docs(upstream): record the v0.52.2 release (#297) #686
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| merge_group: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| env: | |
| CARGO_TERM_COLOR: always | |
| CARGO_INCREMENTAL: 0 | |
| RUST_BACKTRACE: "1" | |
| SCCACHE_GHA_ENABLED: "true" | |
| RUSTC_WRAPPER: sccache | |
| jobs: | |
| workspace-version: | |
| name: Workspace Version | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 10 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21 | |
| with: | |
| toolchain: 1.98.0 | |
| - name: Require the version gate's parser | |
| run: command -v jq >/dev/null 2>&1 || { echo "jq is required"; exit 1; } | |
| # This is deliberately the workflow's first Cargo subprocess. Every | |
| # Cargo-running job below depends on this job. | |
| - name: Verify workspace version surfaces | |
| run: bash scripts/check-workspace-versions.sh | |
| linux: | |
| name: Linux | |
| needs: workspace-version | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 45 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21 | |
| with: | |
| toolchain: 1.98.0 | |
| components: rustfmt,clippy | |
| - name: Verify workspace version surfaces before Cargo/cache | |
| run: bash scripts/check-workspace-versions.sh | |
| - name: Cache Rust inputs | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }} | |
| cache-targets: false | |
| - name: Configure compiler cache | |
| uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11 | |
| with: | |
| version: "v0.16.0" | |
| - name: Set up Node.js | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: "24" | |
| - name: Install pinned repository tools | |
| run: npm install --global oxfmt@0.64.0 | |
| - name: Install pinned actionlint | |
| run: bash .github/scripts/install-actionlint.sh | |
| - name: Require fixture parsers and shell linter | |
| run: | | |
| set -euo pipefail | |
| command -v shellcheck >/dev/null 2>&1 || { echo "shellcheck is required"; exit 1; } | |
| python3 -c 'import yaml' \ | |
| || python3 -m pip install --break-system-packages PyYAML==6.0.3 \ | |
| || python3 -m pip install PyYAML==6.0.3 | |
| - name: Run the complete local gate | |
| run: make check | |
| windows-clippy: | |
| name: Windows Clippy | |
| needs: workspace-version | |
| runs-on: windows-2025 | |
| timeout-minutes: 35 | |
| env: | |
| CARGO_PROFILE_TEST_DEBUG: 0 | |
| CARGO_PROFILE_TEST_SPLIT_DEBUGINFO: off | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21 | |
| with: | |
| toolchain: 1.98.0 | |
| components: clippy | |
| - name: Verify workspace version surfaces before Cargo/cache | |
| shell: bash | |
| run: bash scripts/check-workspace-versions.sh | |
| - name: Cache Rust inputs | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }} | |
| cache-targets: false | |
| - name: Configure compiler cache | |
| uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11 | |
| with: | |
| version: "v0.16.0" | |
| - name: Clippy | |
| run: cargo clippy --workspace --exclude codegraph-bench --all-targets --locked -- -D warnings | |
| windows-test: | |
| name: Windows Tests | |
| needs: workspace-version | |
| runs-on: windows-2025 | |
| timeout-minutes: 40 | |
| env: | |
| CARGO_PROFILE_TEST_DEBUG: 0 | |
| CARGO_PROFILE_TEST_SPLIT_DEBUGINFO: off | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21 | |
| with: | |
| toolchain: 1.98.0 | |
| - name: Verify workspace version surfaces before Cargo/cache | |
| shell: bash | |
| run: bash scripts/check-workspace-versions.sh | |
| - name: Parse the PowerShell installer | |
| shell: pwsh | |
| run: | | |
| $tokens = $null | |
| $errors = $null | |
| [System.Management.Automation.Language.Parser]::ParseFile( | |
| "scripts/install.ps1", [ref]$tokens, [ref]$errors | |
| ) | Out-Null | |
| if ($errors.Count -ne 0) { | |
| $errors | ForEach-Object { Write-Error $_.ToString() } | |
| exit 1 | |
| } | |
| - name: Cache Rust inputs | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }} | |
| cache-targets: false | |
| - name: Configure compiler cache | |
| uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11 | |
| with: | |
| version: "v0.16.0" | |
| - name: Run native Windows tests | |
| run: cargo test --workspace --exclude codegraph-bench --locked | |
| # A retained SQLite handle makes the replacement rename fail with a | |
| # sharing violation, so this remains an explicit native acceptance gate. | |
| - name: Run long-lived MCP database replacement acceptance | |
