Repository navigation
33 lines (30 loc) · 1.48 KB
/
Copy pathci.yml
File metadata and controls
33 lines (30 loc) · 1.48 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
jobs:
# fmt · clippy · test (3 OS) · MSRV · cargo-deny · cargo-vet · secret scan ·
# fuzz build-check · rustdoc · 100% per-line coverage · path-dep gate.
#
# No inputs. The old `coverage` job enforced 100% per-line at
# `--all-features`, failing on any `DA:n,0` that did not carry
# `// cov:unreachable` — exactly the shared workflow's default gate. Since the
# ADR-0008 split this is a THREE-crate workspace (shellitem facade,
# shellitem-core reader, shellitem-forensic analyzer); `--workspace` is what
# makes the gate see all three, and `--lib` would silently miss the
# analyzer's integration tests. The one existing marker carries a reason, so
# the default `require-exemption-reason: true` holds. MSRV is read from
# rust-version, which is what the old `check-msrv` job pinned by hand.
#
# The old gate also skipped paths containing `/tests/` and `/fuzz/`. Not
# carried across as an input: `coverage-ignore-regex` is interpolated
# UNQUOTED into the coverage job's shell, so the `(tests|fuzz)` alternation
# needed to express it would abort the job with a bash syntax error. It is a
# no-op in practice — the fuzz crate is outside the workspace so llvm-cov
# never reports it, and test code executes during the run it is measured by.
ci:
uses: SecurityRonin/fleet-ci/.github/workflows/rust-ci.yml@85c7263e5e1a25a090f602419ac27f87aeb1d1e3