Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/atomic-rules-ref
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f
28 changes: 24 additions & 4 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,6 @@ on:
env:
CARGO_TERM_COLOR: always
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
# Update this commit deliberately when the rules repository's atomic suite changes.
RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f

permissions:
contents: read
Expand Down Expand Up @@ -330,11 +328,22 @@ jobs:
run: python tests\native_capture_contract.py --binary "$env:GITHUB_WORKSPACE\target\release\rustinel.exe"
shell: pwsh

- name: Read shared atomic rules pin
id: rules-pin
shell: bash
run: |
ref="$(cat .github/atomic-rules-ref)"
if [[ ! "$ref" =~ ^[0-9a-f]{40}$ ]]; then
echo "Expected a full commit SHA in .github/atomic-rules-ref" >&2
exit 1
fi
echo "ref=$ref" >> "$GITHUB_OUTPUT"

- name: Check out pinned rules
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
repository: Karib0u/rustinel-rules
ref: ${{ env.RUSTINEL_RULES_REF }}
ref: ${{ steps.rules-pin.outputs.ref }}
path: rustinel-rules
persist-credentials: false

Expand Down Expand Up @@ -484,11 +493,22 @@ jobs:
rm -f "$RUNNER_TEMP/cert.p12" "$RUNNER_TEMP/rustinel.provisionprofile"
security delete-keychain "$RUNNER_TEMP/rustinel-signing.keychain-db" 2>/dev/null || true

- name: Read shared atomic rules pin
id: rules-pin
shell: bash
run: |
ref="$(cat .github/atomic-rules-ref)"
if [[ ! "$ref" =~ ^[0-9a-f]{40}$ ]]; then
echo "Expected a full commit SHA in .github/atomic-rules-ref" >&2
exit 1
fi
echo "ref=$ref" >> "$GITHUB_OUTPUT"

- name: Check out pinned rules
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
repository: Karib0u/rustinel-rules
ref: ${{ env.RUSTINEL_RULES_REF }}
ref: ${{ steps.rules-pin.outputs.ref }}
path: rustinel-rules
persist-credentials: false

Expand Down
15 changes: 12 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,6 @@ on:
env:
CARGO_TERM_COLOR: always
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
# Update this commit deliberately when the rules repository's atomic suite changes.
RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f

permissions:
contents: read
Expand Down Expand Up @@ -305,11 +303,22 @@ jobs:
name: ${{ matrix.artifact }}
path: release-artifact/

- name: Read shared atomic rules pin
id: rules-pin
shell: bash
run: |
ref="$(cat .github/atomic-rules-ref)"
if [[ ! "$ref" =~ ^[0-9a-f]{40}$ ]]; then
echo "Expected a full commit SHA in .github/atomic-rules-ref" >&2
exit 1
fi
echo "ref=$ref" >> "$GITHUB_OUTPUT"

- name: Check out pinned rules
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
repository: Karib0u/rustinel-rules
ref: ${{ env.RUSTINEL_RULES_REF }}
ref: ${{ steps.rules-pin.outputs.ref }}
path: rustinel-rules
persist-credentials: false

Expand Down
Loading