| run: cargo test -p codegraph-rs --locked --test batch_m_long_lived_mcp | |
| # FSEvents is the one native-recursive watcher backend no other job runs: | |
| # Linux uses inotify and Windows ReadDirectoryChangesW. This job runs the | |
| # symlink-following scan and watcher tests on macOS (#770). | |
| macos-watcher: | |
| name: macOS Watcher | |
| needs: workspace-version | |
| runs-on: macos-15 | |
| timeout-minutes: 40 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21 | |
| with: | |
| toolchain: 1.98.0 | |
| - name: Verify workspace version surfaces before Cargo/cache | |
| run: bash scripts/check-workspace-versions.sh | |
| - name: Cache Rust inputs | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }} | |
| cache-targets: false | |
| - name: Configure compiler cache | |
| uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11 | |
| with: | |
| version: "v0.16.0" | |
| - name: Run the symlink scan and watcher tests | |
| run: | | |
| cargo test -p codegraph-extract --locked --test scan_symlinks | |
| cargo test -p codegraph-watch --locked symlink | |
| audit: | |
| name: Security Audit | |
| needs: workspace-version | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21 | |
| with: | |
| toolchain: 1.98.0 | |
| - name: Verify workspace version surfaces before Cargo | |
| run: bash scripts/check-workspace-versions.sh | |
| - name: Install cargo-audit | |
| uses: taiki-e/install-action@a2a5f6e99e1a31540baa0468acfa302cff0f359f # v2.86.4 | |
| with: | |
| tool: cargo-audit@0.22.2 | |
| - name: Audit dependencies | |
| run: cargo audit | |
| # Informational by policy: omitted from CI Success and informational in | |
| # codecov.yml. A reporting outage or a below-target percentage cannot block. | |
| coverage: | |
| name: Coverage | |
| needs: workspace-version | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 45 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21 | |
| with: | |
| toolchain: 1.98.0 | |
| components: llvm-tools-preview | |
| - name: Verify workspace version surfaces before Cargo/cache | |
| run: bash scripts/check-workspace-versions.sh | |
| - name: Cache Rust inputs | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }} | |
| cache-targets: false | |
| - name: Install cargo-llvm-cov | |
| uses: taiki-e/install-action@a2a5f6e99e1a31540baa0468acfa302cff0f359f # v2.86.4 | |
| with: | |
| tool: cargo-llvm-cov@0.8.7 | |
| - name: Generate coverage | |
| # Instrumented builds bypass the compiler cache: this job never | |
| # configures sccache, so the workflow-level wrapper must not apply. | |
| env: | |
| RUSTC_WRAPPER: "" | |
| SCCACHE_GHA_ENABLED: "false" | |
| run: make coverage-lcov | |
| - name: Upload coverage to Codecov | |
| uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 | |
| with: | |
| files: lcov.info | |
| fail_ci_if_error: false | |
| token: ${{ secrets.CODECOV_TOKEN }} | |
| ci-success: | |
| name: CI Success | |
| needs: [workspace-version, linux, windows-clippy, windows-test, macos-watcher, audit] | |
| if: always() | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| steps: | |
| - name: Require every CI job to succeed | |
| env: | |
| NEEDS_JSON: ${{ toJSON(needs) }} | |
| run: | | |
| set -euo pipefail | |
| if [ -z "${NEEDS_JSON:-}" ]; then | |
| echo "::error title=CI gate::the needs context was empty; failing closed" | |
| exit 1 | |
| fi | |
| if ! printf '%s' "$NEEDS_JSON" | jq -e 'type == "object" and length > 0' >/dev/null 2>&1; then | |
| echo "::error title=CI gate::the needs context was not a non-empty object; failing closed" | |
| exit 1 | |
| fi | |
| mapfile -t rows < <( | |
| printf '%s' "$NEEDS_JSON" \ | |
| | jq -r 'to_entries | sort_by(.key)[] | "\(.key)\t\(.value.result // "<missing>")"' | |
| ) | |
| ((${#rows[@]} > 0)) || { echo "::error title=CI gate::no required jobs found"; exit 1; } | |
| offenders=0 | |
| for row in "${rows[@]}"; do | |
| job="${row%%$'\t'*}" | |
| result="${row#*$'\t'}" | |
| if [ "$result" = success ]; then | |
| printf ' OK %-20s %s\n' "$job" "$result" | |
| else | |
| printf ' FAIL %-20s %s\n' "$job" "$result" | |
| echo "::error title=CI gate::required job '${job}' concluded '${result}', not 'success'" | |
| offenders=$((offenders + 1)) | |
| fi | |
| done | |
| if [ "$offenders" -ne 0 ]; then | |
| echo "CI failed: ${offenders} of ${#rows[@]} required job(s) did not conclude 'success'." | |
| exit 1 | |
| fi | |
| echo "CI passed: all ${#rows[@]} required job(s) concluded 'success'." |