Skip to content

Commit 85bb250

Browse files
committed
Merge origin/main (#1008) into arch-fix/sec-credentials
engine.rs imports: keep this branch's removal of url_host from the guidance import list and add #1008's NPM_REPLACE_REGISTRY_HOST_CODE. Co-Authored-By: Claude <noreply@anthropic.com>
2 parents c387851 + f3c6313 commit 85bb250

432 files changed

Lines changed: 31658 additions & 12588 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/actions/upload-artifact/action.yml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,9 @@ inputs:
1616
include-hidden-files:
1717
description: Include hidden files in the artifact
1818
default: 'false'
19+
compression-level:
20+
description: ZIP compression level (0 for files that are already compressed)
21+
default: '6'
1922
outputs:
2023
artifact-id:
2124
description: ID of the uploaded artifact
@@ -47,6 +50,7 @@ runs:
4750
if-no-files-found: ${{ inputs.if-no-files-found }}
4851
retention-days: ${{ inputs.retention-days }}
4952
include-hidden-files: ${{ inputs.include-hidden-files }}
53+
compression-level: ${{ inputs.compression-level }}
5054
overwrite: true
5155

5256
- name: Wait before retrying
@@ -65,6 +69,7 @@ runs:
6569
if-no-files-found: ${{ inputs.if-no-files-found }}
6670
retention-days: ${{ inputs.retention-days }}
6771
include-hidden-files: ${{ inputs.include-hidden-files }}
72+
compression-level: ${{ inputs.compression-level }}
6873
overwrite: true
6974

7075
- name: Wait before the final attempt
@@ -84,4 +89,5 @@ runs:
8489
if-no-files-found: ${{ inputs.if-no-files-found }}
8590
retention-days: ${{ inputs.retention-days }}
8691
include-hidden-files: ${{ inputs.include-hidden-files }}
92+
compression-level: ${{ inputs.compression-level }}
8793
overwrite: true

‎.github/workflows/bun-compatibility.yml‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -130,11 +130,11 @@ jobs:
130130

131131
- name: Cache cargo
132132
# save-if keeps writes on main so open PRs do not churn the repo's
133-
# 10 GiB cache budget; rust-cache's automatic key already includes
134-
# the runner OS, so one logical key serves all three builds.
133+
# 10 GiB cache budget. Share dependency artifacts with the other
134+
# debug=0 E2E builders on the same runner image.
135135
uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
136136
with:
137-
key: bun-native
137+
shared-key: e2e-${{ matrix.os }}
138138
save-if: ${{ github.ref == 'refs/heads/main' }}
139139

140140
- name: Build CLI
@@ -390,7 +390,7 @@ jobs:
390390
uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
391391
with:
392392
# Keep binaries linked against different glibc versions separate.
393-
key: bun-native-binary-${{ matrix.os }}
393+
shared-key: e2e-${{ matrix.os }}
394394
save-if: ${{ github.ref == 'refs/heads/main' }}
395395

396396
- name: Setup Python

‎.github/workflows/ci.yml‎

Lines changed: 240 additions & 92 deletions
Large diffs are not rendered by default.

‎.github/workflows/composer-compatibility.yml‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -110,7 +110,7 @@ jobs:
110110
- run: rustup show
111111
- uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
112112
with:
113-
key: composer-compat
113+
shared-key: dev-${{ matrix.os }}
114114
save-if: ${{ github.ref == 'refs/heads/main' }}
115115
- uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
116116
with:
@@ -181,7 +181,10 @@ jobs:
181181
include:
182182
- {os: macos-latest, composer: '1.10.28', php: '8.1', sha256: 0915af36eb01e3f0e16cd309adff7051832b9ef014e38371756804b20425cd5a}
183183
- {os: macos-latest, composer: '2.2.30', php: '8.3', sha256: 8c2b4478b64f8f7cdf1574838fdb0033b29049ca821dad452db7a3dcfcdbffc2}
184-
- {os: macos-latest, composer: '2.10.3', php: '8.5', sha256: 7a2d379d5b8ffdaa028580ef26494c36d2feef4b178d3dd1473a4dbc5e17c8d6}
184+
# PHP 8.4 on macOS: setup-php 2.37.2 cannot install 8.5 from Homebrew
185+
# since PHP 8.6 shipped (every run from 2026-10-07 23:51Z failed in
186+
# "Setup PHP"). Ubuntu and Windows keep the 2.10.3 / 8.5 cell.
187+
- {os: macos-latest, composer: '2.10.3', php: '8.4', sha256: 7a2d379d5b8ffdaa028580ef26494c36d2feef4b178d3dd1473a4dbc5e17c8d6}
185188
runs-on: ${{ matrix.os }}
186189
timeout-minutes: 60
187190
steps: *native-steps

‎.github/workflows/go-compatibility.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ jobs:
5555
- run: rustup show
5656
- uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
5757
with:
58-
key: go-compat
58+
shared-key: dev-${{ matrix.os }}
5959
save-if: ${{ github.ref == 'refs/heads/main' }}
6060
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
6161
with:

