check / check (push) Waiting to run
upaas uploads its clone as a tar context, which .dockerignore does not filter, so its builds already carried .git; the binary said "unknown" because the VERSION build arg defaulted to "unknown". The old .git/ exclusion kept .git out of a directory-context build only. .dockerignore now lets .git through without its config, which can carry a credential, and leaves out no tracked file (an excluded one would read as deleted and mark the version -dirty). The VERSION build arg loses its "unknown" default, so script/version derives the version inside the build; a given VERSION still takes precedence. The builder stage installs git, trusts the copied checkout whoever owns its files, and fails when its context carries .git and the version still comes out "unknown". The CI fingerprint is now the commit being checked. Model: opus-5-5
38 lines
1.3 KiB
YAML
38 lines
1.3 KiB
YAML
name: check
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- '**'
|
|
|
|
jobs:
|
|
check:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 2024-10-23
|
|
with:
|
|
# The superseded-status step needs history to walk ancestors (it
|
|
# aborts on a shallow clone).
|
|
fetch-depth: 0
|
|
|
|
- name: Mark superseded run statuses
|
|
# Gitea cancels the in-flight run when another commit is pushed to the
|
|
# same branch and records the cancellation as `failure`, so a commit
|
|
# that was never tested reads as a test result. The script rewrites
|
|
# those statuses to say what happened. See its header for why the
|
|
# state stays `failure` and not `skipped`.
|
|
env:
|
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
run: script/ci-mark-superseded
|
|
|
|
- name: Fingerprint the build context
|
|
# Writes the hash of the commit being checked into the context, which
|
|
# invalidates the `COPY . .` layer of both check stages: a commit
|
|
# that was never linted, format-checked, tested and built cannot
|
|
# report success from cache.
|
|
run: git rev-parse HEAD > .ci-fingerprint
|
|
|
|
- name: Build Docker image (runs make check)
|
|
run: script/cibuild
|