Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
15 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 48 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
version: 2
updates:
- package-ecosystem: cargo
directory: "/"
schedule:
interval: weekly
open-pull-requests-limit: 10
groups:
tokio-ecosystem:
patterns:
- "tokio*"
- "hyper*"
- "axum*"
- "tower*"
serialization:
patterns:
- "serde*"
- "prost*"
wasm:
patterns:
- "wasmtime*"
- "wit-*"
- "wasm-*"
- "cargo-component*"
everything-else:
patterns:
- "*"
exclude-patterns:
- "tokio*"
- "hyper*"
- "axum*"
- "tower*"
- "serde*"
- "prost*"
- "wasmtime*"
- "wit-*"
- "wasm-*"
- "cargo-component*"

- package-ecosystem: github-actions
directory: "/"
schedule:
interval: weekly
open-pull-requests-limit: 5
groups:
actions:
patterns:
- "*"
5 changes: 3 additions & 2 deletions .github/workflows/claude-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,12 +20,13 @@ jobs:
if: contains(github.event.pull_request.labels.*.name, 'staging-promotion')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
fetch-depth: 0
persist-credentials: false

- name: Run Claude Code review
uses: anthropics/claude-code-action@v1
uses: anthropics/claude-code-action@1eddb334cfa79fdb21ecbe2180ca1a016e8e7d47 # v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
allowed_bots: "ironclaw-ci[bot]"
Expand Down
36 changes: 24 additions & 12 deletions .github/workflows/code_style.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,15 +2,20 @@ name: Code Style
on:
pull_request:

permissions:
contents: read

jobs:
format:
name: Formatting
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- name: Install Rust
uses: dtolnay/rust-toolchain@stable
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
components: rustfmt
- name: Check formatting
Expand All @@ -21,9 +26,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- name: Run cargo deny
uses: EmbarkStudios/cargo-deny-action@v2
uses: EmbarkStudios/cargo-deny-action@3fd3802e88374d3fe9159b834c7714ec57d6c979 # v2

clippy:
name: Clippy (${{ matrix.name }})
Expand All @@ -40,12 +47,14 @@ jobs:
flags: "--no-default-features --features libsql"
steps:
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- name: Install Rust
uses: dtolnay/rust-toolchain@stable
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
components: clippy
- uses: Swatinem/rust-cache@v2
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
key: clippy-${{ matrix.name }}
- name: Check lints
Expand All @@ -67,12 +76,14 @@ jobs:
flags: "--no-default-features --features libsql"
steps:
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false
- name: Install Rust
uses: dtolnay/rust-toolchain@stable
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
components: clippy
- uses: Swatinem/rust-cache@v2
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
key: clippy-windows-${{ matrix.name }}
- name: Check lints
Expand All @@ -83,10 +94,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
fetch-depth: 0
- uses: actions/setup-python@v5
persist-credentials: false
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
with:
python-version: "3.12"
- name: Check for .unwrap(), .expect(), assert!() in production code
Expand Down
35 changes: 22 additions & 13 deletions .github/workflows/coverage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,13 +32,15 @@ on:
branches: [main]

permissions:
id-token: write
contents: read

jobs:
coverage:
name: Coverage (${{ matrix.name }})
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
strategy:
fail-fast: false
matrix:
Expand Down Expand Up @@ -67,19 +69,21 @@ jobs:
--health-timeout 5s
--health-retries 5
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false

- uses: dtolnay/rust-toolchain@stable
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
components: llvm-tools-preview
targets: wasm32-wasip2

- uses: Swatinem/rust-cache@v2
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
key: coverage-${{ matrix.name }}

- name: Install cargo-llvm-cov
uses: taiki-e/install-action@cargo-llvm-cov
uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # cargo-llvm-cov

- name: Install cargo-component
run: |
Expand Down Expand Up @@ -113,7 +117,7 @@ jobs:
run: cargo llvm-cov ${{ matrix.flags }} --workspace --lcov --output-path lcov.info

- name: Upload to Codecov
uses: codecov/codecov-action@v5
uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe # v5
with:
files: lcov.info
flags: ${{ matrix.name }}
Expand All @@ -125,20 +129,25 @@ jobs:
name: E2E Coverage
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
id-token: write
contents: read
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
persist-credentials: false

- uses: dtolnay/rust-toolchain@stable
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
components: llvm-tools-preview
targets: wasm32-wasip2

- uses: Swatinem/rust-cache@v2
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
key: e2e-coverage

- name: Install cargo-llvm-cov
uses: taiki-e/install-action@cargo-llvm-cov
uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # cargo-llvm-cov

- name: Install cargo-component
run: |
Expand All @@ -162,7 +171,7 @@ jobs:
- name: Build instrumented binary
run: cargo build --no-default-features --features libsql

- uses: actions/setup-python@v5
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
with:
python-version: "3.12"

Expand Down Expand Up @@ -197,7 +206,7 @@ jobs:

