-
Notifications
You must be signed in to change notification settings - Fork 0
25 lines (23 loc) · 1.19 KB
/
Copy pathci.yml
File metadata and controls
25 lines (23 loc) · 1.19 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
name: CI
on:
push:
pull_request:
branches: [main]
jobs:
check:
# Pinned to a specific runner image, not `ubuntu-latest`, so a GitHub
# `-latest` migration can't silently change the build environment. Renovate
# (github-actions manager, github-runners datasource) bumps this via the
# same age-gated PRs as the action SHAs; it can't manage `-latest` itself.
runs-on: ubuntu-24.04
steps:
# Actions pinned to commit-SHA digests, not mutable tags/branches, to
# close the supply-chain hole a force-pushed tag/branch would open. The
# trailing comment tracks the human-readable version; Renovate
# (.github/renovate.json5) bumps the SHAs so the pins don't rot.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23
# All gate tooling (bun + uv) comes from the flake's lean .#ci shell, so
# the Python gate (//#test:hermes) resolves uv the same way locally and
# in CI. No setup-bun: bun is in the shell too.
- run: nix develop .#ci --command bash -euo pipefail -c 'bun install --frozen-lockfile && bun run check'