Skip to content

[mise-lock] chore: migrate CI to mise-action - #12

Merged
krukonshedul merged 3 commits into
mainfrom
chore/add-mise-lock
Aug 26, 2026
Merged

krukonshedul merged 3 commits into
mainfrom
chore/add-mise-lock

Conversation

@krukonshedul

@krukonshedul krukonshedul commented Aug 21, 2026 •

Copy link
Copy Markdown

Part of the fleet-wide mise-action CI migration.

  • Added root mise.toml with elixir = "1.17.2-otp-27" / erlang = "27.0", taken verbatim from the removed .tool-versions.
  • Generated mise.lock, now in the versioned lockfile_version = 1 format mise 2026.8.11+ requires.
  • Removed .tool-versions.
  • .github/workflows/test.yml: this repo runs an intentional Elixir/OTP compat-test matrix (elixir 1.12–1.17 x otp 24–27). Replaced step-security/setup-beam with step-security/mise-action, pinned to v4.2.4 (mise CLI 2026.8.12), using the mise_toml input to override [tools] per matrix job — same pattern already used in sibling repo timex.
    • Judgment call: the old matrix used fuzzy 1.17.x/27.x version ranges (supported by setup-beam) which mise does not support as version specs. Replaced each with the concrete latest-patch pin for that minor/OTP pairing (e.g. 1.17.x/27.x -> elixir = "1.17.3-otp-27", otp = "27"), preserving the original intent of testing against the latest patch of each Elixir/OTP combination.
    • Adjusted the Mix deps cache key to reference matrix.otp/matrix.elixir directly instead of the removed setup-beam step's outputs.
  • Added .github/actions.lock.yaml to .gitignore (new line) and regenerated it via alflow.

No functional CI behavior change intended beyond the setup-action swap.

Replace step-security/setup-beam with step-security/mise-action across the
Elixir/OTP compat-test matrix, using mise-action's mise_toml input to override
per-matrix-job versions (fuzzy .x versions replaced with concrete
elixir/erlang pins mise supports). Add root mise.toml (from .tool-versions),
generate mise.lock, remove .tool-versions, and ignore .github/actions.lock.yaml.
@socket-security

socket-security Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedstep-security/​mise-action@​6e96d2ffbc65c037f23c78818f2a339d6cf830f799100100100100

View full report

krukonshedul and others added 2 commits August 26, 2026 11:23
…26.8.12

Pins step-security/mise-action to v4.2.4 (mise CLI 2026.8.12) and
regenerates mise.lock to the versioned lockfile format mise 2026.8.11+
requires.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The multi-version matrix predates the mise migration and generated a
per-row inline mise_toml, bypassing the checked-in mise.toml/mise.lock
and its checksum pins. Collapse to the single locked toolchain version.

Also, step-security/mise-action doesn't install Hex/Rebar the way
erlef/setup-elixir used to, so `mix test` was prompting to install Hex
interactively and failing in CI. Pin Hex to 2.5.1 explicitly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@krukonshedul krukonshedul changed the title chore: migrate CI to mise-action [mise-lock] chore: migrate CI to mise-action Aug 26, 2026

@dyl-sv dyl-sv left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed all 3 commits (mechanical migration -> lockfile_version=1 refresh + mise-action v4.2.4 pin -> matrix/Hex fix) and the cumulative diff against the known bug-pattern list.

Verified against live CI on current head (57aef47), both the push and pull_request-triggered test runs (32967018556, 32967022655) are green:

  • mise install --locked succeeds cleanly, installing erlang 27.0 and elixir 1.17.2-otp-27 from mise.lock (no lockfile parse errors despite erlang's lockfile having 3 [[tools.erlang]] blocks split by precompiled_os — that's expected mise-generated structure for OS-specific precompiled variants, not corruption; install logs confirm it resolves correctly).
  • Obsolete elixir/otp version matrix removed (pattern #1) — single job now runs on the mise.toml-pinned toolchain only; confirmed no matrix: block remains and no per-row inline mise_toml overrides.
  • Hex/Rebar install fixed explicitly (mix local.hex --force 2.5.1) — resolves the interactive-prompt failure the mechanical commit introduced; confirmed non-interactive install succeeds in logs.
  • mix.exs declares elixir: "~> 1.12"; pinned 1.17.2-otp-27 satisfies this (pattern #5 not applicable).
  • runner label ubuntu-latest is current, not deprecated (pattern #6 n/a).
  • version: '2026.8.12' input matches the mise CLI version actually downloaded/run in CI logs and is compatible with lockfile_version=1 (pattern #8 n/a — no separate MISE_VERSION env var present).
  • step-security/mise-action pin 6e96d2ffbc65c037f23c78818f2a339d6cf830f7 verified against upstream tags = v4.2.4, matching the commit message; only one workflow file (test.yml) and no composite actions in this repo, so no other stale pins to check (pattern #9 n/a for the workflow itself).
  • mix test: 10 tests, 0 failures. mix format --check-formatted: no output (pass).

Minor non-blocking nit: .github/actions.lock.yaml (a StepSecurity metadata file, not consumed by the workflow itself) still records step-security/mise-action@v4.2.0 while the workflow was bumped to v4.2.4 — it's now gitignored going forward per the first commit, so this is stale committed metadata rather than a functional issue, and none of the passing checks depend on it.

CI is green on the actual PR head via a real pull_request-triggered run, not just diff-reading. Approving.

@krukonshedul
krukonshedul merged commit 93d90e5 into main Aug 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants