Skip to content

Commit f570fab

Browse files
committed
Consolidate the workflows and ship prebuilt
artifact-scans.yml folds into ci.yml as a job of its own. A guard in repo-guards.rs had to learn to read every file under .github/workflows before it could see that a whole gate ran in the second file, which is the failure that guard exists to prevent, one file over. The paths-ignore filter is gone. It skipped every job on a push touching only markdown, which skipped cargo test --test unit and check-artifacts.sh, the two gates that read the markdown. The filter turned off precisely the checks for the files being changed. A build job produces Linux x86_64 and macOS arm64 tarballs and runs each binary on the platform it was built for, and a release job republishes them as a rolling "latest" on every green push to main. Cargo.lock is tracked and the build passes --locked, so a published binary is a function of the commit that names it. The fast lane gains a macOS leg for the same reason the build job runs what it produced: the tarball ships for a platform no test had run on. repo-guards.rs gains released_tarball_names_match_the_build_matrix, pinning the asset names in the build matrix, the release job and README to one list. The release job checks its own copy against the artifacts at run time; README's copy was checked by nothing, and a renamed target would have left it pointing at a download that 404s while every gate stayed green. ci_runs_every_test_target now reads the one-line "run:" form as its two siblings already did. It saw only the block form, so it reported test-integration as run by nobody once that step no longer needed a block.
1 parent b173753 commit f570fab

10 files changed

Lines changed: 2032 additions & 41 deletions

File tree

‎.github/dependabot.yml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
# ci.yml names actions by major version, so upstream patches arrive on their own
2+
# and only a major bump needs a commit. This is what opens that pull request,
3+
# rather than leaving it to somebody noticing that v7 became v8.
4+
version: 2
5+
updates:
6+
- package-ecosystem: github-actions
7+
directory: /
8+
schedule:
9+
interval: weekly
10+
11+
# Cargo.lock is tracked so the released binaries are a function of the commit
12+
# that produced them, which means a dependency fix now needs a commit here
13+
# rather than arriving on its own at the next build.
14+
- package-ecosystem: cargo
15+
directory: /
16+
schedule:
17+
interval: weekly

‎.github/workflows/ci.yml‎

Lines changed: 460 additions & 0 deletions
Large diffs are not rendered by default.

‎.gitignore‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,6 @@ _opam/
1919

2020
# Rust (for experiments)
2121
target/
22-
Cargo.lock
2322

2423
# Editor
2524
*~

0 commit comments

Comments
 (0)