Repository navigation
135 lines (125 loc) · 4.17 KB
/
Copy pathci.yml
File metadata and controls
135 lines (125 loc) · 4.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
name: CI
on:
pull_request:
push:
branches: [master, main]
permissions:
contents: read
jobs:
nightly-quality:
name: Nightly format and Clippy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@master
with:
toolchain: nightly
components: clippy,rustfmt
- uses: Swatinem/rust-cache@v2
with:
shared-key: nightly-quality
- run: cargo +nightly fmt --all -- --check
- run: cargo +nightly clippy --workspace --exclude code-system-graph-fuzz --all-targets --all-features --locked -- -D warnings
stable:
name: Stable build and tests
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- run: git diff --check
- uses: dtolnay/rust-toolchain@master
with:
toolchain: stable
- uses: Swatinem/rust-cache@v2
with:
shared-key: stable
- run: cargo +stable check --workspace --exclude code-system-graph-fuzz --all-targets --all-features --locked
- run: cargo +stable test --workspace --exclude code-system-graph-fuzz --all-targets --all-features --locked
- run: RUSTDOCFLAGS="-D warnings" cargo +stable doc --workspace --exclude code-system-graph-fuzz --all-features --no-deps --locked
native-platforms:
name: Native ${{ matrix.name }}
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
include:
- name: macOS x86_64
os: macos-15-intel
- name: macOS ARM64
os: macos-15
- name: Windows x86_64
os: windows-2025
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@master
with:
toolchain: stable
- uses: Swatinem/rust-cache@v2
with:
shared-key: native-${{ matrix.os }}
- run: cargo +stable build --workspace --exclude code-system-graph-fuzz --all-features --locked
- run: cargo +stable test --workspace --exclude code-system-graph-fuzz --all-targets --all-features --locked -- --test-threads=1
msrv:
name: Rust 1.96.0 MSRV
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@master
with:
toolchain: 1.96.0
- uses: Swatinem/rust-cache@v2
with:
shared-key: msrv
- run: cargo check --workspace --exclude code-system-graph-fuzz --all-targets --all-features --locked
policy:
name: Dependency policy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: EmbarkStudios/cargo-deny-action@v2
with:
command: check
- uses: dtolnay/rust-toolchain@master
with:
toolchain: stable
- uses: taiki-e/install-action@cargo-audit
- run: cargo audit --deny warnings
secrets:
name: Secret scanning
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0
- uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3.0.0
env:
# Automatic read-only job token; never replace with a PAT.
GITHUB_TOKEN: ${{ github.token }}
GITLEAKS_ENABLE_COMMENTS: "false"
linux-release:
name: Linux release smoke
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@master
with:
toolchain: stable
- uses: Swatinem/rust-cache@v2
- uses: anchore/sbom-action/download-syft@v0
- run: scripts/package-release.sh
- run: |
version="$(awk -F '"' '/^version = / { print $2; exit }' Cargo.toml)"
scripts/smoke-install.sh "dist/code-system-graph-x86_64-unknown-linux-gnu-v${version}"
release-workloads:
name: Linux release workloads
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@master
with:
toolchain: stable
- uses: Swatinem/rust-cache@v2
with:
shared-key: release-workloads
- run: cargo +stable test -p code-system-graph --test extraction_scale_e2e --release --locked -- --ignored --test-threads=1