Skip to content

chore(deps): update rust crate tokio to v1.53.2 #599

chore(deps): update rust crate tokio to v1.53.2

chore(deps): update rust crate tokio to v1.53.2 #599

Workflow file for this run

name: SonarQube
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
jobs:
version:
name: Resolve latest release tag
runs-on: ubuntu-latest
outputs:
version: ${{ steps.tag.outputs.version }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
fetch-depth: 0
- id: tag
run: |
TAG=$(git tag -l 'v[0-9]*.[0-9]*.[0-9]*' --sort=-v:refname | head -n1)
VERSION="${TAG#v}"
echo "version=${VERSION:-0.0.0}" >> "$GITHUB_OUTPUT"
coverage:
name: Coverage
runs-on: ubuntu-latest
services:
postgres:
image: postgres:17-alpine
env:
POSTGRES_USER: stashden
POSTGRES_PASSWORD: stashden
POSTGRES_DB: stashden
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U stashden"
--health-interval 5s
--health-timeout 3s
--health-retries 12
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
- uses: taiki-e/install-action@v2
with:
tool: cargo-tarpaulin
# stashden-app is excluded: it has no tests, and building it would need
# both the webview toolchain and a built web/dist for generate_context!.
#
# The llvm engine rather than the default ptrace one, which segfaults on a test binary that
# spawns blocking threads. Thumbnail decoding runs off the async runtime on purpose, so the
# coverage tool is what has to give.
#
# --timeout because 0.37.4 made the llvm engine honour it, and its default of 60 seconds is
# per test binary rather than per test. Instrumented, the database suites go past that:
# attempts takes 81s on the runner and dav 56s, each test creating a database, running the
# migrations, and hashing with Argon2id where a login is involved. 600 leaves room for a
# slower runner without letting a hung run sit there.
- run: cargo tarpaulin --workspace --exclude stashden-app --engine llvm --out xml --skip-clean --timeout 600
env:
DATABASE_URL: postgres://stashden:stashden@localhost:5432/stashden
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: coverage-cobertura
path: cobertura.xml
retention-days: 1
scan:
needs: [version, coverage]
# reusable-sonarqube-scan declares `pull-requests: write` to post the diff
# on a pull request. A called workflow cannot get more than its caller
# grants, and permissions are checked before any job runs.
permissions:
contents: read
pull-requests: write
uses: FerrLabs/.github/.github/workflows/reusable-sonarqube-scan.yml@dc37316d0b31cb7a47455f2933202533f9c909bd # main
with:
runner: ubuntu-latest
project-key: RoxyCloud
coverage-artifact: coverage-cobertura
args: >-
-Dsonar.projectVersion=${{ needs.version.outputs.version }}
-Dsonar.rust.cobertura.reportPaths=.sonarcov/cobertura.xml
secrets: inherit