate jsonschema (0.49.9 → 0.50.0)

chore(deps): update rust crate jsonschema (0.49.9 → 0.50.0) #1011

Workflow file for this run

name: Docs
on:
push:
# See the matching note on ci.yml's trigger: Renovate's automerge branches
# never become pull requests, so without `renovate/**` here a dependency
# bump could break the docs build and still fast-forward onto main.
branches: [main, "renovate/**"]
pull_request:
workflow_dispatch:
# Serialize Pages deploys (matches the official GitHub Pages flow) and never
# cancel an in-flight one — a half-deployed site is worse than a stale one.
# The deploying ref (main) keeps the single shared `pages` group: two deploys
# racing for the same environment is exactly what this prevents. Refs that only
# ever build — pull requests and Renovate branches — get a per-ref group
# instead, because sharing `pages` with `cancel-in-progress: false` would make
# a dozen Renovate branches queue single-file behind each other and stall the
# automerge gate for hours.
concurrency:
group: ${{ github.ref == 'refs/heads/main' && 'pages' || format('pages-{0}', github.ref) }}
cancel-in-progress: false
# Least privilege at the top; the publish job widens it for itself only.
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
RUST_BACKTRACE: 1
jobs:
build:
name: build docs site
runs-on: ubuntu-24.04
# The build is seconds of mkdocs plus a cached `cargo doc`; anything near
# this is a hang, not slowness.
timeout-minutes: 15
permissions:
contents: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 # pin to SHA
with:
persist-credentials: false
- uses: jdx/mise-action@3c2e0cf82a5b2e5249f0d3635a4d83d0ae861518 # v4.2.5
with:
install_args: rust uv
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 # pin to SHA
with:
key: docs
# Only needed for deployment (it configures the base path); skip anywhere
# that does not deploy.
- name: Configure Pages
if: github.ref == 'refs/heads/main'
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 # pin to SHA
# `mise run docs` is the same command a developer runs, so a green PR here
# means the site really does build on their machine too. --strict turns a
# broken internal link, a nav entry naming a missing page, or a `--8<--`
# include pointing at a deleted example into a failure.
- name: Build docs site
run: mise run docs
- name: Upload artifact
if: github.ref == 'refs/heads/main'
# MkDocs builds into site/, with rustdoc nested under site/rustdoc/ and
# the CNAME that pins docs.domarinn.com written alongside.
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 # pin to SHA
with:
path: ./site
publish:
name: publish to GitHub Pages
# Everything that is not main builds for breakage detection but must never
# deploy — a fork PR would otherwise publish arbitrary content to the
# production domain.
#
# This is an allow-list (`ref == main`) rather than the deny-list it used
# to be (`event_name != 'pull_request'`) on purpose. The deny-list was only
# ever safe because the push trigger was restricted to main; adding
# `renovate/**` to that trigger would have silently turned every Renovate
# branch into a production Pages deploy. Keyed on the ref, the guard cannot
# be widened by a change to the trigger list.
if: github.ref == 'refs/heads/main'
needs: [build]
runs-on: ubuntu-24.04
timeout-minutes: 10
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
permissions:
pages: write
id-token: write
steps:
- name: Publish to GitHub Pages
id: deployment
uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0 # pin to SHA