Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
57 commits
Select commit Hold shift + click to select a range
da12de9
chore(deny): ignore RUSTSEC-2026-0285 until the rustls fix clears the…
prom3theu5 Sep 19, 2026
b369fb6
chore(deny): allow the CC0-1.0 licence
prom3theu5 Sep 19, 2026
2359033
refactor(workspace): turn the root package into a workspace
prom3theu5 Sep 19, 2026
db62b8a
refactor(workspace): move wire types and ids into keryx-core
prom3theu5 Sep 19, 2026
3081054
refactor(workspace): move policy, storage and db into leaf crates
prom3theu5 Sep 19, 2026
75ea80c
refactor(workspace): move render and server into their own crates
prom3theu5 Sep 19, 2026
c179c86
refactor(workspace): move the HTTP client and git provenance into ker…
prom3theu5 Sep 19, 2026
1e2d141
refactor(workspace): point the binary at the crates by name
prom3theu5 Sep 19, 2026
3a9ca92
chore(vet): exempt the crates reqwest 0.13 brings in
prom3theu5 Sep 19, 2026
1b4e74c
chore(deps): bump reqwest to 0.13 on rustls-no-provider with ring
prom3theu5 Sep 19, 2026
2ff5fd9
chore(vet): prune exemptions for crates reqwest 0.12 no longer brings in
prom3theu5 Sep 19, 2026
b9a4960
chore(vet): exempt the OpenDAL and reqsign dependency tree
prom3theu5 Sep 19, 2026
540b21d
chore(deps): add the pinned OpenDAL and reqsign crates behind an s3 f…
prom3theu5 Sep 19, 2026
c4db222
feat(store): add the BlobBackend trait and its OpenDAL backends
prom3theu5 Sep 19, 2026
961f282
test(store): gate on reading a data directory written by 0.5.1
prom3theu5 Sep 19, 2026
7a9cab0
refactor(db): lift the blob write out of record_upload
prom3theu5 Sep 19, 2026
34db0c7
feat(server): store blobs through a pluggable backend chosen at startup
prom3theu5 Sep 19, 2026
a452dbb
feat(cli): add keryx storage migrate and keryx storage gc
prom3theu5 Sep 19, 2026
3e73e77
docs(readme): document blob storage, S3 permissions and migration
prom3theu5 Sep 19, 2026
e785eee
chore(vet): exempt the oci-client and docker_credential dependency tree
prom3theu5 Sep 19, 2026
8fb3f11
chore(deps): add oci-client on ring, with no TLS feature of its own
prom3theu5 Sep 19, 2026
2e38284
feat(share): add keryx-share, draft versions as OCI artifacts
prom3theu5 Sep 19, 2026
dd009a1
feat(client): fetch one version's metadata alongside raw_html
prom3theu5 Sep 19, 2026
97a3c95
feat(cli): add keryx share, pull and inspect
prom3theu5 Sep 19, 2026
d7dd631
docs: document OCI sharing and teach the agent skills the new commands
prom3theu5 Sep 19, 2026
e567336
chore(deps): build stylo from the SimCubeLtd fork with one fix
prom3theu5 Sep 19, 2026
084f489
chore(vet): exempt the SeaORM and sqlx dependency tree
prom3theu5 Sep 19, 2026
0387cdc
chore(deps): add SeaORM 2.0.2 and its migration crate to keryx-db
prom3theu5 Sep 19, 2026
9a1f677
feat(db): add the m0001_baseline migration and SQLite connection setup
prom3theu5 Sep 19, 2026
2c6bd94
feat(db): add SeaORM entities for the five tables
prom3theu5 Sep 19, 2026
cca6c49
feat(db): adopt legacy SQLite databases in place
prom3theu5 Sep 19, 2026
cce42b9
test(db): add the three-level parity gate for legacy databases
prom3theu5 Sep 19, 2026
a7665cf
refactor(db): move the backend-neutral types out of the rusqlite file
prom3theu5 Sep 19, 2026
942b746
feat(db): add the DraftStore trait and its SeaORM implementation
prom3theu5 Sep 19, 2026
6a83a77
feat(server): hold an Arc<dyn DraftStore> instead of a locked connection
prom3theu5 Sep 19, 2026
7704178
refactor(cli): read blob records through DraftStore in the storage co…
prom3theu5 Sep 19, 2026
b02ec12
test(db): pin the rows the old upgrade path produces
prom3theu5 Sep 19, 2026
61ee6bf
refactor(db): delete rusqlite
prom3theu5 Sep 19, 2026
7756e83
chore(vet): prune exemptions for crates rusqlite no longer brings in
prom3theu5 Sep 19, 2026
f661519
feat(db): run on Postgres through --database-url
prom3theu5 Sep 19, 2026
258201b
feat(db): lock the migrator and the draft row on Postgres
prom3theu5 Sep 19, 2026
94d4ffe
ci: run the store suite against Postgres
prom3theu5 Sep 19, 2026
944a7ae
docs(readme): document running on Postgres
prom3theu5 Sep 19, 2026
1454fba
chore(vet): exempt config-rs and the toml crates it brings in
prom3theu5 Sep 19, 2026
ea96044
chore(deps): add config-rs and toml_edit in a new keryx-config crate
prom3theu5 Sep 19, 2026
3537158
feat(config): add the config.toml layer
prom3theu5 Sep 19, 2026
b5f614a
feat(cli): layer config.toml beneath environment variables and flags
prom3theu5 Sep 19, 2026
a00dd20
feat(client): keep the API URL in config.toml and migrate the old JSON
prom3theu5 Sep 19, 2026
af19b4b
docs(readme): document config.toml and the order settings resolve in
prom3theu5 Sep 19, 2026
43f91c7
chore(release): bump version to 0.6.0
prom3theu5 Sep 19, 2026
d28af29
chore(vet): import public audits and prune the exemptions they cover
prom3theu5 Sep 19, 2026
d0ca4db
chore(vet): trust publishers that at least two imported organisations…
prom3theu5 Sep 19, 2026
7a168a3
chore(vet): audit seven small crates this branch added
prom3theu5 Sep 19, 2026
d1c9d31
docs(supply-chain): record the vetting policy and what is knowingly u…
prom3theu5 Sep 19, 2026
2e5d094
fix(server): shut down while a dashboard live-update stream is open
prom3theu5 Sep 19, 2026
f05cdff
ci: pin cargo-vet to 0.10.2, the version that writes imports.lock
prom3theu5 Sep 19, 2026
30fc9ac
ci: build cargo-vet with stable
prom3theu5 Sep 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
63 changes: 62 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,39 @@ jobs:
- name: cargo test
run: cargo test