‎.github/workflows/gradle-compatibility.yml‎

Lines changed: 12 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -21,8 +21,8 @@ name: Gradle patch compatibility
2121
#
2222
# 9.8.0 is the current release on services.gradle.org (re-checked
2323
# 2026-10-02; bump it here and in ci.yml together when a newer 9.x ships).
24-
# 7.6.6 is the last 7.x. Every distribution is sha256-checked against
25-
# services.gradle.org before use.
24+
# 7.6.6 is the last 7.x. scripts/install-gradle.sh pins every
25+
# distribution's sha256; add the new version's digest there too.
2626
#
2727
# Each mode runs its suites' `#[ignore]` tests by name prefix (the contract
2828
# scripts/ci-e2e-bundle.py --check enforces): agent = e2e_gradle_discovery_build
@@ -44,6 +44,7 @@ on:
4444
paths:
4545
- '.github/workflows/gradle-compatibility.yml'
4646
- 'scripts/ci-e2e-bundle.py'
47+
- 'scripts/install-gradle.sh'
4748
- 'Cargo.lock'
4849
- 'Cargo.toml'
4950
- 'crates/*/Cargo.toml'
@@ -125,7 +126,7 @@ jobs:
125126
- name: Cache cargo
126127
uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
127128
with:
128-
key: gradle-compat
129+
shared-key: e2e-${{ matrix.os }}
129130
save-if: ${{ github.ref == 'refs/heads/main' }}
130131

131132
- name: Check the Gradle test-name prefixes
@@ -256,9 +257,13 @@ jobs:
256257
# TLS handshake with CRYPT_E_REVOCATION_OFFLINE whenever the CA's
257258
# revocation server is unreachable. A revoked certificate still fails;
258259
# the body is checked against a digest right after. A no-op elsewhere.
259-
url="https://archive.apache.org/dist/maven/maven-3/${MAVEN_VERSION}/binaries/apache-maven-${MAVEN_VERSION}-bin.tar.gz"
260+
# Tarball from Maven Central's CDN, digest from the Apache archive,
261+
# which throttles the tarball itself to minutes (ci.yml's copy).
262+
file="apache-maven-${MAVEN_VERSION}-bin.tar.gz"
263+
url="https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/${MAVEN_VERSION}/${file}"
264+
sha_url="https://archive.apache.org/dist/maven/maven-3/${MAVEN_VERSION}/binaries/${file}.sha512"
260265
curl -fsSL --retry 5 --retry-all-errors --ssl-revoke-best-effort "$url" -o "$RUNNER_TEMP/maven.tgz"
261-
curl -fsSL --retry 5 --retry-all-errors --ssl-revoke-best-effort "$url.sha512" -o "$RUNNER_TEMP/maven.sha512"
266+
curl -fsSL --retry 5 --retry-all-errors --ssl-revoke-best-effort "$sha_url" -o "$RUNNER_TEMP/maven.sha512"
262267
python -c 'import hashlib, pathlib, os; p=pathlib.Path(os.environ["RUNNER_TEMP"]); assert hashlib.sha512((p/"maven.tgz").read_bytes()).hexdigest() == (p/"maven.sha512").read_text().split()[0]'
263268
python -m tarfile -e "$RUNNER_TEMP/maven.tgz" "$RUNNER_TEMP"
264269
launcher="$RUNNER_TEMP/apache-maven-${MAVEN_VERSION}/bin/mvn"
@@ -273,16 +278,8 @@ jobs:
273278
shell: bash
274279
env:
275280
GRADLE_VERSION: ${{ matrix.gradle }}
276-
run: |
277-
# Download flags: see the Maven step above.
278-
url="https://services.gradle.org/distributions/gradle-${GRADLE_VERSION}-bin.zip"
279-
curl -fsSL --retry 5 --retry-all-errors --ssl-revoke-best-effort "$url" -o "$RUNNER_TEMP/gradle.zip"
280-
curl -fsSL --retry 5 --retry-all-errors --ssl-revoke-best-effort "$url.sha256" -o "$RUNNER_TEMP/gradle.sha256"
281-
python -c 'import hashlib, pathlib, os; p=pathlib.Path(os.environ["RUNNER_TEMP"]); assert hashlib.sha256((p/"gradle.zip").read_bytes()).hexdigest() == (p/"gradle.sha256").read_text().strip()'
282-
unzip -q "$RUNNER_TEMP/gradle.zip" -d "$RUNNER_TEMP"
283-
launcher="$RUNNER_TEMP/gradle-${GRADLE_VERSION}/bin/gradle"
284-
if [ "$RUNNER_OS" = Windows ]; then launcher="${launcher}.bat"; fi
285-
echo "SOCKET_PATCH_GRADLE_E2E_GRADLE=$launcher" >> "$GITHUB_ENV"
281+
# Pinned digest, GitHub-release origin: see the script.
282+
run: scripts/install-gradle.sh "$GRADLE_VERSION" "$RUNNER_TEMP" >> "$GITHUB_ENV"
286283

