dtg-credentials 0.11.0

Decentralized Trust Graph (DTG) Credentials Library
Documentation
name: CI

# This repository had no automated checks. Two releases' worth of a credential
# library - including `authority::verify_chain`, which is the part that decides
# whether a holder acquired authority they were never granted - merged on local
# runs alone. That is the gap this closes.
#
# Every third-party action is pinned to a full commit SHA, with the release it
# corresponds to in a trailing comment that Dependabot keeps current. A tag or a
# branch can be moved to point at different code; a commit cannot. The Rust
# toolchain comes from the runner's own `rustup` rather than from an action that
# tracks a branch.

on:
  push:
    branches: [main]
  pull_request:

# Nothing here writes to the repository, so no job is given a token that can.
permissions:
  contents: read

env:
  CARGO_TERM_COLOR: always

jobs:
  fmt:
    name: Format
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          persist-credentials: false
      - name: Install Rust toolchain
        run: |
          rustup toolchain install stable --profile minimal --component rustfmt
          rustup default stable
      - run: cargo fmt --all --check

  clippy:
    name: Clippy
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          persist-credentials: false
      - name: Install Rust toolchain
        run: |
          rustup toolchain install stable --profile minimal --component clippy
          rustup default stable
      - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
      # affinidi-tdk (a dev-dependency) reaches the OS keyring, which links
      # dbus and pcsclite. Only the jobs that build dev-dependencies need these
      # — `cargo check` and `cargo package` do not, and stay lean.
      - name: System dependencies
        run: sudo apt-get update && sudo apt-get install -y libpcsclite-dev libdbus-1-dev
      - run: cargo clippy --all-targets --all-features -- -D warnings

  test:
    name: Test
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          persist-credentials: false
      - name: Install Rust toolchain
        run: |
          rustup toolchain install stable --profile minimal
          rustup default stable
      - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
      # affinidi-tdk (a dev-dependency) reaches the OS keyring, which links
      # dbus and pcsclite. Only the jobs that build dev-dependencies need these
      # — `cargo check` and `cargo package` do not, and stay lean.
      - name: System dependencies
        run: sudo apt-get update && sudo apt-get install -y libpcsclite-dev libdbus-1-dev
      - run: cargo test --all-features

  # The signing backend is optional and `default = ["affinidi-signing"]`, so the
  # default build never exercises the feature-off path. A consumer who disables
  # default features is the one who finds out.
  no-default-features:
    name: No default features
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          persist-credentials: false
      - name: Install Rust toolchain
        run: |
          rustup toolchain install stable --profile minimal
          rustup default stable
      - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
      # affinidi-tdk (a dev-dependency) reaches the OS keyring, which links
      # dbus and pcsclite. Only the jobs that build dev-dependencies need these
      # — `cargo check` and `cargo package` do not, and stay lean.
      - name: System dependencies
        run: sudo apt-get update && sudo apt-get install -y libpcsclite-dev libdbus-1-dev
      - run: cargo test --no-default-features

  msrv:
    name: Minimum Supported Rust Version
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          persist-credentials: false
      - name: Install Rust toolchain
        run: |
          rustup toolchain install 1.95.0 --profile minimal
          rustup default 1.95.0
      - run: cargo check --all-features

  # A crate that cannot be packaged cannot be released, and finding that out at
  # tag time means the tag is already wrong. `--locked` is deliberate: it is what
  # the publish job uses, so a lockfile that has drifted fails here first.
  package:
    name: Package
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          persist-credentials: false
      - name: Install Rust toolchain
        run: |
          rustup toolchain install stable --profile minimal
          rustup default stable
      - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
      - run: cargo package --locked