Files
sanderling/.github/workflows/ci.yml
T
pj 4848b8c067 ci: lint the workflows on every pr
The workflows that fuzz the examples are dispatch-only, and GitHub will
not dispatch a workflow that is not on the default branch, so their first
real run is after merge. actionlint and the reference checker are the
only things that can fail before that.

actionlint is pinned by commit, and its tool version is pinned too so a
new release cannot change what CI enforces.
2026-08-16 01:55:06 +05:30

150 lines
4.7 KiB
YAML

name: ci
on:
# Runs on PRs (opened / synchronize / reopened, which are the defaults) and
# manual dispatch only. We deliberately don't run on direct pushes to master:
# master is PR-merge-only, and PR validation already covers the merge
# commit via the `synchronize` event on the PR branch.
pull_request:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Set up Go
uses: actions/setup-go@v7
with:
go-version-file: go.mod
cache: true
- name: Set up JDK 17
uses: actions/setup-java@v5
with:
distribution: temurin
java-version: "17"
- name: Set up Android SDK
uses: android-actions/setup-android@40fd30fb8d7440372e1316f5d1809ec01dcd3699 # v4.0.1
- name: Set up Node 22
uses: actions/setup-node@v7
with:
node-version: "22"
cache: npm
cache-dependency-path: pkg/spec/package-lock.json
- name: Set up bun
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3.13"
- name: Cache bun store
uses: actions/cache@v6
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('replay-ui/bun.lock') }}
restore-keys: |
bun-${{ runner.os }}-
# The token is what stops this step flaking: without it the action pulls
# buf's release tarball from github.com anonymously, on the shared runner
# IP's rate limit, and a throttled connection shows up as `socket hang
# up` after three retries. The version is the action's own default, made
# explicit so a new action release cannot move the buf we build with.
- name: Install buf
uses: bufbuild/buf-setup-action@a47c93e0b1648d5651a065437926377d060baa99 # v1.50.0
with:
version: "1.50.0"
github_token: ${{ secrets.GITHUB_TOKEN }}
- name: Install protoc plugins
run: |
go install google.golang.org/protobuf/cmd/protoc-gen-go@latest
go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH"
- name: Cache Gradle
uses: actions/cache@v6
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: |
gradle-${{ runner.os }}-
- name: Bootstrap
run: make bootstrap
- name: Lint proto
run: buf lint
- name: Go vet
run: go vet ./...
- name: Run tests
run: make test
# folio is its own gradle build, and the metro plugin it compiles with
# needs a 21 runtime where the sidecar toolchain pins 17. Switching
# JAVA_HOME after `make test` rather than installing both up front
# leaves every step above this one on exactly the JDK it ran on before.
- name: Set up JDK 21 for folio
uses: actions/setup-java@v5
with:
distribution: temurin
java-version: "21"
- name: Run folio's unit tests
run: make test-folio
browser:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Set up Go
uses: actions/setup-go@v7
with:
go-version-file: go.mod
cache: true
- name: Set up headless Chrome
uses: ./.github/actions/headless-chrome
- name: Drive web fixtures through headless Chrome
run: make test-browser
# Four workflows and four composite actions, and the ones that fuzz the
# examples are dispatch-only, which GitHub refuses to dispatch until they are
# on the default branch. Their first real run is therefore after merge, so a
# bad expression or a missing action would land before anything caught it.
workflows:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
# Pinned so a new actionlint release cannot change what CI enforces,
# for the same reason the buf version above is spelled out. shellcheck
# runs over every run: block by default.
- name: Lint the workflows
uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0
with:
version: 1.7.12
# actionlint reads a local action's inputs but never checks that its path
# exists: `uses: ./.github/actions/typo` lints clean and fails only when
# the job runs.
- name: Check that the workflow references resolve
run: .github/scripts/workflow-refs.sh