287284
- name: Run the ${{ matrix.mode }} suites
288285
shell: bash
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
name: Merge queue fail-fast
2+
3+
# Cancels a merge-queue entry's CI run the moment one of its jobs fails, so
4+
# `ci-ok` (if: always()) reports failure in seconds instead of after the
5+
# slowest e2e leg, and the queue evicts the entry and rebuilds the ones
6+
# behind it ~40 minutes sooner. See scripts/merge-queue-fail-fast.py.
7+
# Not a required check; it never fails.
8+
9+
on:
10+
merge_group:
11+
types: [checks_requested]
12+
13+
permissions: {}
14+
15+
jobs:
16+
watch:
17+
runs-on: ubuntu-latest
18+
timeout-minutes: 110
19+
permissions:
20+
actions: write
21+
contents: read
22+
steps:
23+
- name: Checkout
24+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
25+
# Run the canceller as it is on the base branch, never the queued
26+
# PRs' copy: this job holds an actions:write token, so executing
27+
# merge-group-head bytes would hand that token to any queued PR.
28+
with:
29+
ref: ${{ github.event.merge_group.base_sha }}
30+
persist-credentials: false
31+
sparse-checkout: scripts/merge-queue-fail-fast.py
32+
sparse-checkout-cone-mode: false
33+
34+
- name: Cancel the CI run on its first failed job
35+
env:
36+
GH_TOKEN: ${{ github.token }}
37+
HEAD_SHA: ${{ github.event.merge_group.head_sha }}
38+
# Until this workflow lands, the base branch has no canceller to run.
39+
run: |
40+
if [ ! -f scripts/merge-queue-fail-fast.py ]; then
41+
echo "scripts/merge-queue-fail-fast.py is not on the base branch yet; nothing to watch."
42+
exit 0
43+
fi
44+
python3 -B scripts/merge-queue-fail-fast.py
Lines changed: 55 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,55 @@
1+
name: Merge queue janitor
2+
3+
# Cancels merge-group runs the queue has orphaned. Each queue entry runs CI on
4+
# its own `gh-readonly-queue/main/pr-<n>-<base sha>` ref, so ci.yml's
5+
# concurrency group never lets a newer run cancel an older one. When an entry
6+
# ahead fails or is removed, the queue deletes the refs of every entry behind
7+
# it and rebuilds them on new refs, but the runs on the deleted refs keep going
8+
# (each one is a full ~200-job CI run, macOS legs included). A run whose ref no
9+
# longer exists can never merge, so it is cancelled here. Every rebuild creates
10+
# a new merge group, which triggers this sweep.
11+
#
12+
# Not a required check, and it never fails the merge group: a sweep error is
13+
# only a warning.
14+
15+
on:
16+
merge_group:
17+
types: [checks_requested]
18+
workflow_dispatch:
19+
20+
permissions: {}
21+
22+
concurrency:
23+
group: merge-queue-janitor
24+
cancel-in-progress: false
25+
26+
jobs:
27+
cancel-orphaned-runs:
28+
runs-on: ubuntu-latest
29+
timeout-minutes: 5
30+
permissions:
31+
actions: write
32+
contents: read
33+
steps:
34+
- name: Cancel merge-group runs whose queue ref is gone
35+
env:
36+
GH_TOKEN: ${{ github.token }}
37+
REPO: ${{ github.repository }}
38+
run: |
39+
set -uo pipefail
40+
for status in queued in_progress; do
41+
gh api --paginate "repos/$REPO/actions/runs?event=merge_group&status=$status&per_page=100" \
42+
-q '.workflow_runs[] | "\(.id) \(.head_branch)"' || echo "::warning::could not list $status runs"
43+
done | sort -u | while read -r id branch; do
44+
case "$branch" in gh-readonly-queue/*) ;; *) continue ;; esac
45+
# Only a definite 404 means the entry is gone; any other lookup
46+
# error (rate limit, 5xx) leaves the run alone.
47+
if err=$(gh api "repos/$REPO/git/ref/heads/$branch" --silent 2>&1); then
48+
continue
49+
fi
50+
case "$err" in *"HTTP 404"*) ;; *) echo "::warning::ref lookup for $branch failed: $err"; continue ;; esac
51+
echo "Cancelling run $id: $branch is no longer in the queue"
52+
gh api -X POST "repos/$REPO/actions/runs/$id/cancel" --silent \
53+
|| echo "::warning::could not cancel run $id"
54+
done
55+
exit 0

‎.github/workflows/pdm-compatibility.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ jobs:
7878
persist-credentials: false
7979
- uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
8080
with:
81-
key: pdm-compat
81+
shared-key: dev-${{ matrix.os }}
8282
save-if: ${{ github.ref == 'refs/heads/main' }}
8383
- name: Compile the CLI and the capstone once
8484
run: |

‎.github/workflows/pipenv-compatibility.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ jobs:
6868
- name: Cache cargo
6969
uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
7070
with:
71-
key: pipenv-compat
71+
shared-key: dev-${{ matrix.os }}
7272
save-if: ${{ github.ref == 'refs/heads/main' }}
7373
- name: Install uv
7474
uses: astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6.8.0

0 commit comments

Comments
 (0)