1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
name: macOS
# The second platform, reported and NOT gating (bl-0158).
#
# This job used to live in `ci.yml`. It could not stay there: release-plz.yml
# gates the publish on `github.event.workflow_run.conclusion == 'success'`, and
# a workflow run concludes `success` only when every one of its jobs does — so
# a red macOS job in the `CI` workflow is a permanent hold on every release,
# not a warning. macOS has never been green (14 tests, two root causes, tracked
# as bl-1015), so under the 2026-08-13 ruling to leave it for later, it moves
# here rather than blocking the pipeline or being deleted.
#
# It keeps `ci.yml`'s triggers exactly, so nothing about its visibility changes:
# it runs on every push to main, on every pull request, and on demand, and it
# reports red where it is red. What changed is only which verdict the publish
# waits on. Moving a platform back under the name `CI` is a decision to let it
# block a release; make it deliberately.
#
# Actions are pinned to full commit SHAs with their tag in the trailing comment
# — a tag can be repointed at new code by its owner between two runs, a commit
# SHA cannot (bl-5ae6). The pins here are `ci.yml`'s, and must be bumped with
# them.
on:
push:
branches:
pull_request:
workflow_dispatch:
# Reads the tree, writes nothing back.
permissions:
contents: read
jobs:
macos:
runs-on: macos-14
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable branch @ 2026-08-05
with:
toolchain: stable
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
- run: cargo build --locked
- run: make test