ci: pin Protocol verification actions
This commit is contained in:
@@ -20,8 +20,8 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
timeout-minutes: 10
|
timeout-minutes: 10
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v7
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
||||||
- uses: actions/setup-go@v7
|
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
|
||||||
with:
|
with:
|
||||||
go-version: "1.26.5"
|
go-version: "1.26.5"
|
||||||
cache: true
|
cache: true
|
||||||
@@ -44,7 +44,7 @@ jobs:
|
|||||||
runs-on: macos-26
|
runs-on: macos-26
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v7
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
||||||
- name: Assert pinned toolchain
|
- name: Assert pinned toolchain
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.PHONY: verify generate proto-lint proto-breaking source-verify scope-verify conformance frame-verify go-test binding-compile strict-contracts clean-generated
|
.PHONY: verify generate proto-lint proto-breaking source-verify scope-verify ci-verify conformance frame-verify go-test binding-compile strict-contracts clean-generated
|
||||||
|
|
||||||
PYTHON ?= python3
|
PYTHON ?= python3
|
||||||
PROTOC ?= protoc
|
PROTOC ?= protoc
|
||||||
@@ -23,6 +23,9 @@ scope-verify:
|
|||||||
$(PYTHON) -B tools/test_check_scope.py
|
$(PYTHON) -B tools/test_check_scope.py
|
||||||
$(PYTHON) -B tools/check_scope.py
|
$(PYTHON) -B tools/check_scope.py
|
||||||
|
|
||||||
|
ci-verify:
|
||||||
|
$(PYTHON) -B tools/check_ci_actions.py
|
||||||
|
|
||||||
go-test:
|
go-test:
|
||||||
go test ./gen/go/... ./tests/go
|
go test ./gen/go/... ./tests/go
|
||||||
|
|
||||||
@@ -45,4 +48,4 @@ frame-verify:
|
|||||||
clean-generated:
|
clean-generated:
|
||||||
$(PYTHON) tools/generate.py --check
|
$(PYTHON) tools/generate.py --check
|
||||||
|
|
||||||
verify: generate proto-lint proto-breaking source-verify scope-verify go-test binding-compile strict-contracts conformance frame-verify clean-generated
|
verify: generate proto-lint proto-breaking source-verify scope-verify ci-verify go-test binding-compile strict-contracts conformance frame-verify clean-generated
|
||||||
|
|||||||
@@ -0,0 +1,19 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Require immutable commits for third-party Gitea workflow actions."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import pathlib
|
||||||
|
import re
|
||||||
|
|
||||||
|
|
||||||
|
ROOT = pathlib.Path(__file__).resolve().parents[1]
|
||||||
|
USE = re.compile(r"^\s*-\s+uses:\s+([^@\s]+)@([^\s#]+)", re.MULTILINE)
|
||||||
|
|
||||||
|
|
||||||
|
for workflow in sorted((ROOT / ".gitea/workflows").glob("*.y*ml")):
|
||||||
|
for action, revision in USE.findall(workflow.read_text(encoding="utf-8")):
|
||||||
|
if not action.startswith("./") and not re.fullmatch(r"[0-9a-f]{40}", revision):
|
||||||
|
raise SystemExit(f"{workflow.relative_to(ROOT)}: mutable action {action}@{revision}")
|
||||||
|
|
||||||
|
print("Protocol CI action references are immutable")
|
||||||
Reference in New Issue
Block a user