forked from HyperSafeD/Sanctifier
-
Notifications
You must be signed in to change notification settings - Fork 0
144 lines (116 loc) · 3.97 KB
/
Copy pathrust.yml
File metadata and controls
144 lines (116 loc) · 3.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
name: Rust CI
on:
push:
branches: ["main"]
pull_request:
branches: ["main"]
env:
CARGO_TERM_COLOR: always
jobs:
build-and-test:
name: Build & Test
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Install stable Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy
- name: Cache cargo registry & build artifacts
uses: actions/cache@v4
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-${{ hashFiles('**/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-
- name: Check formatting
run: cargo fmt --check
- name: Run Clippy
run: cargo clippy -p sanctifier-cli -p sanctifier-core --all-targets -- -D warnings
- name: Install cargo-nextest
uses: taiki-e/install-action@nextest
- name: Run tests (JUnit XML)
run: cargo nextest run -p sanctifier-cli -p sanctifier-core --profile ci
- name: Upload test results
if: always()
uses: actions/upload-artifact@v4
with:
name: junit-test-results
path: target/nextest/ci/junit.xml
retention-days: 7
- name: Build release binary
run: cargo build --release -p sanctifier-cli
coverage:
name: Coverage Gate (≥ 80% per crate)
runs-on: ubuntu-latest
# Only enforce on push/PR to main to avoid gating dependabot bumps
if: github.event_name == 'push' || github.event_name == 'pull_request'
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Install stable Rust toolchain
uses: dtolnay/rust-toolchain@stable
- name: Cache cargo registry & build artifacts
uses: actions/cache@v4
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-cov-${{ hashFiles('**/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-cov-
- name: Install cargo-llvm-cov
uses: taiki-e/install-action@cargo-llvm-cov
- name: Collect coverage — sanctifier-core
run: |
cargo llvm-cov --lcov --output-path lcov-core.info \
-p sanctifier-core \
--ignore-filename-regex '(_tests\.rs|/tests/|/benches/)'
- name: Collect coverage — sanctifier-cli
run: |
cargo llvm-cov --lcov --output-path lcov-cli.info \
-p sanctifier-cli \
--ignore-filename-regex '(_tests\.rs|/tests/|/benches/)'
- name: Upload coverage to Codecov (sanctifier-core)
uses: codecov/codecov-action@v5
with:
files: lcov-core.info
flags: sanctifier-core
fail_ci_if_error: true
- name: Upload coverage to Codecov (sanctifier-cli)
uses: codecov/codecov-action@v5
with:
files: lcov-cli.info
flags: sanctifier-cli
fail_ci_if_error: true
sarif-snapshots:
name: SARIF Snapshot Tests
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Install stable Rust toolchain
uses: dtolnay/rust-toolchain@stable
- name: Cache cargo registry & build artifacts
uses: actions/cache@v4
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-snapshots-${{ hashFiles('**/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-snapshots-
- name: Install cargo-insta
run: cargo install cargo-insta --locked
- name: Generate missing snapshots
env:
INSTA_UPDATE: new
run: cargo test --test sarif_snapshots -p sanctifier-core
- name: Verify snapshots are committed and unchanged
run: cargo insta review --no-input --check