Skip to content

Verify the upstream signature on every run and add zizmor and cargo-deny #22

Verify the upstream signature on every run and add zizmor and cargo-deny

Verify the upstream signature on every run and add zizmor and cargo-deny #22

Workflow file for this run

---
name: CI
"on":
push:
branches: [main]
pull_request:
schedule:
# Re-proves the vendored bytes against the upstream release and the build on current runners.
- cron: "41 6 * * 2"
# The release workflow runs this whole file on the tagged commit before publishing.
workflow_call:
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
env:
CARGO_TERM_COLOR: always
jobs:
test:
name: Test ${{ matrix.toolchain }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
toolchain: [stable, "1.81"]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: ${{ matrix.toolchain }}
- run: cargo test --all-targets
- run: cargo test --doc
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
components: rustfmt, clippy
- run: cargo fmt --check
- run: cargo clippy --all-targets -- -D warnings
- run: cargo fmt --manifest-path smoke/Cargo.toml --check
- run: cargo clippy --manifest-path smoke/Cargo.toml --all-targets -- -D warnings
- run: cargo fmt --manifest-path wasm/Cargo.toml --check
- run: cargo doc --no-deps
env:
RUSTDOCFLAGS: -D warnings
scripts:
name: Scripts and workflows
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- run: shellcheck -x upgrade.sh bump.sh sigstore.sh
- name: actionlint
run: |
bash <(curl -sSfL https://raw.githubusercontent.com/rhysd/actionlint/914e7df21a07ef503a81201c76d2b11c789d3fca/scripts/download-actionlint.bash) 1.7.12
./actionlint -color
- uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19
with:
tool: zizmor@1.30.1
# The token enables the online audits, which catch impostor commits and known-vulnerable actions.
- run: zizmor .
env:
GH_TOKEN: ${{ github.token }}
deny:
name: Dependencies of the test crates pass cargo-deny
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
- uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19
with:
tool: cargo-deny@0.20.2
- run: cargo deny --manifest-path smoke/Cargo.toml check
- run: cargo deny --manifest-path wasm/Cargo.toml check
compile:
name: Compile the packaged amalgamation on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
# The consumer runs against the unpacked .crate, which holds only what crates.io would serve.
- name: Package and unpack
shell: bash
run: |
cargo package
crate=$(echo target/package/sqlite3mc-src-*.crate)
dir=$(basename "$crate" .crate)
tar -xzf "$crate" -C target/package
cp -r smoke "target/package/$dir/smoke"
echo "SMOKE_MANIFEST=target/package/$dir/smoke/Cargo.toml" >> "$GITHUB_ENV"
- run: cargo run --manifest-path "$SMOKE_MANIFEST"
shell: bash
wasm:
name: sqlite-wasm-rs builds the packaged amalgamation for Wasm
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
targets: wasm32-unknown-unknown
components: clippy
- uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19
with:
tool: wasm-pack
# A C library function the released sqlite-wasm-rs does not provide fails this link.
- name: Package and unpack
run: |
set -euo pipefail
cargo package
crate=$(echo target/package/sqlite3mc-src-*.crate)
tar -xzf "$crate" -C target/package
echo "SQLITE_WASM_RS_SOURCE_DIR=$PWD/target/package/$(basename "$crate" .crate)/sqlite3mc" >> "$GITHUB_ENV"
- run: wasm-pack test --node --release
working-directory: wasm
# sqlite-wasm-rs vendors the same release, so only its build log shows which copy it compiled.
- run: grep -rqsF "rerun-if-changed=$SQLITE_WASM_RS_SOURCE_DIR" wasm/target/wasm32-unknown-unknown/release/build
- run: cargo clippy --manifest-path wasm/Cargo.toml --target wasm32-unknown-unknown --all-targets -- -D warnings
release-bytes:
name: Vendored files match the release
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- run: ./upgrade.sh
- run: git diff --exit-code