Update Gradle to v9.8.0 #28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Generated by velnor-workflow. Regenerate; do not hand-edit. | ||
|
Check warning on line 1 in .github/workflows/ci-policy.yml
|
||
| name: Velnor workflow policy | ||
| on: | ||
| pull_request_target: | ||
| types: [opened, synchronize, reopened] | ||
| workflow_dispatch: | ||
| concurrency: | ||
| group: policy-${{ github.repository }}-${{ github.event.pull_request.number || github.ref }} | ||
| cancel-in-progress: true | ||
| permissions: | ||
| contents: read | ||
| jobs: | ||
| policy: | ||
| name: Policy | ||
| runs-on: ubuntu-24.04 | ||
| timeout-minutes: 20 | ||
| # Trust invariant: this job runs the base branch's validator against the | ||
| # audited tree under pull_request_target. It holds `contents: read` only, | ||
| # references no secrets, and its checkout persists no credentials, so | ||
| # building and running the tree's declared generator here is no more | ||
| # privileged than the pull_request lanes that already build the tree. | ||
| permissions: | ||
| contents: read | ||
| steps: | ||
| - name: Checkout repository history | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
| with: | ||
| path: policy-checkout | ||
| fetch-depth: 0 | ||
| persist-credentials: false | ||
| - name: Check out audited head | ||
| working-directory: policy-checkout | ||
| env: | ||
| HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }} | ||
| HEAD_REPOSITORY: ${{ github.event.pull_request.head.repo.full_name || github.repository }} | ||
| run: | | ||
| set -euo pipefail | ||
| if ! git cat-file -e "$HEAD_SHA^{commit}" 2>/dev/null; then | ||
| git fetch --no-tags "$GITHUB_SERVER_URL/$HEAD_REPOSITORY" "$HEAD_SHA" | ||
| fi | ||
| git checkout --quiet --detach "$HEAD_SHA" | ||
| - name: Bound the Mr. Boxington store | ||
| shell: bash | ||
| run: echo "MBX_GC_MAX_SIZE=12GiB" >> "$GITHUB_ENV" | ||
| - name: Set up Mr. Boxington | ||
| uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 | ||
| with: | ||
| backend: github | ||
| version: 1.11.1 | ||
| cache-key: velnor-policy-mbx-1.11.1-${{ runner.os }}-${{ runner.arch }}-b9c3156cdb88e63c11b9e595a3e694b02238c09a | ||
| restore-keys: | | ||
| velnor-policy-mbx-1.11.1-${{ runner.os }}-${{ runner.arch }}- | ||
| - name: Install pinned Velnor workflow runtime | ||
| env: | ||
| CARGO_HOME: ${{ runner.temp }}/velnor-workflow-cargo-home | ||
| CARGO_TARGET_DIR: ${{ runner.temp }}/velnor-workflow-cargo-target | ||
| VELNOR_WORKFLOW_INSTALL_DIR: ${{ runner.temp }}/velnor-workflow-install | ||
| VELNOR_WORKFLOW_ROOT: ${{ runner.temp }}/velnor-workflow | ||
| run: | | ||
| set -euo pipefail | ||
| install -d -m 700 \ | ||
| "$CARGO_HOME" \ | ||
| "$CARGO_TARGET_DIR" \ | ||
| "$VELNOR_WORKFLOW_INSTALL_DIR" | ||
| cd "$VELNOR_WORKFLOW_INSTALL_DIR" | ||
| env -u RUSTC_WRAPPER -u SCCACHE_GHA_ENABLED -u CARGO_INCREMENTAL -u RUSTFLAGS -u CARGO_ENCODED_RUSTFLAGS \ | ||
| cargo install \ | ||
| --locked \ | ||
| --git https://github.com/tailrocks/velnor \ | ||
| --rev b9c3156cdb88e63c11b9e595a3e694b02238c09a \ | ||
| --root "$VELNOR_WORKFLOW_ROOT" \ | ||
| velnor-workflow \ | ||
| --bin velnor-workflow | ||
| echo "$VELNOR_WORKFLOW_ROOT/bin" >> "$GITHUB_PATH" | ||
| - name: Resolve required status checks | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| DEFAULT_BRANCH: main | ||
| DECLARED_RULESET_CONTEXTS: DCO,Policy,ci-required | ||
| run: | | ||
| set -euo pipefail | ||
| stderr="$(mktemp)" | ||
| trap 'rm -f "$stderr"' EXIT | ||
| if contexts="$(gh api "repos/$GITHUB_REPOSITORY/rulesets?includes_parents=true" 2>"$stderr" \ | ||
| | jq -r '.[] | select(.target == "branch" and .enforcement == "active") | .id' \ | ||
| | while read -r id; do gh api "repos/$GITHUB_REPOSITORY/rulesets/$id"; done \ | ||
| | jq -r --arg branch "refs/heads/$DEFAULT_BRANCH" 'select(.conditions.ref_name.include | any(. == "~DEFAULT_BRANCH" or . == "~ALL" or . == $branch)) | .rules[] | select(.type == "required_status_checks") | .parameters.required_status_checks[].context' \ | ||
| | sort -u | paste -sd, -)"; then | ||
| : | ||
| elif grep -qE '(HTTP 403|Upgrade to GitHub Team)' "$stderr"; then | ||
| echo "::warning::rulesets API returned 403; falling back to declared contexts [$DECLARED_RULESET_CONTEXTS]" | ||
| contexts="$DECLARED_RULESET_CONTEXTS" | ||
| else | ||
| cat "$stderr" >&2 | ||
| exit 1 | ||
| fi | ||
| echo "RULESET_CONTEXTS=$contexts" >> "$GITHUB_ENV" | ||
| - name: Enforce workflow policy | ||
| env: | ||
| WORKFLOW_ROOT: ${{ github.workspace }}/policy-checkout | ||
| HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }} | ||
| BASE_SHA: ${{ github.event.pull_request.base.sha || github.sha }} | ||
| VELNOR_WORKFLOW_POLICY_REVISION: b9c3156cdb88e63c11b9e595a3e694b02238c09a | ||
| run: | | ||
| set -euo pipefail | ||
| velnor-workflow policy \ | ||
| --workflow-root "$WORKFLOW_ROOT" \ | ||
| --head-sha "$HEAD_SHA" \ | ||
| --base-sha "$BASE_SHA" \ | ||
| --ruleset-contexts "$RULESET_CONTEXTS" | ||
| - name: Set up actionlint | ||
| uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | ||
| with: | ||
| install_args: actionlint@1.7.12 | ||
| cache: false | ||
| - name: Lint caller workflows | ||
| working-directory: policy-checkout | ||
| run: mise exec actionlint@1.7.12 -- actionlint | ||