Skip to content

chore(deps): Bump github/codeql-action/analyze from 4.37.6 to 4.38.2 #80

chore(deps): Bump github/codeql-action/analyze from 4.37.6 to 4.38.2

chore(deps): Bump github/codeql-action/analyze from 4.37.6 to 4.38.2 #80

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ci-${{ github.workflow }}-${{ github.event_name }}-${{ github.event_name == 'push' && github.sha || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
env:
CARGO_INCREMENTAL: "0"
RUST_BACKTRACE: "1"
jobs:
change-scope:
name: Classify validation scope
runs-on: ubuntu-24.04
timeout-minutes: 5
outputs:
requires_full_validation: ${{ steps.scope.outputs.requires_full_validation }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Validate change-scope classifier
shell: pwsh
run: .\scripts\Test-CiChangeScope.ps1
- name: Validate release tag helper
shell: pwsh
run: .\scripts\Test-ReleaseTag.ps1
- name: Validate tracked workflow scripts
shell: pwsh
run: .\scripts\Test-WorkflowScripts.ps1
- name: Classify changed paths
id: scope
shell: pwsh
run: .\scripts\Get-CiChangeScope.ps1 -WriteGitHubOutput
windows:
name: Windows Rust, native, and WinCred
needs: change-scope
if: needs.change-scope.outputs.requires_full_validation == 'true'
runs-on: windows-2022
timeout-minutes: 45
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Install pinned Rust toolchain
shell: pwsh
run: |
rustup toolchain install 1.97.1 --profile minimal --component clippy,rustfmt
rustup default 1.97.1
if ((rustc --version) -notmatch '1\.97\.1') { throw 'Rust 1.97.1 was not selected.' }
- name: Restore Rust compilation and Cargo cache
env:
CARGO_TARGET_DIR: target-ci
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
key: windows-2022-rust-1.97.1-x86_64-pc-windows-msvc-ci-target
# Preserve the clean release build while caching validation dependencies.
workspaces: |
. -> target-ci
- name: Validate Rust, CMake, CTest, and live WinCred
shell: pwsh
env:
CARGO_TARGET_DIR: target-ci
run: .\test.ps1 -Configuration Debug -RunWinCredLive
- name: Assemble reproducible Windows release inputs
shell: pwsh
run: |
$env:SOURCE_DATE_EPOCH = (git log -1 --format=%ct).Trim()
.\scripts\build.ps1 -Configuration Release -SkipLinux -Clean
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: windows-release
path: |
artifacts/Release/windows
artifacts/Release/symbols
if-no-files-found: error
retention-days: 30
ubuntu:
name: Ubuntu provider and D-Bus contract
needs: change-scope
if: needs.change-scope.outputs.requires_full_validation == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 35
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Install Linux test prerequisites
shell: bash
run: bash scripts/ci/install-linux-test-prerequisites.sh
- name: Install pinned Rust and musl target
shell: bash
run: |
set -euo pipefail
rustup toolchain install 1.97.1 --profile minimal --component clippy,rustfmt
rustup default 1.97.1
rustup target add x86_64-unknown-linux-musl --toolchain 1.97.1
rustc --version | grep -F '1.97.1'
- name: Restore Rust compilation and Cargo cache
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
key: ubuntu-24.04-rust-1.97.1-x86_64-unknown-linux-gnu-musl
- name: Validate shell contracts
shell: bash
run: |
set -euo pipefail
bash -n packaging/linux/wincred-libsecret-bootstrap.sh scripts/build-linux.sh scripts/test-linux.sh tests/e2e/run-linux-e2e.sh tests/linux/test-bootstrap-no-backup.sh tests/linux/test-refresh-unit-contract.sh tests/linux/test-interop-unit-contract.sh tests/linux/test-libsecret-client-compile.sh
test -x scripts/build-linux.sh
test -x scripts/test-linux.sh
test -x tests/e2e/run-linux-e2e.sh
- name: Test provider and libsecret contract
shell: bash
env:
WINCRED_REQUIRE_DBUS_TESTS: "1"
run: scripts/test-linux.sh
- name: Assemble musl provider release input
shell: bash
run: |
set -euo pipefail
export SOURCE_DATE_EPOCH="$(git log -1 --format=%ct)"
scripts/build-linux.sh Release
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: linux-release
path: artifacts/Release/linux
if-no-files-found: error
retention-days: 30
package:
name: Assemble and validate signed-layout MSI
needs: [change-scope, windows, ubuntu]
if: >-
always() &&
needs.change-scope.outputs.requires_full_validation == 'true' &&
needs.windows.result == 'success' &&
needs.ubuntu.result == 'success'
runs-on: windows-2022
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: windows-release
path: artifacts/Release
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: linux-release
path: artifacts/Release/linux
- name: Restore pinned WiX v5 tool
shell: pwsh
run: dotnet tool restore
- name: Build MSI, metadata, and checksums
shell: pwsh
run: .\scripts\package.ps1 -Configuration Release -SkipBuild
- name: Validate package and MSI database
shell: pwsh
run: |
.\scripts\Test-Packaging.ps1 `
-StageDirectory .\packages\stage\Release `
-MsiPath .\packages\Release\wincred-libsecret-wsl-plugin.msi
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: release-layout-unsigned
path: |
packages/Release
packages/stage/Release
if-no-files-found: error
retention-days: 14
dependency-security:
name: Cargo advisory and license policy
needs: change-scope
if: needs.change-scope.outputs.requires_full_validation == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 25
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install pinned Rust toolchain
shell: bash
run: |
set -euo pipefail
rustup toolchain install 1.97.1 --profile minimal
rustup default 1.97.1
- name: Restore Cargo tool cache
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
key: ubuntu-24.04-rust-1.97.1-cargo-deny-0.20.2-cargo-audit-0.22.2
cache-targets: "false"
- name: Install pinned dependency scanners
shell: bash
run: |
set -euo pipefail
cargo install --locked cargo-deny --version 0.20.2
cargo install --locked cargo-audit --version 0.22.2
- name: Enforce advisory, source, ban, and license policy
shell: bash
run: |
set -euo pipefail
cargo deny --config deny.toml check advisories bans licenses sources
cargo audit