- name: Upload to Codecov
if: always()
uses: codecov/codecov-action@v5
uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe # v5
with:
files: e2e-coverage.info
flags: e2e
Expand All @@ -207,7 +216,7 @@ jobs:

- name: Upload screenshots on failure
if: failure()
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: e2e-screenshots
path: tests/e2e/screenshots/
Expand Down
50 changes: 27 additions & 23 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,9 +35,10 @@ jobs:
actions: write
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: ${{ github.event_name == 'schedule' && 'staging' || '' }}
persist-credentials: false

- name: Extract version from Cargo.toml
id: version
Expand All @@ -48,50 +49,53 @@ jobs:

- name: Determine tags
id: tags
env:
VERSION: ${{ steps.version.outputs.version }}
EVENT_NAME: ${{ github.event_name }}
INPUT_TAG: ${{ inputs.tag }}
run: |
VERSION="${{ steps.version.outputs.version }}"
SHA="sha-${GITHUB_SHA::7}"
echo "sha_tag=${SHA}" >> "$GITHUB_OUTPUT"

if [[ "${{ github.event_name }}" == "workflow_call" ]]; then
if [[ "${EVENT_NAME}" == "workflow_call" ]]; then
# Release: :version + :latest + :sha-xxx
TAGS="${{ env.IMAGE_NAME }}:${VERSION}"
TAGS="${TAGS},${{ env.IMAGE_NAME }}:latest"
TAGS="${TAGS},${{ env.IMAGE_NAME }}:${SHA}"
WORKER_TAGS="${{ env.WORKER_IMAGE_NAME }}:${VERSION}"
WORKER_TAGS="${WORKER_TAGS},${{ env.WORKER_IMAGE_NAME }}:latest"
WORKER_TAGS="${WORKER_TAGS},${{ env.WORKER_IMAGE_NAME }}:${SHA}"
elif [[ "${{ github.event_name }}" == "schedule" ]]; then
TAGS="${IMAGE_NAME}:${VERSION}"
TAGS="${TAGS},${IMAGE_NAME}:latest"
TAGS="${TAGS},${IMAGE_NAME}:${SHA}"
WORKER_TAGS="${WORKER_IMAGE_NAME}:${VERSION}"
WORKER_TAGS="${WORKER_TAGS},${WORKER_IMAGE_NAME}:latest"
WORKER_TAGS="${WORKER_TAGS},${WORKER_IMAGE_NAME}:${SHA}"
elif [[ "${EVENT_NAME}" == "schedule" ]]; then
# Daily staging: :staging + :sha-xxx
TAGS="${{ env.IMAGE_NAME }}:staging"
TAGS="${TAGS},${{ env.IMAGE_NAME }}:${SHA}"
WORKER_TAGS="${{ env.WORKER_IMAGE_NAME }}:staging"
WORKER_TAGS="${WORKER_TAGS},${{ env.WORKER_IMAGE_NAME }}:${SHA}"
TAGS="${IMAGE_NAME}:staging"
TAGS="${TAGS},${IMAGE_NAME}:${SHA}"
WORKER_TAGS="${WORKER_IMAGE_NAME}:staging"
WORKER_TAGS="${WORKER_TAGS},${WORKER_IMAGE_NAME}:${SHA}"
else
# Manual dispatch: :sha-xxx only
TAGS="${{ env.IMAGE_NAME }}:${SHA}"
WORKER_TAGS="${{ env.WORKER_IMAGE_NAME }}:${SHA}"
TAGS="${IMAGE_NAME}:${SHA}"
WORKER_TAGS="${WORKER_IMAGE_NAME}:${SHA}"
fi

# Manual override adds an extra tag (e.g. "staging")
if [[ -n "${{ inputs.tag }}" ]]; then
TAGS="${TAGS},${{ env.IMAGE_NAME }}:${{ inputs.tag }}"
WORKER_TAGS="${WORKER_TAGS},${{ env.WORKER_IMAGE_NAME }}:${{ inputs.tag }}"
if [[ -n "${INPUT_TAG}" ]]; then
TAGS="${TAGS},${IMAGE_NAME}:${INPUT_TAG}"
WORKER_TAGS="${WORKER_TAGS},${WORKER_IMAGE_NAME}:${INPUT_TAG}"
fi
echo "tags=${TAGS}" >> "$GITHUB_OUTPUT"
echo "worker_tags=${WORKER_TAGS}" >> "$GITHUB_OUTPUT"

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3

- name: Log in to Docker Hub
uses: docker/login-action@v3
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
with:
username: ${{ vars.DOCKER_REGISTRY_USER }}
password: ${{ secrets.DOCKER_REGISTRY_TOKEN }}

- name: Build and push (ironclaw)
uses: docker/build-push-action@v6
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
context: .
push: true
Expand All @@ -101,7 +105,7 @@ jobs:
cache-to: type=gha,mode=max

- name: Build and push (ironclaw-worker)
uses: docker/build-push-action@v6
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
context: .
file: Dockerfile.worker
Expand Down
Loading
Loading