Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 6 additions & 7 deletions .github/pinact.yaml
Original file line number Diff line number Diff line change
@@ -1,8 +1,7 @@
# yaml-language-server: $schema=https://raw.githubusercontent.com/suzuki-shunsuke/pinact/main/json-schema/pinact.json
version: 3

ignore_actions:
# ci-workflows publishes no tags, so its actions are pinned to a commit of
# `main` and carry no release comment for pinact to verify.
- name: argumentcomputer/ci-workflows/.*
ref: "[0-9a-f]{40}"
rules:
# Branch refs that must keep tracking their branch: there is no stable tag
# to pin to. The shared ci-workflows actions are consumed from `main`.
- ignore: true
conditions:
- expr: ActionName matches "^argumentcomputer/ci-workflows/"
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ jobs:
# actionlint, shellcheck, pinact and zizmor over this repo's workflows.
# Runs before the toolchain setup so a workflow problem fails fast.
- name: Lint workflows
uses: argumentcomputer/ci-workflows/.github/actions/lint-workflows@a3a7b1b8f081503e6bf26341a3c5f759df96497a # main
uses: argumentcomputer/ci-workflows/.github/actions/lint-workflows@main
- uses: actions-rust-lang/setup-rust-toolchain@ecabd13d1c56bd1345c230e542e9144811ad706f # v2.0.0
- name: Check Rustfmt code style
run: cargo fmt --all --check
Expand Down
35 changes: 35 additions & 0 deletions .github/workflows/update-rust.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: Update Rust toolchain

on:
schedule:
# Weekly on Monday at midnight
- cron: "0 0 * * 1"
timezone: America/New_York
workflow_dispatch:

permissions:
contents: write
pull-requests: write

jobs:
update:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

# `update-flake` below rewrites the fenix hash and runs `nix flake update`
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
with:
github_access_token: ${{ github.token }}

# Moves `rust-toolchain.toml` to the latest stable release, with the
# fenix `sha256` and the fenix and crane inputs in `flake.nix`, and
# opens a PR on `update/rust-<version>`. nixpkgs follows fenix here, so
# it moves in the same PR. The PR is opened with `GITHUB_TOKEN`, so a
# maintainer closes and reopens it to run CI.
- uses: argumentcomputer/ci-workflows/.github/actions/rust-version@main
with:
update-flake: 'true'
pr: 'true'
7 changes: 7 additions & 0 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
rules:
unpinned-uses:
config:
policies:
# Branch-tracking ref allowed by .github/pinact.yaml
"argumentcomputer/ci-workflows/*": ref-pin
"*": hash-pin
Loading