Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 10 additions & 9 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,12 @@
version: 2
updates:
- package-ecosystem: npm
directory: /
schedule:
interval: weekly

- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
- package-ecosystem: npm
directory: /
open-pull-requests-limit: 0
schedule:
interval: weekly
- package-ecosystem: github-actions
directory: /
open-pull-requests-limit: 0
schedule:
interval: weekly
108 changes: 71 additions & 37 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,42 +1,76 @@
name: CI

on:
push:
branches: [main]
pull_request:

push:
branches: [main]
pull_request:
workflow_dispatch:
permissions:
contents: read

contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# gitleaks scans history; a shallow clone gives it one commit.
fetch-depth: 0
persist-credentials: false

# glib-compile-schemas validates the gschema; it is not a mise tool
# because it must match the GLib the target Shell was built against.
- name: Install GLib schema compiler
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends libglib2.0-bin

- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4

- run: npm ci

# The docs site's suite runs in real browsers.
- name: Install test browsers
run: npx playwright install --with-deps chromium firefox

# The same recipe a developer runs: lint, test, test-docs, security, build.
- run: just ci
checks:
name: checks
runs-on: ubuntu-24.04
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
with:
version: 2026.9.1
- name: Install native test tools
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends gjs gnome-shell libglib2.0-bin librsvg2-common gir1.2-soup-3.0 gir1.2-secret-1 dbus-daemon
- run: npm ci --ignore-scripts
- run: ./node_modules/.bin/playwright install --with-deps chromium firefox
- run: just ci
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: extension-bundle
path: '*.shell-extension.zip'
if-no-files-found: error
retention-days: 90
- uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
with:
path: docs
security:
name: security
uses: $/.github/workflows/security.yml
permissions:
contents: read
security-events: write # Upload CodeQL findings to GitHub code scanning.
actions: read # Inspect workflow runs and download their tested artifacts.
sonar:
name: sonar
uses: $/.github/workflows/sonar.yml
secrets:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
ci:
name: ci
if: always()
needs: [checks, security, sonar]
runs-on: ubuntu-24.04
timeout-minutes: 2
steps:
- name: Require every verification job
env:
CHECKS: ${{ needs.checks.result }}
SECURITY: ${{ needs.security.result }}
SONAR: ${{ needs.sonar.result }}
run: test "$CHECKS" = success && test "$SECURITY" = success && test "$SONAR" = success
docs:
name: docs
needs: ci
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
uses: $/.github/workflows/pages.yml
permissions:
contents: read
actions: read # Inspect workflow runs and download their tested artifacts.
pages: write # Publish the tested documentation artifact to Pages.
id-token: write # Authenticate the Pages deployment with GitHub OIDC.
25 changes: 25 additions & 0 deletions .github/workflows/pages.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
name: Docs
on:
workflow_call:
permissions:
contents: read
concurrency:
group: pages
cancel-in-progress: false
jobs:
deploy:
name: deploy
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
actions: read # Inspect workflow runs and download their tested artifacts.
pages: write # Publish the tested documentation artifact to Pages.
id-token: write # Authenticate the Pages deployment with GitHub OIDC.
environment:
name: github-pages
url: ${{ steps.deploy.outputs.page_url }}
steps:
- uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4
id: deploy
with:
artifact_name: github-pages
151 changes: 71 additions & 80 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,84 +1,75 @@
name: Release

on:
push:
tags: ['v*']

push:
tags: ['v*']
permissions:
contents: read

contents: read
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
release:
runs-on: ubuntu-latest
timeout-minutes: 20
permissions:
contents: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false

# Before anything is built or published: a tag that disagrees with
# the tree ships a release titled v0.2.0 containing a zip that tells
# GNOME it is 0.1.0, and nothing downstream would notice.
- name: Check the tag matches the version in the tree
env:
TAG: ${{ github.ref_name }}
run: |
version="${TAG#v}"
meta="$(jq -r '."version-name"' metadata.json)"
pkg="$(jq -r .version package.json)"
status=0

if [ "$meta" != "$version" ]; then
echo "::error::metadata.json version-name is '$meta', tag is '$version'"
status=1
fi

if [ "$pkg" != "$version" ]; then
echo "::error::package.json version is '$pkg', tag is '$version'"
status=1
fi

exit "$status"

- name: Install GLib schema compiler
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends libglib2.0-bin

- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4
with:
# A release publishes a runtime artifact, so it must not restore a
# cache that a pull request could have poisoned.
cache: false

- run: npm ci

# The docs site's suite runs in real browsers.
- name: Install test browsers
run: npx playwright install --with-deps chromium firefox

# Gate the release on the full suite; never publish an untested build.
- run: just ci

- name: Create the release
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.ref_name }}
run: |
# Derived from metadata.json, like the justfile's, so renaming
# the extension cannot leave this uploading a file that
# `just build` no longer produces.
zip="$(jq -r .uuid metadata.json).shell-extension.zip"

if [ ! -f "$zip" ]; then
echo "::error::just ci did not produce $zip"
exit 1
fi

gh release create "$TAG" \
--title "$TAG" \
--generate-notes \
"$zip"
verify:
name: verify
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: read
actions: read # Inspect workflow runs and download their tested artifacts.
outputs:
run: ${{ steps.verify.outputs.run }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
with:
version: 2026.9.1
cache: false
- name: Verify tag and tested commit
id: verify
env:
TAG: ${{ github.ref_name }}
GH_TOKEN: ${{ github.token }}
REPOSITORY: ${{ github.repository }}
run: |
version="${TAG#v}"
test "$version" = "$(jq -r '."version-name"' metadata.json)"
test "$version" = "$(jq -r .version package.json)"
git merge-base --is-ancestor HEAD origin/main
revision="$(git rev-parse HEAD)"
run="$(gh run list --repo "$REPOSITORY" --workflow ci.yml --branch main --event push --commit "$revision" --status success --limit 1 --json databaseId --jq '.[0].databaseId')"
test -n "$run" && test "$run" != null
echo "run=$run" >> "$GITHUB_OUTPUT"
publish:
name: publish
needs: verify
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: write # Create the release and attach its tested ZIP.
actions: read # Inspect workflow runs and download their tested artifacts.
steps:
- uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
with:
version: 2026.9.1
cache: false
mise_toml: |
[tools]
gh = "2.99.0"
- uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5
with:
name: extension-bundle
run-id: ${{ needs.verify.outputs.run }}
github-token: ${{ github.token }}
path: bundle
- name: Publish the tested artifact
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
TAG: ${{ github.ref_name }}
run: |
shopt -s nullglob
files=(bundle/*.shell-extension.zip)
test "${#files[@]}" -eq 1
gh release create "$TAG" --verify-tag --title "$TAG" --generate-notes "${files[0]}"
Loading
Loading