Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ jobs:
name: Product version identity
runs-on: windows-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Verify every remote GitHub Action is commit-pinned
shell: pwsh
run: ./scripts/Test-GitHubActionPins.ps1
Expand Down Expand Up @@ -98,7 +98,7 @@ jobs:
runs-on: ${{ matrix.os }}
timeout-minutes: 25
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@2eae45db285e407f22119950686d47e1101e071b # 1.88.0
- name: Assert exact MSRV toolchain
shell: pwsh
Expand Down Expand Up @@ -139,7 +139,7 @@ jobs:
# to reach its own bounded-process diagnostic.
timeout-minutes: 75
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@f8be11a05b1d4f3fcebe6410cc16743212b999b0 # 1.98.0
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
- run: cargo fmt --all -- --check
Expand Down Expand Up @@ -179,7 +179,7 @@ jobs:
target: macos-aarch64
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@f8be11a05b1d4f3fcebe6410cc16743212b999b0 # 1.98.0
- name: Provision OpenSSL 3 on macOS
if: runner.os == 'macOS'
Expand Down Expand Up @@ -268,12 +268,12 @@ jobs:
# of canceling a healthy compiler process at the old 45-minute ceiling.
timeout-minutes: 75
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@f8be11a05b1d4f3fcebe6410cc16743212b999b0 # 1.98.0
- uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
- uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
with:
version: 11.0.8
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24.19.0
cache: pnpm
Expand Down Expand Up @@ -361,7 +361,7 @@ jobs:
Select-Object FullName,LastWriteTime,Length
- name: Upload Windows controller/worker round-trip evidence
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-windows-controller-worker-roundtrip
path: |
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,16 +32,16 @@ jobs:

steps:
- name: Check out source
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Initialize CodeQL
uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4
with:
languages: ${{ matrix.language }}
build-mode: none
queries: security-extended

- name: Analyze
uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4
with:
category: "/language:${{ matrix.language }}"
12 changes: 6 additions & 6 deletions .github/workflows/dependency-security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,9 +34,9 @@ jobs:
lockfile: apps/desktop/src-tauri/Cargo.lock
steps:
- name: Check out source
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install pinned cargo-audit
uses: taiki-e/install-action@b6ff580856c41316412a0b9b60540fbc6f8c82cc # v2
uses: taiki-e/install-action@83ac0ad63c0167e6f06796fab0fce28db1bf3db0 # v2
with:
tool: cargo-audit@0.22.2
- name: Reject known Rust vulnerabilities
Expand All @@ -56,7 +56,7 @@ jobs:
manifest: ./apps/desktop/src-tauri/Cargo.toml
steps:
- name: Check out source
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2
with:
Expand All @@ -70,13 +70,13 @@ jobs:
timeout-minutes: 15
steps:
- name: Check out source
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up pnpm
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
with:
version: 11.0.8
- name: Set up Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24.19.0
cache: pnpm
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/ga.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ jobs:
# used only for that endpoint; an absent token intentionally fails closed.
CYC_GA_GOVERNANCE_TOKEN: ${{ secrets.CYC_GA_GOVERNANCE_TOKEN }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.source_tag }}
fetch-depth: 0
Expand Down Expand Up @@ -427,7 +427,7 @@ jobs:

