mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-08 03:10:26 +00:00
Start every workflow with permissions: {} and grant the minimum
required per job, following Astral's defense-in-depth pattern so a
newly added job can't silently inherit repo read access.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
73 lines
2.3 KiB
YAML
73 lines
2.3 KiB
YAML
name: Nightly
|
|
|
|
on:
|
|
schedule:
|
|
- cron: "0 9 * * *"
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: nightly-release
|
|
cancel-in-progress: false
|
|
|
|
permissions: {}
|
|
|
|
jobs:
|
|
tag-nightly:
|
|
name: Tag nightly
|
|
runs-on: ubuntu-latest
|
|
environment: nightly
|
|
permissions:
|
|
contents: read
|
|
env:
|
|
CARGO_TERM_COLOR: always
|
|
steps:
|
|
- name: Mint GitHub App token
|
|
id: app-token
|
|
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2.2.2
|
|
with:
|
|
app-id: ${{ vars.FABRO_RELEASES_APP_ID }}
|
|
private-key: ${{ secrets.FABRO_RELEASES_APP_PRIVATE_KEY }}
|
|
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
fetch-depth: 0 # full history + tags for nightly probing
|
|
persist-credentials: false
|
|
|
|
- name: Skip if HEAD is already a nightly tag
|
|
id: skip
|
|
run: |
|
|
last_tag=$(git describe --tags --match 'v*-nightly.*' --abbrev=0 2>/dev/null || true)
|
|
if [[ -n "$last_tag" ]] && [[ "$(git rev-parse HEAD)" == "$(git rev-parse "$last_tag^{commit}")" ]]; then
|
|
echo "HEAD already tagged as $last_tag — nothing to release."
|
|
echo "skip=true" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
|
|
if: steps.skip.outputs.skip != 'true'
|
|
with:
|
|
no-cache: true
|
|
|
|
- name: Install bun deps (for SPA verify)
|
|
if: steps.skip.outputs.skip != 'true'
|
|
run: bun install
|
|
|
|
- name: Set up Rust
|
|
if: steps.skip.outputs.skip != 'true'
|
|
run: |
|
|
rustup toolchain install stable --profile minimal --no-self-update
|
|
rustup default stable
|
|
|
|
- uses: taiki-e/install-action@773334c0e05d7e699e4d78234494308223f3a2cf # nextest
|
|
if: steps.skip.outputs.skip != 'true'
|
|
|
|
- name: Release nightly
|
|
if: steps.skip.outputs.skip != 'true'
|
|
env:
|
|
GH_TOKEN: ${{ steps.app-token.outputs.token }}
|
|
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
|
|
run: |
|
|
git config user.name "fabro-releases[bot]"
|
|
git config user.email "fabro-releases[bot]@users.noreply.github.com"
|
|
git remote set-url origin \
|
|
"https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git"
|
|
bin/dev/release.sh nightly
|