Repository navigation
Lock file maintenance #1232
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| pull_request: | |
| branches: [main] | |
| jobs: | |
| check: | |
| # Pinned to a specific runner image, not `ubuntu-latest`, so a GitHub | |
| # `-latest` migration can't silently change the build environment. Renovate | |
| # (github-actions manager, github-runners datasource) bumps this via the | |
| # same age-gated PRs as the action SHAs; it can't manage `-latest` itself. | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| # Actions pinned to commit-SHA digests, not mutable tags/branches, to | |
| # close the supply-chain hole a force-pushed tag/branch would open. The | |
| # trailing comment tracks the human-readable version; Renovate | |
| # (.github/renovate.json5) bumps the SHAs so the pins don't rot. | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 | |
| # All gate tooling (bun + uv) comes from the flake's lean .#ci shell, so | |
| # the Python gate (//#test:hermes) resolves uv the same way locally and | |
| # in CI. No setup-bun: bun is in the shell too. | |
| - run: nix develop .#ci --command bash -euo pipefail -c 'bun install --frozen-lockfile && bun run check' |