-
Notifications
You must be signed in to change notification settings - Fork 0
75 lines (72 loc) · 3.21 KB
/
Copy pathci.yaml
File metadata and controls
75 lines (72 loc) · 3.21 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
name: CI
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
jobs:
baseline:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- uses: actions/setup-node@v7
with:
node-version: 22.14.0
- name: Check whitespace
run: git diff --check "$(git hash-object -t tree /dev/null)" HEAD
- name: Install validation dependencies
run: npm ci --ignore-scripts --no-audit
- name: Check generator syntax
run: node --check scripts/generate.mjs
- name: Test shared-source generation and drift rejection
run: npm test
- name: Verify committed generated content
run: npm run check
- name: Preserve published immutable machine resources
env:
MACHINE_BASE_REVISION: ${{ github.event.pull_request.base.sha || github.event.before }}
run: node scripts/check-machine-immutability.mjs
- name: Verify machine resource integrity and actual WASM behavior
run: npm run machine:check
- name: Read native conformance pins
id: native
run: |
node --input-type=module -e 'import fs from "node:fs"; const p=JSON.parse(fs.readFileSync("content/machine-resources-v1.json")); console.log(`compiler=${p.compilerRevision}\nspecification=${p.specificationRevision}`)' >> "$GITHUB_OUTPUT"
- uses: actions/checkout@v7
with:
repository: stack-sh/compiler
ref: ${{ steps.native.outputs.compiler }}
path: .stack-compiler
persist-credentials: false
- uses: actions/checkout@v7
with:
repository: stack-sh/specification
ref: ${{ steps.native.outputs.specification }}
path: .stack-specification
persist-credentials: false
- name: Verify native compiler IR and language intelligence conformance
env:
STACK_SPECIFICATION_DIR: ${{ github.workspace }}/.stack-specification
run: |
rustup toolchain install stable --profile minimal
cargo +stable test --manifest-path .stack-compiler/Cargo.toml --locked --features conformance --test conformance --test language_intelligence_conformance
- name: Run a resource consumer against local discovery and immutable upstream URLs
run: node examples/read-machine-resources.mjs --local
- name: Check published CLI freshness
run: npm run release:check
env:
GH_TOKEN: ${{ github.token }}
- name: Verify and exercise published CLI
env:
GH_TOKEN: ${{ github.token }}
run: |
version=$(node -p 'JSON.parse(require("fs").readFileSync("content/cli-release.json")).version')
archive="stack-v${version}-x86_64-unknown-linux-gnu.tar.gz"
mkdir "$RUNNER_TEMP/stack-release"
gh release download "v${version}" --repo stack-sh/cli --pattern "$archive" --dir "$RUNNER_TEMP/stack-release"
gh attestation verify "$RUNNER_TEMP/stack-release/$archive" --repo stack-sh/cli
tar -xzf "$RUNNER_TEMP/stack-release/$archive" -C "$RUNNER_TEMP/stack-release"
STACK_CLI_BIN="$RUNNER_TEMP/stack-release/stack-v${version}-x86_64-unknown-linux-gnu/stack" npm run smoke