name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_call:
inputs:
ref:
type: string
required: false
env:
CARGO_TERM_COLOR: always
permissions: {}
jobs:
lint:
name: Lint
runs-on: ubuntu-latest
env:
NODE_EXTRA_CA_CERTS: /etc/ssl/certs/ca-certificates.crt
permissions:
contents: read
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with:
ref: ${{ inputs.ref || '' }}
persist-credentials: false
- uses: tempoxyz/gh-actions/vendor/dtolnay/rust-toolchain@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 with:
toolchain: stable
components: rustfmt, clippy
- uses: tempoxyz/gh-actions/vendor/Swatinem/rust-cache@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 - name: Resolve Cargo dependencies
run: .github/scripts/resolve-cargo-dependencies.sh
- run: cargo fmt --all -- --check
- run: cargo clippy --workspace --all-targets --all-features -- -D warnings
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with:
node-version: 22
- name: Pin pnpm for Tempo Lints
run: |
set -o pipefail
for attempt in 1 2 3; do
if corepack prepare pnpm@10.28.1 --activate 2>&1 | tee "$RUNNER_TEMP/corepack.log"; then
exit 0
fi
if ! grep -q 'Error when performing the request' "$RUNNER_TEMP/corepack.log" || [[ "$attempt" == 3 ]]; then
exit 1
fi
sleep $((attempt * 5))
done
- name: Run Tempo Lints
uses: tempoxyz/lints@f9268eb2b828dbacf9f4b5d4bf6ad4541826567f env:
COREPACK_DEFAULT_TO_LATEST: "0"
with:
language: rust
path: "."
post-comment: false
github-token: ${{ secrets.GITHUB_TOKEN }}
- name: Install ast-grep
uses: tempoxyz/gh-actions/vendor/jaxxstorm/action-install-gh-release@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 with:
repo: ast-grep/ast-grep
tag: "0.45.0"
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Run ast-grep lint
run: sg scan -c sgconfig.yml src/
- name: Run ast-grep tests
run: sg test -c sgconfig.yml
test:
name: Test
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with:
ref: ${{ inputs.ref || '' }}
persist-credentials: false
- uses: tempoxyz/gh-actions/vendor/dtolnay/rust-toolchain@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 with:
toolchain: stable
- uses: tempoxyz/gh-actions/vendor/Swatinem/rust-cache@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 - name: Resolve Cargo dependencies
run: .github/scripts/resolve-cargo-dependencies.sh
- uses: tempoxyz/gh-actions/vendor/taiki-e/install-action@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 with:
tool: cargo-hack
- name: Tests
run: cargo test --features tempo,stripe,ws,server,client,axum,middleware,tower,utils,integration-stripe,integration-ws
env:
STRIPE_SECRET_KEY: ${{ secrets.STRIPE_SECRET_KEY }}
- name: Check Ring transport dependency graph
run: |
tree=$(cargo tree -p alloy-transport-mpp --no-default-features --features ring --edges normal --prefix none)
if grep -q '^aws-lc-sys ' <<< "$tree"; then
echo "Ring-only transport unexpectedly includes aws-lc-sys"
exit 1
fi
- run: cargo hack check --each-feature --no-dev-deps --skip integration,integration-stripe,integration-ws
- name: Check examples
run: cargo check --workspace --exclude mpp
integration:
name: Integration Test
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
packages: read
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with:
ref: ${{ inputs.ref || '' }}
persist-credentials: false
- uses: tempoxyz/gh-actions/vendor/dtolnay/rust-toolchain@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 with:
toolchain: stable
- uses: tempoxyz/gh-actions/vendor/Swatinem/rust-cache@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 - name: Resolve Cargo dependencies
run: .github/scripts/resolve-cargo-dependencies.sh
- name: Start Tempo localnet
run: docker compose up -d --wait
- name: Run integration tests
run: cargo test --features integration --test integration_charge -- --nocapture
- name: Stop Tempo localnet
if: always()
run: docker compose down
deny:
uses: tempoxyz/gh-actions/.github/workflows/rust-deny.yml@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 with:
rust-toolchain: nightly
permissions:
contents: read
id-token: write
ci-gate:
name: CI Gate
if: always()
needs: [lint, test, integration, deny]
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 - run: |
if [[ "${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}" == "true" ]]; then
echo "One or more required jobs failed or were cancelled"
exit 1
fi