- name: Upload GA gate diagnostics
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-ga-readiness-${{ inputs.source_tag }}
path: ${{ runner.temp }}/cyc-ga-readiness/*
Expand Down Expand Up @@ -467,7 +467,7 @@ jobs:
CYC_GA_GOVERNANCE_TOKEN: ${{ secrets.CYC_GA_GOVERNANCE_TOKEN }}
GH_TOKEN: ${{ github.token }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.source_tag }}
fetch-depth: 0
Expand Down
56 changes: 28 additions & 28 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ jobs:
source_tag: ${{ steps.identity.outputs.source_tag }}
source_commit: ${{ steps.identity.outputs.source_commit }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Verify annotated release tag and checked-out source commit
Expand Down Expand Up @@ -150,7 +150,7 @@ jobs:
os: windows-latest
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@2eae45db285e407f22119950686d47e1101e071b # 1.88.0
- name: Assert exact MSRV toolchain
shell: pwsh
Expand All @@ -176,7 +176,7 @@ jobs:
os: [windows-latest, ubuntu-latest, macos-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Verify private signing-key file protection
shell: pwsh
run: ./scripts/Test-WorkerKitSigningKeyProtection.ps1
Expand Down Expand Up @@ -227,7 +227,7 @@ jobs:
include_worker: "true"
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@f8be11a05b1d4f3fcebe6410cc16743212b999b0 # 1.98.0
with:
targets: ${{ matrix.target }}
Expand Down Expand Up @@ -304,7 +304,7 @@ jobs:
if ($LASTEXITCODE -ne 0) { throw "Windows controller/worker round trip failed with exit code $LASTEXITCODE." }
- name: Upload Windows controller/worker round-trip evidence
if: runner.os == 'Windows' && always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-windows-controller-worker-roundtrip-${{ matrix.label }}
path: |
Expand Down Expand Up @@ -592,14 +592,14 @@ jobs:
if (-not [string]::IsNullOrWhiteSpace([string]$env:CYC_WORKER_KIT_SIGNING_KEY_PATH)) {
[IO.File]::Delete([string]$env:CYC_WORKER_KIT_SIGNING_KEY_PATH)
}
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-${{ matrix.label }}-preview
path: release-assets/*
if-no-files-found: error
- name: Upload managed worker kit for controller aggregation
if: matrix.include_worker == 'true'
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-worker-kit-${{ matrix.label }}
path: release-stage/*/worker-kit/*
Expand All @@ -618,7 +618,7 @@ jobs:
CC_aarch64_unknown_linux_gnu: aarch64-linux-gnu-gcc
AR_aarch64_unknown_linux_gnu: aarch64-linux-gnu-ar
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@f8be11a05b1d4f3fcebe6410cc16743212b999b0 # 1.98.0
with:
targets: aarch64-unknown-linux-gnu
Expand Down Expand Up @@ -695,7 +695,7 @@ jobs:
if (-not [string]::IsNullOrWhiteSpace([string]$env:CYC_WORKER_KIT_SIGNING_KEY_PATH)) {
[IO.File]::Delete([string]$env:CYC_WORKER_KIT_SIGNING_KEY_PATH)
}
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-worker-kit-linux-arm64
path: worker-kit-artifact/*
Expand All @@ -709,15 +709,15 @@ jobs:
CYC_PRODUCT_VERSION: ${{ needs.release-identity.outputs.product_version }}
runs-on: windows-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@f8be11a05b1d4f3fcebe6410cc16743212b999b0 # 1.98.0
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
key: release-integration-preview
- uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
- uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
with:
version: 11.0.8
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24.19.0
cache: pnpm
Expand Down Expand Up @@ -936,7 +936,7 @@ jobs:
$hash = (Get-FileHash -Algorithm SHA256 -LiteralPath $archive).Hash.ToLowerInvariant()
"$hash $(Split-Path $archive -Leaf)" |
Set-Content -NoNewline -Encoding ascii "$archive.sha256"
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-integration-preview
path: release-assets/*
Expand All @@ -953,9 +953,9 @@ jobs:
CYC_SOURCE_COMMIT: ${{ needs.release-identity.outputs.source_commit }}
runs-on: windows-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Download cross-platform managed worker kits
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: ClusterYourCodex-worker-kit-*
path: ${{ runner.temp }}\cyc-downloaded-worker-kits
Expand Down Expand Up @@ -1017,10 +1017,10 @@ jobs:
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
key: windows-self-contained-preview
- uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
- uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
with:
version: 11.0.8
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24.19.0
cache: pnpm
Expand Down Expand Up @@ -1420,7 +1420,7 @@ jobs:
if ($LASTEXITCODE -ne 0) { throw 'fresh deployment lifecycle smoke failed' }
- name: Upload fresh deployment diagnostics
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-windows-fresh-deployment-diagnostics
path: ${{ runner.temp }}\ClusterYourCodex-fresh-deployment-smoke\**
Expand Down Expand Up @@ -1452,12 +1452,12 @@ jobs:
if ($LASTEXITCODE -ne 0) { throw 'silent Setup lifecycle smoke failed' }
- name: Upload silent Setup diagnostics
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-windows-setup-silent-diagnostics
path: ${{ runner.temp }}\ClusterYourCodex-setup-silent-smoke\**
if-no-files-found: warn
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-windows-x64-self-contained-preview
path: release-assets/*
Expand All @@ -1480,9 +1480,9 @@ jobs:
CYC_PRODUCT_VERSION: ${{ needs.release-identity.outputs.product_version }}
CYC_DISPOSABLE_WINDOWS: "1"
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Download the Windows x64 self-contained preview
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ClusterYourCodex-windows-x64-self-contained-preview
path: ${{ runner.temp }}\cyc-windows11-acceptance-artifact
Expand Down Expand Up @@ -1634,7 +1634,7 @@ jobs:
if ($matrixExitCode -ne 0) { throw "Windows profile/path matrix failed with exit code $matrixExitCode." }
- name: Upload Windows 11 ARM64 compatibility diagnostics
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-windows11-arm64-compatibility-diagnostics
path: ${{ runner.temp }}\cyc-windows11-acceptance-diagnostics\**
Expand All @@ -1653,7 +1653,7 @@ jobs:
CYC_PRODUCT_VERSION: ${{ needs.release-identity.outputs.product_version }}
runs-on: ubuntu-latest
steps:
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
path: downloaded-artifacts
- name: Verify sidecars and assemble indexed release assets
Expand Down Expand Up @@ -1901,7 +1901,7 @@ jobs:
- id: provenance
name: Attest every tagged prerelease payload asset with GitHub build provenance
if: github.ref_type == 'tag' && needs.release-identity.outputs.source_tag != ''
uses: actions/attest-build-provenance@96278af6caaf10aea03fd8d33a09a777ca52d62f # v3.2.0
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-path: provenance-subjects/*
- name: Verify tagged provenance evidence exists before publication
Expand Down Expand Up @@ -1942,7 +1942,7 @@ jobs:
$combined = @($index.artifacts | Sort-Object name | ForEach-Object { "$($_.sha256) $($_.name)" })
$combined += "$indexHash release-index.json"
$combined | Set-Content -LiteralPath (Join-Path $PWD 'release-assets/SHA256SUMS') -Encoding ASCII
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ClusterYourCodex-release-index-preview
path: release-assets/*
Expand All @@ -1961,11 +1961,11 @@ jobs:
permissions:
contents: write
steps:
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ClusterYourCodex-release-index-preview
path: release-assets
- uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2
- uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3
with:
draft: false
prerelease: ${{ needs.release-identity.outputs.release_channel != 'stable' }}
Expand Down
Loading
Loading