Repository navigation
Fix uv project with no env falling back to system Python (#964) #1230
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: pnpm hosted compatibility | |
| on: | |
| # PRs: any crate source, but only the test files these capstones | |
| # compile (a later `!` pattern excludes, a later plain one re-includes). | |
| # Main pushes stay unfiltered. | |
| pull_request: | |
| paths: | |
| - '.github/actions/upload-artifact/**' | |
| - 'Cargo.lock' | |
| - 'Cargo.toml' | |
| - 'rust-toolchain.toml' | |
| - '.cargo/config.toml' | |
| - '.github/workflows/pnpm-compatibility.yml' | |
| - 'crates/**' | |
| - '!crates/**/*.md' | |
| - '!crates/socket-patch-node/**' | |
| - '!crates/socket-patch-core/tests/**' | |
| - '!crates/socket-patch-cli/tests/**' | |
| - 'crates/socket-patch-cli/tests/vex_e2e_common/**' | |
| - 'crates/socket-patch-cli/tests/e2e_redirect_pnpm_build.rs' | |
| - 'crates/socket-patch-cli/tests/e2e_vendor_pnpm_build.rs' | |
| - 'crates/socket-patch-cli/tests/common/cache_env.rs' | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| # A newer push to the same PR supersedes the older run. Every other event | |
| # gets its own group (run_id), so no main push is cancelled, even while | |
| # pending behind another. | |
| concurrency: | |
| group: pnpm-compat-${{ github.event.pull_request.number || github.run_id }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - name: Compile CLI and pnpm integration tests once | |
| run: | | |
| cargo test --locked -p socket-patch-cli --test e2e_redirect_pnpm_build --test e2e_vendor_pnpm_build --no-run --message-format=json > target-build.json | |
| python3 - <<'PY' | |
| import json, pathlib, shutil | |
| dest = pathlib.Path('target/pnpm-e2e') | |
| dest.mkdir(parents=True, exist_ok=True) | |
| shutil.copy2('target/debug/socket-patch', dest / 'socket-patch') | |
| names = {'e2e_redirect_pnpm_build': 'pnpm-e2e', 'e2e_vendor_pnpm_build': 'pnpm-vendor-e2e'} | |
| for line in pathlib.Path('target-build.json').read_text().splitlines(): | |
| item = json.loads(line) | |
| name = item.get('target', {}).get('name') | |
| if name in names and item.get('executable'): | |
| shutil.copy2(item['executable'], dest / names[name]) | |
| for n in names.values(): | |
| assert (dest / n).is_file(), n | |
| PY | |
| - uses: ./.github/actions/upload-artifact | |
| with: | |
| name: pnpm-e2e | |
| path: target/pnpm-e2e/ | |
| if-no-files-found: error | |
| retention-days: 7 | |
| install-proof: | |
| # One job per Node runtime; each walks its pnpm versions in turn. A leg | |
| # does ~20 s of work, so 25 single-version jobs spent most of their time | |
| # (and runner slots) on setup, and any one leg left waiting for a runner | |
| # failed the whole run. Every version still runs; a failure names it. | |
| name: install-proof (node ${{ matrix.node }}) | |
| needs: build | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| # 1.0.0 must explicitly refuse its non-durable shrinkwrap format. | |
| - node: '10.24.1' | |
| pnpm: 1.0.0 1.43.1 2.0.0 2.25.7 3.0.0 3.8.1 | |
| - node: '16.20.2' | |
| pnpm: 4.0.0 4.14.4 5.0.0 5.18.11 6.0.0 6.35.1 7.0.0 7.33.7 8.0.0 8.15.9 | |
| - node: '24.11.1' | |
| pnpm: 9.0.0 9.15.9 10.0.0 10.33.0 10.34.5 11.0.0 11.27.0 12.0.0 12.4.2 | |
| steps: | |
| - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 | |
| with: | |
| pattern: pnpm-e2e* | |
| merge-multiple: true | |
| path: bin | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 | |
| with: | |
| node-version: '24.11.1' | |
| - name: Install the pinned package managers | |
| env: | |
| PNPM_TEST_VERSIONS: ${{ matrix.pnpm }} | |
| run: | | |
| for v in $PNPM_TEST_VERSIONS; do | |
| npm install --prefix "$RUNNER_TEMP/pnpm-$v" --no-audit --no-fund "pnpm@$v" | |
| done | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 | |
| with: | |
| node-version: ${{ matrix.node }} | |
| # Per version: installation, verified VEX, rollback and integrity | |
| # rejection, then the vendored lifecycle and manifest-less VEX (pnpm | |
| # >= 9: full vendored capstone; 7-8: the legacy lifecycle; 1-6: | |
| # vendoring refused, nothing attested). Each version gets its own | |
| # TMPDIR, so the suites' shared cache sandbox (cache_env::cache_root) | |
| # and fixtures start as empty as on a fresh runner. | |
| - name: Require every pinned pnpm to install, verify, roll back and vendor | |
| env: | |
| PNPM_TEST_VERSIONS: ${{ matrix.pnpm }} | |
| SOCKET_PATCH_PNPM_E2E_REQUIRED: '1' | |
| SOCKET_NO_CONFIG: '1' | |
| SOCKET_NO_UPDATE_CHECK: '1' | |
| run: | | |
| chmod +x bin/socket-patch bin/pnpm-e2e bin/pnpm-vendor-e2e | |
| export SOCKET_PATCH_PNPM_E2E_SOCKET_BIN="$PWD/bin/socket-patch" | |
| failed=() | |
| for v in $PNPM_TEST_VERSIONS; do | |
| echo "::group::pnpm $v" | |
| if ( | |
| export SOCKET_PATCH_PNPM_E2E_VERSION="$v" | |
| export SOCKET_PATCH_PNPM_E2E_BIN="$RUNNER_TEMP/pnpm-$v/node_modules/.bin/pnpm" | |
| export TMPDIR="$RUNNER_TEMP/tmp-$v" | |
| mkdir -p "$TMPDIR" && | |
| bin/pnpm-e2e pnpm_pinned_matrix --ignored --nocapture && | |
| bin/pnpm-vendor-e2e pnpm_pinned_matrix --ignored --nocapture | |
| ); then | |
| echo "::endgroup::" | |
| else | |
| echo "::endgroup::" | |
| echo "::error title=pnpm $v::pnpm $v install-proof failed (expand its log group)" | |
| failed+=("$v") | |
| fi | |
| done | |
| if [ "${#failed[@]}" -ne 0 ]; then | |
| echo "Failed pnpm versions: ${failed[*]}" | |
| exit 1 | |
| fi |