postgres:
name: Store suite on Postgres
runs-on: ubuntu-latest
env:
CARGO_PROFILE_DEV_DEBUG: 0
# The store's test factory opens a fresh schema here instead of
# in-memory SQLite, so the same suite proves both backends. The plain
# test job above is the SQLite run.
KERYX_TEST_DATABASE_URL: postgres://postgres:keryx@localhost:5432/keryx
services:
postgres:
image: postgres:18.6-alpine
env:
POSTGRES_PASSWORD: keryx
POSTGRES_DB: keryx
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U postgres"
--health-interval 5s
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@v4
- name: Install the pinned toolchain
run: rustup toolchain install
- uses: Swatinem/rust-cache@v2
# keryx-db holds the store suite, including concurrent uploads to one
# draft and concurrent migrators; keryx-server drives the same store
# through every handler.
- name: cargo test (Postgres)
run: cargo test -p keryx-db -p keryx-server

supply-chain:
name: Supply chain (deny + vet)
runs-on: ubuntu-latest
Expand All @@ -53,8 +86,36 @@ jobs:

- uses: taiki-e/install-action@v2
with:
tool: cargo-deny,cargo-vet
tool: cargo-deny
# Pinned, and built from crates.io, on purpose. The newest prebuilt
# cargo-vet release is 0.10.0, which cannot parse the trusted-publisher
# entries that 0.10.2 writes to imports.lock for crates published through
# crates.io Trusted Publishing. CI must run the version that writes the
# files.
#
# Built with stable, not the repository's nightly: cargo-vet's own
# lockfile pins a rustix that turns on internal rustc attributes when it
# sees a nightly compiler, and current nightlies reject them. Only this
# tool build uses stable; Keryx itself stays on the pinned nightly.
# rust-cache keeps ~/.cargo/bin, so this compiles once.
- name: Install cargo-vet
working-directory: ${{ runner.temp }}
run: |
if ! cargo vet --version 2>/dev/null | grep -qx "cargo-vet 0.10.2"; then
rustup toolchain install stable --profile minimal
cargo +stable install cargo-vet --version 0.10.2 --locked
fi
- name: cargo deny
run: cargo deny check
- name: cargo vet
run: cargo vet --locked
# ring is the only crypto backend. aws-lc-rs is a C build and a second
# TLS provider, and several dependencies switch it on by default.
- name: aws-lc-rs must never enter the build
run: |
for crate in aws-lc-rs aws-lc-sys; do
if cargo tree --workspace --all-features --target all -i "$crate" 2>/dev/null; then
echo "::error::$crate entered the dependency graph"
exit 1
fi
done
Loading
Loading