fabro/.github/workflows/nightly.yml
Bryan Helmkamp 31fa23eb6a
chore(ci): default workflows to no permissions
Start every workflow with permissions: {} and grant the minimum
required per job, following Astral's defense-in-depth pattern so a
newly added job can't silently inherit repo read access.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-18 01:30:43 -04:00

73 lines
2.3 KiB
YAML

name: Nightly
on:
schedule:
- cron: "0 9 * * *"
workflow_dispatch:
concurrency:
group: nightly-release
cancel-in-progress: false
permissions: {}
jobs:
tag-nightly:
name: Tag nightly
runs-on: ubuntu-latest
environment: nightly
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
steps:
- name: Mint GitHub App token
id: app-token
uses: actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349 # v2.2.2
with:
app-id: ${{ vars.FABRO_RELEASES_APP_ID }}
private-key: ${{ secrets.FABRO_RELEASES_APP_PRIVATE_KEY }}
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0 # full history + tags for nightly probing
persist-credentials: false
- name: Skip if HEAD is already a nightly tag
id: skip
run: |
last_tag=$(git describe --tags --match 'v*-nightly.*' --abbrev=0 2>/dev/null || true)
if [[ -n "$last_tag" ]] && [[ "$(git rev-parse HEAD)" == "$(git rev-parse "$last_tag^{commit}")" ]]; then
echo "HEAD already tagged as $last_tag — nothing to release."
echo "skip=true" >> "$GITHUB_OUTPUT"
fi
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
if: steps.skip.outputs.skip != 'true'
with:
no-cache: true
- name: Install bun deps (for SPA verify)
if: steps.skip.outputs.skip != 'true'
run: bun install
- name: Set up Rust
if: steps.skip.outputs.skip != 'true'
run: |
rustup toolchain install stable --profile minimal --no-self-update
rustup default stable
- uses: taiki-e/install-action@773334c0e05d7e699e4d78234494308223f3a2cf # nextest
if: steps.skip.outputs.skip != 'true'
- name: Release nightly
if: steps.skip.outputs.skip != 'true'
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
git config user.name "fabro-releases[bot]"
git config user.email "fabro-releases[bot]@users.noreply.github.com"
git remote set-url origin \
"https://x-access-token:${GH_TOKEN}@github.com/${GITHUB_REPOSITORY}.git"
bin/dev/release.sh nightly