-
Notifications
You must be signed in to change notification settings - Fork 5
Expand file tree
/
Copy pathaction.yml
More file actions
94 lines (94 loc) · 3.56 KB
/
Copy pathaction.yml
File metadata and controls
94 lines (94 loc) · 3.56 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
name: 'Axint proof gate'
description: 'Run local Axint proof for an Apple project and expose its verdict and signed receipt.'
author: 'Agentic Empire'
branding:
icon: 'check-circle'
color: 'orange'
inputs:
directory:
description: 'Path to the Apple project, relative to the workspace.'
required: false
default: '.'
version:
description: 'Published @axint/compiler version. Pin this for repeatable CI.'
required: false
default: '0.6.0'
scheme:
description: 'Optional Xcode scheme. Axint discovers one when omitted.'
required: false
default: ''
destination:
description: 'Optional xcodebuild destination (e.g. platform=macOS).'
required: false
default: ''
strict:
description: 'Fail on needs-review as well as failed proof.'
required: false
default: 'true'
outputs:
status:
description: 'Axint proof status: pass, needs_review, or fail.'
value: ${{ steps.prove.outputs.status }}
verdict:
description: 'Axint proof gate decision (for example evidence_required).'
value: ${{ steps.prove.outputs.verdict }}
receipt:
description: 'Local path to the signed, source-free JSON receipt.'
value: ${{ steps.prove.outputs.receipt }}
runs:
using: 'composite'
steps:
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: '22'
- name: Prove Apple project
id: prove
shell: bash
env:
AXINT_DIRECTORY: ${{ inputs.directory }}
AXINT_VERSION: ${{ inputs.version }}
AXINT_SCHEME: ${{ inputs.scheme }}
AXINT_DESTINATION: ${{ inputs.destination }}
AXINT_STRICT: ${{ inputs.strict }}
run: |
set -euo pipefail
if [[ ! "$AXINT_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+([-.][A-Za-z0-9.-]+)?$ ]]; then
echo 'version must be a published semver release' >&2
exit 2
fi
if [[ ! -d "$AXINT_DIRECTORY" ]]; then
echo 'directory does not exist' >&2
exit 2
fi
args=(prove --dir "$AXINT_DIRECTORY" --json)
if [[ -n "$AXINT_SCHEME" ]]; then args+=(--scheme "$AXINT_SCHEME"); fi
if [[ -n "$AXINT_DESTINATION" ]]; then args+=(--destination "$AXINT_DESTINATION"); fi
if [[ "$AXINT_STRICT" == true ]]; then args+=(--strict); fi
tool_root="$(mktemp -d)"
npm install --prefix "$tool_root" --no-save --no-audit --no-fund "@axint/compiler@$AXINT_VERSION"
output="$(mktemp)"
set +e
"$tool_root/node_modules/.bin/axint" "${args[@]}" > "$output"
code=$?
set -e
if [[ ! -s "$output" ]]; then
echo "Axint produced no JSON; CLI exit code: $code" >&2
exit 1
fi
node - "$output" "$GITHUB_OUTPUT" "$GITHUB_STEP_SUMMARY" <<'NODE'
const fs = require('node:fs');
const [output, actionOutput, summary] = process.argv.slice(2);
const report = JSON.parse(fs.readFileSync(output, 'utf8'));
if (!['pass', 'needs_review', 'fail'].includes(report.status) ||
typeof report.gate?.decision !== 'string' ||
typeof report.artifacts?.receipt?.json !== 'string') {
throw new Error('Axint returned an incomplete proof report');
}
fs.appendFileSync(actionOutput,
`status=${report.status}\nverdict=${report.gate.decision}\nreceipt=${report.artifacts.receipt.json}\n`);
fs.appendFileSync(summary,
`## Axint proof\n\nStatus: ${report.status}\n\nVerdict: ${report.gate.decision}\n\nReceipt: \`${report.artifacts.receipt.json}\`\n`);
NODE
cat "$output"
exit "$code"