Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
59 changes: 55 additions & 4 deletions .github/workflows/release-please.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,20 @@
name: Release Please

on:
# Fires when a human merges the platform-managed release PR into main
# (the PR's base, so its diff shows the full pending release). Regenerations and
# custom-code pushes only touch scalar-next and never run this workflow.
# A release is cut when a human merges the platform-managed release PR into
# main (the PR's base, so its diff shows the full pending release).
# Every other push here runs release-please as well — commits written straight to
# this branch included — and cuts nothing, there being no release commit at the tip.
push:
branches:
- main
# The Scalar platform pushes these workflow files straight to main to keep them
# current between releases; that is bookkeeping, never a release. Running anyway is worse
# than pointless on a branch that has not been handed a .release-please-manifest.json yet —
# release-please fails the run outright when it cannot read one. A release commit always
# rewrites the manifest and the changelog, so this filter can never swallow one.
paths-ignore:
- '.github/workflows/**'
# Manual fallback only; nothing in the automated chain depends on dispatch.
workflow_dispatch:

Expand Down Expand Up @@ -35,7 +43,7 @@ jobs:
# credential (so their CI runs without manual approval); this workflow only
# cuts the tag + GitHub Release once a release PR is merged.
skip-github-pull-request: true
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
if: ${{ steps.release.outputs.release_created == 'true' }}
with:
fetch-depth: 0
Expand All @@ -55,3 +63,46 @@ jobs:
git checkout -B scalar-next origin/scalar-next
git merge --no-edit -m "Sync release ${{ steps.release.outputs.tag_name }} back to scalar-next" "${{ steps.release.outputs.sha }}"
git push origin scalar-next
publish:
needs: release-please
# `!cancelled()` keeps publishing even when the back-sync to the integration branch
# failed: a raced integration branch must not block the release from reaching its
# registry.
if: ${{ !cancelled() && needs.release-please.outputs.release_created == 'true' }}
runs-on: ubuntu-latest
# Job-level permissions replace the workflow's release-cutting grants with the publish
# floor. OIDC trusted publishing verifies this run's claims, which name this workflow
# file — register release-please.yml as the trusted publisher on the registry.
permissions:
contents: read
id-token: write
packages: write
env:
VERSIONING_POLICY: manual
steps:
# Publishing runs inline — a top-level job of this same run — rather than dispatching
# sdk-release.yml: workflow_dispatch resolves the target workflow on the repository's
# default branch only, so a dispatch would 404 whenever the release line is any other
# branch, while OIDC trusted publishing accepts this job because it stays top-level
# (never a reusable-workflow call). The release-please job cut the tag earlier in this
# run; checking it out publishes exactly the released commit, not the branch head that
# triggered the workflow.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ needs.release-please.outputs.tag_name }}
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
toolchain: stable
- run: cargo build --all-features
- uses: rust-lang/crates-io-auth-action@c6f97d42243bad5fab37ca0427f495c86d5b1a18 # v1.0.5
id: crates-auth
- name: Publish to crates.io
run: |
VERSION="$(sed -n 's/^version = "\(.*\)"$/\1/p' Cargo.toml | head -n1)"
if curl -sf -A "scalar-sdk-release" "https://crates.io/api/v1/crates/profound/${VERSION}" -o /dev/null; then
echo "profound@${VERSION} already on crates.io, skipping"
else
cargo publish
fi
env:
CARGO_REGISTRY_TOKEN: ${{ steps.crates-auth.outputs.token }}
4 changes: 2 additions & 2 deletions .github/workflows/release-title-edit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ jobs:
&& startsWith(github.event.pull_request.title, 'release: ') }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# The version committed on the PR head is what merging would actually release.
ref: ${{ github.event.pull_request.head.sha }}
Expand Down Expand Up @@ -108,7 +108,7 @@ jobs:
permissions:
contents: write
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# The PR head, so the version the pull request currently carries can be read before
# deciding whether anything needs to change.
Expand Down
85 changes: 12 additions & 73 deletions .github/workflows/sdk-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,84 +11,23 @@ permissions:
contents: read

jobs:
# Lint gate: formatting plus clippy with warnings denied, over every target
# and feature — the same bar the generator holds its own baselines to, so a
# generated-code lint regression fails here instead of in a consumer's tree.
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
toolchain: stable
components: rustfmt, clippy
- run: cargo fmt --check
- run: cargo clippy --all-targets --all-features -- -D warnings

