diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 3baecfb..46c1368 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -6,6 +6,8 @@ updates: separator: "-" schedule: interval: "weekly" + cooldown: + default-days: 7 groups: rust-dependencies: patterns: @@ -23,6 +25,8 @@ updates: directory: "/" schedule: interval: "weekly" + cooldown: + default-days: 7 groups: actions-dependencies: patterns: diff --git a/.github/pinact.yaml b/.github/pinact.yaml new file mode 100644 index 0000000..75ff053 --- /dev/null +++ b/.github/pinact.yaml @@ -0,0 +1,9 @@ +version: 3 +rules: + # Branch refs that must keep tracking their branch: there is no stable tag + # to pin to. lean-update's `dev` carries the fork's features, and the shared + # ci-workflows actions are consumed from `main`. + - ignore: true + conditions: + - expr: ActionName == "argumentcomputer/lean-update" + - expr: ActionName matches "^argumentcomputer/ci-workflows/" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3397d2e..6b3e177 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -17,15 +17,17 @@ jobs: test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 - - uses: actions-rust-lang/setup-rust-toolchain@v2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: actions-rust-lang/setup-rust-toolchain@ecabd13d1c56bd1345c230e542e9144811ad706f # v2.0.0 # Simpler to install Lean than to use lean-action for only this purpose. - name: Install Lean run: | - curl -sSf https://raw.githubusercontent.com/leanprover/elan/master/elan-init.sh | sh -s -- -y --default-toolchain $(cat lean-toolchain) - echo "$HOME/.elan/bin" >> $GITHUB_PATH + curl -sSf https://raw.githubusercontent.com/leanprover/elan/master/elan-init.sh | sh -s -- -y --default-toolchain "$(cat lean-toolchain)" + echo "$HOME/.elan/bin" >> "$GITHUB_PATH" - name: Check Rustfmt code style - uses: actions-rust-lang/rustfmt@v1 + uses: actions-rust-lang/rustfmt@4066006ec54a31931b9b1fddfd38f2fdf2d27143 # v1.1.2 - name: Check clippy warnings run: cargo clippy --workspace --all-targets --all-features - name: Check *everything* compiles @@ -34,7 +36,7 @@ jobs: run: cargo test --workspace --all-targets --all-features # Restore and then save .lake to the GitHub cache # Essentially the same as lean-action but without re-downloading the Lean toolchain - - uses: actions/cache@v6 + - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: ./.lake key: lake-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('lean-toolchain') }}-${{ hashFiles('lake-manifest.json') }}-${{ github.sha }} @@ -56,12 +58,14 @@ jobs: nix: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 - - uses: cachix/install-nix-action@v31 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 with: nix_path: nixpkgs=channel:nixos-unstable - github_access_token: ${{ secrets.GITHUB_TOKEN }} - - uses: cachix/cachix-action@v17 + github_access_token: ${{ github.token }} + - uses: cachix/cachix-action@38b082610b782e7e93e209c35fd730d399dee866 # v17 with: name: argumentcomputer authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} @@ -73,3 +77,14 @@ jobs: # Catch-all: near-free after the steps above; fails if a check is added # to the flake without a step here. - run: nix flake check --accept-flake-config + + lints: + name: Lint workflows + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + # actionlint, shellcheck over composite action scripts, pinact (actions + # must be SHA-pinned with a matching version comment) and zizmor + - uses: argumentcomputer/ci-workflows/.github/actions/lint-workflows@main diff --git a/.github/workflows/update.yml b/.github/workflows/update.yml index b84c49f..94a8b9d 100644 --- a/.github/workflows/update.yml +++ b/.github/workflows/update.yml @@ -14,11 +14,13 @@ jobs: update: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - - uses: cachix/install-nix-action@v31 + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 with: - github_access_token: ${{ secrets.GITHUB_TOKEN }} + github_access_token: ${{ github.token }} # `dev` carries pinned-tag updates and lean4-nix gating; `main` only # mirrors upstream and ignores these inputs. diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000..576392f --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,8 @@ +rules: + unpinned-uses: + config: + policies: + # Branch-tracking refs allowed by .github/pinact.yaml + "argumentcomputer/lean-update": ref-pin + "argumentcomputer/ci-workflows/*": ref-pin + "*": hash-pin