diff --git a/.github/atomic-rules-ref b/.github/atomic-rules-ref new file mode 100644 index 0000000..4ec0452 --- /dev/null +++ b/.github/atomic-rules-ref @@ -0,0 +1 @@ +fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0278dc1..01eafa4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -16,8 +16,6 @@ on: env: CARGO_TERM_COLOR: always FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true - # Update this commit deliberately when the rules repository's atomic suite changes. - RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f permissions: contents: read @@ -330,11 +328,22 @@ jobs: run: python tests\native_capture_contract.py --binary "$env:GITHUB_WORKSPACE\target\release\rustinel.exe" shell: pwsh + - name: Read shared atomic rules pin + id: rules-pin + shell: bash + run: | + ref="$(cat .github/atomic-rules-ref)" + if [[ ! "$ref" =~ ^[0-9a-f]{40}$ ]]; then + echo "Expected a full commit SHA in .github/atomic-rules-ref" >&2 + exit 1 + fi + echo "ref=$ref" >> "$GITHUB_OUTPUT" + - name: Check out pinned rules uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: repository: Karib0u/rustinel-rules - ref: ${{ env.RUSTINEL_RULES_REF }} + ref: ${{ steps.rules-pin.outputs.ref }} path: rustinel-rules persist-credentials: false @@ -484,11 +493,22 @@ jobs: rm -f "$RUNNER_TEMP/cert.p12" "$RUNNER_TEMP/rustinel.provisionprofile" security delete-keychain "$RUNNER_TEMP/rustinel-signing.keychain-db" 2>/dev/null || true + - name: Read shared atomic rules pin + id: rules-pin + shell: bash + run: | + ref="$(cat .github/atomic-rules-ref)" + if [[ ! "$ref" =~ ^[0-9a-f]{40}$ ]]; then + echo "Expected a full commit SHA in .github/atomic-rules-ref" >&2 + exit 1 + fi + echo "ref=$ref" >> "$GITHUB_OUTPUT" + - name: Check out pinned rules uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: repository: Karib0u/rustinel-rules - ref: ${{ env.RUSTINEL_RULES_REF }} + ref: ${{ steps.rules-pin.outputs.ref }} path: rustinel-rules persist-credentials: false diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2117a26..6922348 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -7,8 +7,6 @@ on: env: CARGO_TERM_COLOR: always FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true - # Update this commit deliberately when the rules repository's atomic suite changes. - RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f permissions: contents: read @@ -305,11 +303,22 @@ jobs: name: ${{ matrix.artifact }} path: release-artifact/ + - name: Read shared atomic rules pin + id: rules-pin + shell: bash + run: | + ref="$(cat .github/atomic-rules-ref)" + if [[ ! "$ref" =~ ^[0-9a-f]{40}$ ]]; then + echo "Expected a full commit SHA in .github/atomic-rules-ref" >&2 + exit 1 + fi + echo "ref=$ref" >> "$GITHUB_OUTPUT" + - name: Check out pinned rules uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: repository: Karib0u/rustinel-rules - ref: ${{ env.RUSTINEL_RULES_REF }} + ref: ${{ steps.rules-pin.outputs.ref }} path: rustinel-rules persist-credentials: false