Merge pull request #42 from lucatescari/fix/ls-gpg-users-gpg-program #82
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [dev, master] | |
| pull_request: | |
| schedule: | |
| # Weekly, so newly published advisories are caught without a push. | |
| - cron: "0 6 * * 1" | |
| env: | |
| CARGO_TERM_COLOR: always | |
| jobs: | |
| check: | |
| name: ${{ matrix.os }} | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, macos-latest, windows-latest] | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@stable | |
| with: | |
| components: rustfmt, clippy | |
| - name: Cache cargo registry & build | |
| uses: actions/cache@v6 | |
| with: | |
| path: | | |
| ~/.cargo/registry | |
| ~/.cargo/git | |
| target | |
| key: ${{ runner.os }}-cargo-${{ hashFiles('**/Cargo.lock') }} | |
| - name: Install git-crypt and GPG (Linux) | |
| if: runner.os == 'Linux' | |
| run: sudo apt-get update && sudo apt-get install -y git-crypt gnupg | |
| - name: Install git-crypt and GPG (macOS) | |
| if: runner.os == 'macOS' | |
| run: brew install git-crypt gnupg | |
| - name: Install GPG (Windows) | |
| if: runner.os == 'Windows' | |
| shell: pwsh | |
| run: | | |
| Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser -Force | |
| if (-not (Get-Command scoop -ErrorAction SilentlyContinue)) { | |
| Invoke-RestMethod -Uri https://get.scoop.sh | Invoke-Expression | |
| } | |
| scoop install gnupg | |
| gpg --version | |
| - name: Check formatting | |
| run: cargo fmt --check | |
| - name: Clippy | |
| run: cargo clippy --all-targets -- -D warnings | |
| - name: Unit tests | |
| run: cargo test --bin gitveil | |
| - name: Integration tests | |
| run: cargo test --test integration | |
| - name: GPG integration tests | |
| run: cargo test --test gpg_integration | |
| - name: Cross-compatibility tests | |
| run: cargo test --test cross_compat | |
| audit: | |
| name: cargo audit | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@stable | |
| - name: Cache cargo-audit binary | |
| id: cache-audit | |
| uses: actions/cache@v6 | |
| with: | |
| path: ~/.cargo/bin/cargo-audit | |
| key: ${{ runner.os }}-cargo-audit | |
| - name: Install cargo-audit | |
| if: steps.cache-audit.outputs.cache-hit != 'true' | |
| run: cargo install cargo-audit --locked | |
| - name: Audit dependencies | |
| # Fails the build on known vulnerabilities. RustSec informational | |
| # advisories (unsound / unmaintained) are reported as warnings only — | |
| # Dependabot does not surface those at all, so the log is the record. | |
| run: cargo audit |