Branch Checks #4150
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Branch Checks | |
| on: | |
| merge_group: | |
| types: [checks_requested] | |
| push: | |
| branches: | |
| - "pull-request/[0-9]+" | |
| workflow_dispatch: | |
| env: | |
| CARGO_TERM_COLOR: always | |
| CARGO_INCREMENTAL: "0" | |
| MISE_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| permissions: | |
| contents: read | |
| packages: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| pr_metadata: | |
| name: Resolve PR metadata | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| outputs: | |
| should_run: ${{ steps.gate.outputs.should_run }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - id: gate | |
| uses: ./.github/actions/pr-gate | |
| mise-lockfile: | |
| name: mise Lockfile | |
| needs: pr_metadata | |
| if: needs.pr_metadata.outputs.should_run == 'true' | |
| runs-on: linux-amd64-cpu8 | |
| container: | |
| image: ghcr.io/nvidia/openshell/ci:latest | |
| credentials: | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Mark workspace as safe for git | |
| run: git config --global --add safe.directory "$GITHUB_WORKSPACE" | |
| - name: Verify mise.lock is in sync with mise.toml | |
| run: | | |
| mise lock | |
| if ! git diff --exit-code mise.lock; then | |
| echo "::error::mise.lock is out of sync with mise.toml. Run 'mise lock' locally and commit the result." >&2 | |
| exit 1 | |
| fi | |
| license-headers: | |
| name: License Headers | |
| needs: pr_metadata | |
| if: needs.pr_metadata.outputs.should_run == 'true' | |
| runs-on: linux-amd64-cpu8 | |
| container: | |
| image: ghcr.io/nvidia/openshell/ci:latest | |
| credentials: | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Install tools | |
| run: mise install --locked | |
| - name: Check license headers | |
| run: mise run license:check | |
| cargo-deny: | |
| name: Cargo Deny | |
| needs: pr_metadata | |
| if: needs.pr_metadata.outputs.should_run == 'true' | |
| runs-on: linux-amd64-cpu8 | |
| defaults: | |
| run: | |
| shell: nix develop .#devShells.x86_64-linux.default -c bash -euo pipefail {0} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 | |
| with: | |
| github_access_token: ${{ secrets.GITHUB_TOKEN }} | |
| - uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17 | |
| with: | |
| name: openshell | |
| authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} | |
| - name: Check dependencies | |
| run: cargo deny check licenses bans sources | |
| rust: | |
| name: Rust (${{ matrix.system }}) | |
| needs: pr_metadata | |
| if: needs.pr_metadata.outputs.should_run == 'true' | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - runner: linux-amd64-cpu8 | |
| system: x86_64-linux | |
| - runner: linux-arm64-cpu8 | |
| system: aarch64-linux | |
| - runner: macos-15-xlarge | |
| system: aarch64-darwin | |
| runs-on: ${{ matrix.runner }} | |
| defaults: | |
| run: | |
| shell: nix develop .#devShells.${{ matrix.system }}.default -c bash -euo pipefail {0} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 | |
| with: | |
| github_access_token: ${{ secrets.GITHUB_TOKEN }} | |
| - uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17 | |
| with: | |
| name: openshell | |
| authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} | |
| - name: Realize Nix development shell | |
| shell: bash | |
| run: nix build --no-link ".#devShells.${{ matrix.system }}.default" | |
| - name: Cache Rust target and registry | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| # Keep branch-check caches partitioned by target system; lint | |
| # and test intentionally share the same job-local target directory. | |
| shared-key: rust-checks-${{ matrix.system }} | |
| # Preserve compiled artifacts from failed lint/test runs so the next | |
| # push to the same PR branch does not start from a cold cache. | |
| cache-on-failure: "true" | |
| cache-workspace-crates: "true" | |
| cache-bin: "false" | |
| cmd-format: nix develop .#devShells.${{ matrix.system }}.default -c {0} | |
| - name: Format | |
| run: | | |
| cargo fmt --all -- --check | |
| cargo fmt --manifest-path e2e/rust/Cargo.toml --all -- --check | |
| cargo fmt --manifest-path examples/governance-interceptor/Cargo.toml --all -- --check | |
| - name: Lint | |
| run: | | |
| cargo clippy --workspace --all-targets -- -D warnings | |
| cargo clippy --manifest-path e2e/rust/Cargo.toml --all-targets -- -D warnings | |
| cargo check --manifest-path examples/governance-interceptor/Cargo.toml --all-targets | |
| - name: Test | |
| env: | |
| OPENSHELL_TELEMETRY_ENABLED: "false" | |
| run: | | |
| cargo nextest run --profile ci --workspace --features openshell-server/test-support | |
| python: | |
| name: Python (${{ matrix.runner }}) | |
| needs: pr_metadata | |
| if: needs.pr_metadata.outputs.should_run == 'true' | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| runner: [linux-amd64-cpu8, linux-arm64-cpu8] | |
| runs-on: ${{ matrix.runner }} | |
| container: | |
| image: ghcr.io/nvidia/openshell/ci:latest | |
| credentials: | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Install tools | |
| run: mise install --locked | |
| - name: Install dependencies | |
| run: uv sync --frozen | |
| - name: Format | |
| run: mise run python:format:check | |
| - name: Lint | |
| run: mise run python:lint | |
| - name: Typecheck | |
| run: mise run python:typecheck | |
| - name: Test | |
| run: mise run test:python | |
| go: | |
| name: Go SDK | |
| needs: pr_metadata | |
| if: needs.pr_metadata.outputs.should_run == 'true' | |
| runs-on: linux-amd64-cpu8 | |
| container: | |
| image: ghcr.io/nvidia/openshell/ci:latest | |
| credentials: | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Install tools | |
| run: mise install --locked | |
| - name: Lint, build, test, proto-check | |
| run: mise run go:ci | |
| markdown: | |
| name: Markdown | |
| needs: pr_metadata | |
| if: needs.pr_metadata.outputs.should_run == 'true' | |
| runs-on: linux-amd64-cpu8 | |
| container: | |
| image: ghcr.io/nvidia/openshell/ci:latest | |
| credentials: | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Install tools | |
| run: mise install --locked | |
| - name: Lint | |
| run: mise run markdown:lint | |
| sdk-typescript: | |
| name: TypeScript SDK | |
| needs: pr_metadata | |
| if: needs.pr_metadata.outputs.should_run == 'true' | |
| runs-on: linux-amd64-cpu8 | |
| container: | |
| image: ghcr.io/nvidia/openshell/ci:latest | |
| credentials: | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Install tools | |
| run: mise install --locked | |
| - name: Check TypeScript SDK | |
| run: mise run sdk:ts:ci | |
| # Exercise the full release publish path (version stamp, dist-tag, | |
| # prepublishOnly, tarball) without uploading. Uses the off-tag dev | |
| # version, which validates the prerelease dist-tag branch too. | |
| - name: Verify publishable artifact (dry-run) | |
| env: | |
| OPENSHELL_NPM_PUBLISH_ARGS: --dry-run | |
| run: | | |
| OPENSHELL_NPM_VERSION="$(uv run python tasks/scripts/release.py get-version --npm)" \ | |
| mise run sdk:ts:publish |