Files
pj 93c2d2ba74 ci: fix the node 20 warning and pin the protoc plugins (#84)
* ci: replace the archived buf-setup-action with buf-action

buf-setup-action is archived and runs on node20, which the runners now
warn about. buf-action is its supported replacement and runs on node24.
setup_only keeps it an install, since buf lint is its own step.

* ci: bump bun to 1.3.14

* ci: bump setup-chrome to v2.2.0

* ci: move to node 24 and drop the npm oidc workaround

node 22 is in maintenance and ships npm 10, which is why the publish job
had to install npm@latest over it. node 24 is the active lts and bundles
npm 11.17.0, above the 11.5.1 oidc floor, so the extra step goes.

* ci: pin the protoc plugins instead of installing @latest

these generate the committed stubs, so @latest makes codegen depend on
whatever released most recently. pinned to the versions proto/ records:
protoc-gen-go v1.36.11, protoc-gen-go-grpc v1.6.0.

* ci: run the ios leg on macos-26, pinned to a device and a runtime

macos-26 carries no iPhone 16 Pro at all, and on macos-15 that name spanned
iOS 18.5 through 26.2, so the leg could boot a two-major-old runtime. the
pair is now iPhone 17 Pro on iOS 26.2, resolved to a udid before boot, and
an image that drops it fails naming what it does carry.

iPhone 17 Pro is what examples/folio/justfile already defaulted to.

* ci: keep IOS_DEVICE a device name, not the resolved udid

the boot step exported the udid as IOS_DEVICE, and just ios spends that as
xcodebuild's -destination name=, which matches the display name and
rejected it: 'unable to find a device matching { name:6F69910C-... }'.

nothing downstream needed it. install, launch and terminate all address
booted, and sanderling resolves --ios-device against booted simulators
first, so the simulator this step boots is the one they all get.
2026-08-16 22:57:38 +05:30

31 lines
1.3 KiB
YAML

name: headless chrome
description: Install Chrome and prove it starts headless before a driver depends on it.
runs:
using: composite
steps:
# stable is setup-chrome v2's own default, spelled out so a new release of
# the action cannot move the browser these jobs drive. The alternative it
# offers is Chrome for Testing latest, which tracks ahead of the channel
# users run.
- uses: browser-actions/setup-chrome@48ad923757ca74d66703209fe939badbdf80f2f4 # v2.2.0
with:
chrome-version: stable
# Ubuntu 24.04 (current ubuntu-latest) restricts unprivileged user
# namespaces via AppArmor, which stops headless Chrome from starting even
# with --no-sandbox: the process launches but never opens its DevTools
# socket. Re-enable them so the driver's Chrome can come up.
- name: Allow Chrome under unprivileged user namespaces
shell: bash
run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
# Fail here with Chrome's own stderr if the browser can't launch, instead
# of letting the driver report an opaque DevTools timeout downstream.
- name: Verify headless Chrome starts
shell: bash
run: |
chrome --version
chrome --headless --no-sandbox --disable-gpu --disable-dev-shm-usage \
--dump-dom 'data:text/html,<title>ok</title>'