Skip to content

chore(fleet): pin the d627735 release and hydrate the full payload #84

chore(fleet): pin the d627735 release and hydrate the full payload

chore(fleet): pin the d627735 release and hydrate the full payload #84

Workflow file for this run

# Baseline CI — seeded once by socket-wheelhouse (template/presets/), then
# repo-owned: edit freely. Runs check + test via the LOCAL composite actions
# under .github/actions/fleet/ (cascade-updated), referenced by ./ path — no
# cross-repo reusable workflow, no first-party `uses:@sha`. Add repo-specific
# jobs anywhere under `jobs:`.
name: ⚡ CI
on:
push:
branches: [main]
tags: ['*']
pull_request:
branches: [main]
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
# Fleet no-phone-home posture: CI runners don't source the shell-rc that dev
# machines get from setup-security-tools, so set every FLEET_ENV knob
# workflow-level or the telemetry-env-is-disabled +
# package-manager-auto-update-is-disabled gates (under `check --all`) fail.
# Lockstep source: .claude/hooks/fleet/_shared/fleet-env.mts (FLEET_ENV) —
# the telemetry-env-is-disabled check asserts each knob at CI runtime.
env:
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC: '1'
COREPACK_ENABLE_PROJECT_SPEC: '0'
DISABLE_TELEMETRY: '1'
DO_NOT_TRACK: '1'
# Markdown conformance gate (markdownlint-cli2 + the socket-* GFM rules)
# runs inside `pnpm run lint` when set. Flipped on 2026-07-12 after the
# fleet-wide burn-down took every member to zero findings.
LINT_MARKDOWN: '1'
NO_UPDATE_NOTIFIER: '1'
OTEL_SDK_DISABLED: 'true'
jobs:
# First step of every job is an inline git-fetch bootstrap (no third-party
# actions/checkout) — a job's FIRST step can't call the local
# `./.github/actions/fleet/checkout` composite, since nothing is checked out
# yet for GitHub to resolve `./.github/actions/*` from. It shallow-fetches the
# workspace so those composites resolve; setup-and-install then re-runs the
# checkout composite — full history (fetch-depth 0) in the check job, since
# the commit-history checks it runs (AI-attribution, release-boundary) read
# the default branch's history and refuse a shallow clone rather than
# false-green; the test matrix stays at the default depth (25 — covers CI's
# other git operations) and runs the zizmor Actions audit (its own
# `strategy.job-total < 2` skip runs it in the non-matrix check job, skips it
# in the test matrix).
check:
name: 🔎 Check
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Bootstrap checkout
shell: bash
env:
# Route context through env (no ${{ }} in the shell body —
# zizmor expression-injection). Token authorizes the fetch inline and
# is never persisted to .git/config.
GITHUB_TOKEN: ${{ github.token }}
SERVER_URL: ${{ github.server_url }}
REPOSITORY: ${{ github.repository }}
TRIGGER_REF: ${{ github.ref }}
run: |
set -euo pipefail
git init -q
git config --local advice.detachedHead false
git remote remove origin 2>/dev/null || true
git remote add origin "${SERVER_URL}/${REPOSITORY}"
FETCH_ARGS=(--no-tags --prune --depth 1 origin "${TRIGGER_REF}")
if [ -n "${GITHUB_TOKEN}" ]; then
AUTH_B64="$(printf 'x-access-token:%s' "${GITHUB_TOKEN}" | base64 | tr -d '\n')"
git -c "http.${SERVER_URL}/.extraheader=AUTHORIZATION: basic ${AUTH_B64}" fetch "${FETCH_ARGS[@]}"
else
git fetch "${FETCH_ARGS[@]}"
fi
git checkout -q --detach FETCH_HEAD
- uses: ./.github/actions/fleet/setup-and-install
with:
# Full history: the commit-history checks (AI-attribution,
# release-boundary) read the default branch's history and refuse a
# shallow clone rather than false-green.
checkout-fetch-depth: '0'
socket-api-token: ${{ secrets.SOCKET_API_TOKEN_FOR_CLI_AND_SFW }}
- uses: ./.github/actions/fleet/run-script
with:
main-script: pnpm run check --all
test:
name: 🧪 Test
strategy:
fail-fast: false
max-parallel: 4
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
timeout-minutes: 15
steps:
- name: Bootstrap checkout
shell: bash
env:
# Route context through env (no ${{ }} in the shell body —
# zizmor expression-injection). Token authorizes the fetch inline and
# is never persisted to .git/config.
GITHUB_TOKEN: ${{ github.token }}
SERVER_URL: ${{ github.server_url }}
REPOSITORY: ${{ github.repository }}
TRIGGER_REF: ${{ github.ref }}
run: |
set -euo pipefail
git init -q
git config --local advice.detachedHead false
git remote remove origin 2>/dev/null || true
git remote add origin "${SERVER_URL}/${REPOSITORY}"
FETCH_ARGS=(--no-tags --prune --depth 1 origin "${TRIGGER_REF}")
if [ -n "${GITHUB_TOKEN}" ]; then
AUTH_B64="$(printf 'x-access-token:%s' "${GITHUB_TOKEN}" | base64 | tr -d '\n')"
git -c "http.${SERVER_URL}/.extraheader=AUTHORIZATION: basic ${AUTH_B64}" fetch "${FETCH_ARGS[@]}"
else
git fetch "${FETCH_ARGS[@]}"
fi
git checkout -q --detach FETCH_HEAD
- uses: ./.github/actions/fleet/setup-and-install
with:
socket-api-token: ${{ secrets.SOCKET_API_TOKEN_FOR_CLI_AND_SFW }}
- uses: ./.github/actions/fleet/run-script
env:
# Authenticate build-time GitHub API reads (release listings,
# prebuilt-artifact downloads). Unauthenticated calls share the
# hosted runner's IP-scoped rate limit and 403 under load.
GH_TOKEN: ${{ github.token }}
with:
setup-script: pnpm run build
main-script: pnpm run test --all