Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 15 additions & 10 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,10 +21,10 @@ jobs:
id-token: write # needed for sigstore
container:
image: ${{ matrix.container }}
volumes: ${{ matrix.need_node20_vol && fromJSON('["/node20217:/node20217:rw,rshared", "/node20217:/__e/node20:ro,rshared"]') || fromJSON('[]') }}
env:
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: 'true'
ACTIONS_RUNNER_FORCE_ACTIONS_NODE_VERSION: node16
# JavaScript actions run on the runner's Node 24, which needs a newer
# glibc than CentOS 7's 2.17; those jobs mount a build of it for glibc
# 2.17 over the runner's (see the first step).
volumes: ${{ matrix.need_node24_vol && fromJSON('["/node24217:/node24217:rw,rshared", "/node24217:/__e/node24:ro,rshared"]') || fromJSON('[]') }}
strategy:
fail-fast: false
matrix:
Expand All @@ -36,7 +36,7 @@ jobs:
os: ubuntu-latest
container: aswf/ci-base:2021
vfx-cy: 2021
need_node20_vol: true
need_node24_vol: true
has_cmake_presets: false
buildtype: Release
# use old conan version for CentOS 7
Expand All @@ -54,7 +54,7 @@ jobs:
os: ubuntu-latest
container: aswf/ci-base:2022
vfx-cy: 2022
need_node20_vol: true
need_node24_vol: true
has_cmake_presets: false
buildtype: Release
# use old conan version for CentOS 7
Expand Down Expand Up @@ -224,11 +224,16 @@ jobs:
run:
shell: bash
steps:
- name: install nodejs20glibc2.17
if: matrix.need_node20_vol == true
- name: install nodejs24glibc2.17
if: matrix.need_node24_vol == true
env:
NODE_VERSION: v24.21.0
NODE_SHA256: d2643b829af01eee8b2163c7b42e1f4f7e0ab42ffeafa24e2230ce5b50779109
run: |
curl --silent https://unofficial-builds.nodejs.org/download/release/v20.18.1/node-v20.18.1-linux-x64-glibc-217.tar.xz | \
tar -xJ --strip-components 1 -C /node20217 -f -
NODE_TARBALL="node-$NODE_VERSION-linux-x64-glibc-217.tar.xz"
curl --silent --fail -o "/tmp/$NODE_TARBALL" "https://unofficial-builds.nodejs.org/download/release/$NODE_VERSION/$NODE_TARBALL"
echo "$NODE_SHA256 /tmp/$NODE_TARBALL" | sha256sum -c -
tar -xJ --strip-components 1 -C /node24217 -f "/tmp/$NODE_TARBALL"

- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
Expand Down
1 change: 1 addition & 0 deletions release-notes-next.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,4 +36,5 @@ This is version NEXT of the OpenFX API.
- Conan packaging: restructured the recipe to the standard Conan Center Index layout (headers under `include/`, libs and CMake module under `lib/`, licenses under `licenses/`) (issues #238, #246), and example-only dependencies (OpenGL, CImg, spdlog, OpenCL) are no longer imposed on consumers — they're gated behind a new `build_examples` option (#253).
- Added `SECURITY.md` and fixed stale repository URLs (#242).
- CI: hardened workflows (actions pinned to SHAs, untrusted inputs via env) (#235); updated Conan and pre-authorized future compiler versions so new Xcode/compiler releases don't break builds (#252); pinned the Windows CUDA job to VS2022.
- CI: the CentOS 7 jobs (VFX CY2021 and CY2022) run GitHub's JavaScript actions on a glibc 2.17 build of Node 24, since GitHub's runners no longer have Node 20.

Loading