# One verification job, matching every other target's generated CI: build the crate, then hold it
# to the toolchain's own checks. `--all-features` is load-bearing rather than cosmetic — the mock
# tests declare `required-features = ["mock", "tokio"]` so a bare `cargo test` would silently skip
# them, and the feature-gated surfaces (multipart, websocket) only compile — and only have their
# doctests collected — with their features on.
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
toolchain: stable
components: rustfmt, clippy
- run: cargo build --all-features

# Runs the generated mock round-trips, the in-crate unit tests, and every
# doctest. `--all-features` is load-bearing rather than cosmetic: the mock
# tests declare `required-features = ["mock", "tokio"]` so a bare `cargo test`
# would silently skip them, and the feature-gated surfaces (multipart,
# websocket) only compile — and only have their doctests collected — with
# their features on.
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
toolchain: stable
- run: cargo clippy --all-targets --all-features -- -D warnings
- run: cargo test --all-features

# Proves the BYO-transport story: the library must compile with reqwest
# absent from the tree, and the hyper example (via --all-targets) must build
# against that reqwest-free surface.
no-default-features:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
toolchain: stable
- run: cargo check --no-default-features
- run: cargo check --no-default-features --features tokio --all-targets

# Proves the MSRV floor declared as `rust-version` in Cargo.toml is real.
# `--locked` is the whole point: it forbids re-resolving, so the check runs
# against the exact versions the committed Cargo.lock pins. Without it a
# fresh resolve can pull a newer transitive dependency that raised its own
# floor, and the job would fail for a reason this crate never chose. The
# bootstrap line keeps the job green in a repo that has not committed a
# lockfile yet (the generator cannot emit one — it does not resolve
# dependencies); once Cargo.lock is committed the `test -f` short-circuits.
msrv:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
toolchain: 1.85.0
- run: test -f Cargo.lock || cargo generate-lockfile
- run: cargo check --locked --all-targets --all-features

# Dependency audit against `deny.toml`: RustSec advisories (vulnerable,
# unmaintained, unsound, yanked) and the license allow-list. Scoped to those
# two checks because they are the two `deny.toml` configures; `bans` and
# `sources` are left to the consumer to opt into.
deny:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1
with:
command: check
command-arguments: advisories licenses
# Verification only, never auto-fix: the SDK is generated rustfmt-clean against the committed
# `rustfmt.toml`, so a diff here means either hand-edited custom code or a regenerate that was
# not committed. Auto-fixing would make the pushed bytes differ from generator output.
- run: cargo fmt --check
41 changes: 41 additions & 0 deletions .github/workflows/sdk-release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
name: Rust SDK Release

on:
# Manual re-publish only: the automated publish for each release runs as the `publish` job
# inside release-please.yml, in the same run that cuts the tag (dispatching a workflow here
# instead would resolve it on the repository's default branch only, which breaks releasing
# from any other release line). Dispatch this workflow at an existing release tag to re-run
# a failed or skipped publish. A dispatched run is top-level, so OIDC trusted-publisher
# claims name this file; register it as an additional trusted publisher only when manual
# re-publishes are used. Never add a workflow_call trigger here — registries reject
# publishes from called (reusable) workflows.
workflow_dispatch:

permissions:
contents: read
id-token: write
packages: write

jobs:
release:
runs-on: ubuntu-latest
env:
VERSIONING_POLICY: manual
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
with:
toolchain: stable
- run: cargo build --all-features
- uses: rust-lang/crates-io-auth-action@c6f97d42243bad5fab37ca0427f495c86d5b1a18 # v1.0.5
id: crates-auth
- name: Publish to crates.io
run: |
VERSION="$(sed -n 's/^version = "\(.*\)"$/\1/p' Cargo.toml | head -n1)"
if curl -sf -A "scalar-sdk-release" "https://crates.io/api/v1/crates/profound/${VERSION}" -o /dev/null; then
echo "profound@${VERSION} already on crates.io, skipping"
else
cargo publish
fi
env:
CARGO_REGISTRY_TOKEN: ${{ steps.crates-auth.outputs.token }}
2 changes: 1 addition & 1 deletion .release-please-manifest.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
{
".": "0.1.0"
".": "0.1.1"
}
Loading
Loading