ceremony-ci-probe/.github/workflows/ci.yml
2026-08-02 20:20:41 +00:00

54 lines
2 KiB
YAML

name: CI
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install shellcheck
run: sudo apt-get update -qq && sudo apt-get install -y -qq shellcheck
- name: Shellcheck
run: bash .github/scripts/shellcheck-all.sh
- name: Install actionlint
env:
ACTIONLINT_VERSION: 1.7.12
run: |
curl -fsSLo actionlint.tar.gz \
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
tar -xzf actionlint.tar.gz actionlint
sudo install actionlint /usr/local/bin/actionlint
- name: Actionlint
run: bash .github/scripts/actionlint-all.sh
- name: Self-ref pin
# The pin rules (issue #9; #1 D3): a stale CEREMONY_SELF_REF fails
# CI here, not a consumer's release.
run: bash .github/scripts/self-ref-check.sh
- name: Tests
env:
# The npm-backed version_write case may skip locally when npm is
# absent; in CI a skip must be a failure, or the case could
# quietly stop running (issue #3's test contract).
CEREMONY_REQUIRE_NPM: 1
# Same contract for the yq-backed labeler.yml parse cases
# (#130): yq is preinstalled on ubuntu-latest, optional locally.
CEREMONY_REQUIRE_YQ: 1
run: bash test/run.sh
# The release exercise (issue #9's scratch caller) on every PR, so the
# parse proof and the merge door's step-replay are standing, reviewable
# evidence — not a dispatch someone must remember to run. PR-ONLY, and
# the gate is load-bearing: this CI also runs on push to main, and a
# workflow_call from THAT context would hand release.yml a genuine
# push+refs/heads/main event — the merge door's exact gate — opening a
# live door from CI. A pull_request event can never satisfy either
# door's `if:`.