Verify the upstream signature on every run and add zizmor and cargo-deny #22
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| --- | |
| name: CI | |
| "on": | |
| push: | |
| branches: [main] | |
| pull_request: | |
| schedule: | |
| # Re-proves the vendored bytes against the upstream release and the build on current runners. | |
| - cron: "41 6 * * 2" | |
| # The release workflow runs this whole file on the tagged commit before publishing. | |
| workflow_call: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.ref != 'refs/heads/main' }} | |
| env: | |
| CARGO_TERM_COLOR: always | |
| jobs: | |
| test: | |
| name: Test ${{ matrix.toolchain }} | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| toolchain: [stable, "1.81"] | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master | |
| with: | |
| toolchain: ${{ matrix.toolchain }} | |
| - run: cargo test --all-targets | |
| - run: cargo test --doc | |
| lint: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master | |
| with: | |
| toolchain: stable | |
| components: rustfmt, clippy | |
| - run: cargo fmt --check | |
| - run: cargo clippy --all-targets -- -D warnings | |
| - run: cargo fmt --manifest-path smoke/Cargo.toml --check | |
| - run: cargo clippy --manifest-path smoke/Cargo.toml --all-targets -- -D warnings | |
| - run: cargo fmt --manifest-path wasm/Cargo.toml --check | |
| - run: cargo doc --no-deps | |
| env: | |
| RUSTDOCFLAGS: -D warnings | |
| scripts: | |
| name: Scripts and workflows | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - run: shellcheck -x upgrade.sh bump.sh sigstore.sh | |
| - name: actionlint | |
| run: | | |
| bash <(curl -sSfL https://raw.githubusercontent.com/rhysd/actionlint/914e7df21a07ef503a81201c76d2b11c789d3fca/scripts/download-actionlint.bash) 1.7.12 | |
| ./actionlint -color | |
| - uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19 | |
| with: | |
| tool: zizmor@1.30.1 | |
| # The token enables the online audits, which catch impostor commits and known-vulnerable actions. | |
| - run: zizmor . | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| deny: | |
| name: Dependencies of the test crates pass cargo-deny | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master | |
| with: | |
| toolchain: stable | |
| - uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19 | |
| with: | |
| tool: cargo-deny@0.20.2 | |
| - run: cargo deny --manifest-path smoke/Cargo.toml check | |
| - run: cargo deny --manifest-path wasm/Cargo.toml check | |
| compile: | |
| name: Compile the packaged amalgamation on ${{ matrix.os }} | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, macos-latest, windows-latest] | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master | |
| with: | |
| toolchain: stable | |
| # The consumer runs against the unpacked .crate, which holds only what crates.io would serve. | |
| - name: Package and unpack | |
| shell: bash | |
| run: | | |
| cargo package | |
| crate=$(echo target/package/sqlite3mc-src-*.crate) | |
| dir=$(basename "$crate" .crate) | |
| tar -xzf "$crate" -C target/package | |
| cp -r smoke "target/package/$dir/smoke" | |
| echo "SMOKE_MANIFEST=target/package/$dir/smoke/Cargo.toml" >> "$GITHUB_ENV" | |
| - run: cargo run --manifest-path "$SMOKE_MANIFEST" | |
| shell: bash | |
| wasm: | |
| name: sqlite-wasm-rs builds the packaged amalgamation for Wasm | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master | |
| with: | |
| toolchain: stable | |
| targets: wasm32-unknown-unknown | |
| components: clippy | |
| - uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19 | |
| with: | |
| tool: wasm-pack | |
| # A C library function the released sqlite-wasm-rs does not provide fails this link. | |
| - name: Package and unpack | |
| run: | | |
| set -euo pipefail | |
| cargo package | |
| crate=$(echo target/package/sqlite3mc-src-*.crate) | |
| tar -xzf "$crate" -C target/package | |
| echo "SQLITE_WASM_RS_SOURCE_DIR=$PWD/target/package/$(basename "$crate" .crate)/sqlite3mc" >> "$GITHUB_ENV" | |
| - run: wasm-pack test --node --release | |
| working-directory: wasm | |
| # sqlite-wasm-rs vendors the same release, so only its build log shows which copy it compiled. | |
| - run: grep -rqsF "rerun-if-changed=$SQLITE_WASM_RS_SOURCE_DIR" wasm/target/wasm32-unknown-unknown/release/build | |
| - run: cargo clippy --manifest-path wasm/Cargo.toml --target wasm32-unknown-unknown --all-targets -- -D warnings | |
| release-bytes: | |
| name: Vendored files match the release | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2 | |
| - run: ./upgrade.sh | |
| - run: git diff --exit-code |