Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 28 additions & 12 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,23 @@
with:
node-version: "20"
- name: Set up Bun
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
# The repository's selected-action path rejects setup-bun before job

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 MEDIUM RISK

The implementation removes the oven-sh/setup-bun action entirely. This contradicts the PR description which states the PR would 'retain a full-SHA action pin' on a compatible release.

# instantiation (a zero-job startup_failure). Fetch the immutable Bun
# release asset directly and verify the digest published by GitHub's
# release API instead. The runtime never enters $HOME.
env:
BUN_VERSION: "1.3.14"
BUN_LINUX_X64_SHA256: "951ee2aee855f08595aeec6225226a298d3fea83a3dcd6465c09cbccdf7e848f"
run: |
archive="$RUNNER_TEMP/bun-linux-x64.zip"
install_dir="$RUNNER_TEMP/bun-runtime"
curl --fail --location --retry 3 \
--output "$archive" \
"https://github.com/oven-sh/bun/releases/download/bun-v${BUN_VERSION}/bun-linux-x64.zip"

Check warning on line 72 in .github/workflows/ci.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_affinescript&issues=AaBNUlrr3f23caWmVJZr&open=AaBNUlrr3f23caWmVJZr&pullRequest=736
Comment on lines +68 to +72

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚪ LOW RISK

Suggestion: To keep CI logs clean and the workspace tidy, use the -sS flags with curl to silence the progress bar and store the temporary archive in $RUNNER_TEMP instead of the repository root.

printf '%s %s\n' "$BUN_LINUX_X64_SHA256" "$archive" | sha256sum --check --strict
unzip -q "$archive" -d "$install_dir"
printf '%s\n' "$install_dir/bun-linux-x64" >> "$GITHUB_PATH"
"$install_dir/bun-linux-x64/bun" --version
- name: Install dependencies
run: opam install . --deps-only --with-test --with-doc --yes
- name: Install tree-sitter CLI (for res-to-affine walker tests)
Expand All @@ -68,8 +84,8 @@
# this step is only required to *exercise* the walker — the
# build itself does not depend on it.
run: npm install -g tree-sitter-cli@^0.25.0
- name: Build pinned tree-sitter-affinescript grammar
run: ./editors/tree-sitter-affinescript/scripts/install.sh
- name: Build pinned tree-sitter-rescript grammar
run: ./editors/tree-sitter-rescript/scripts/install.sh
- name: Build
run: opam exec -- dune build
- name: Run tests
Expand Down Expand Up @@ -296,9 +312,9 @@
# 0 with all tests marked skipped (mocha's expected behaviour).
run: xvfb-run -a npm test
migration-assistant:
# Build pinned tree-sitter-affinescript grammar consumed by the
# Build pinned tree-sitter-rescript grammar consumed by the
# `.res → .affine` migration assistant (#57 Phase 2). The grammar
# is manifest-vendored (`editors/tree-sitter-affinescript/package.json`)
# is manifest-vendored (`editors/tree-sitter-rescript/package.json`)
# so this job exists to (a) verify the install script and pinned
# commit still build cleanly and (b) gate `tools/res-to-affine/`
# walker work that depends on the generated parser.
Expand All @@ -315,28 +331,28 @@
- name: Install tree-sitter CLI
# npm install of tree-sitter-cli is the fast CI path (~5 s vs.
# ~5 min for `cargo install tree-sitter-cli`). The repo's
# preferred local path is cargo (see editors/tree-sitter-affinescript/
# preferred local path is cargo (see editors/tree-sitter-rescript/
# README.md) — both produce the same `tree-sitter` binary that
# the install script invokes via `command -v`. The version
# tracks `tree-sitter-affinescript`'s package.json devDependency
# tracks `tree-sitter-rescript`'s package.json devDependency
# range.
run: npm install -g tree-sitter-cli@^0.25.0
- name: Build pinned tree-sitter-affinescript grammar
- name: Build pinned tree-sitter-rescript grammar
# Direct script invocation rather than `just install-grammar` —
# GitHub Actions runners do not ship `just` preinstalled, and
# there is no other recipe used in this workflow that justifies
# adding a setup step for it. The justfile recipe still exists
# for local developer ergonomics; both call the same script.
run: ./editors/tree-sitter-affinescript/scripts/install.sh
run: ./editors/tree-sitter-rescript/scripts/install.sh
- name: Verify generated parser
# `tree-sitter generate` is supposed to drop src/parser.c into
# the cloned grammar. If it didn't, the install path is broken
# and Phase-2 walker work cannot proceed; fail loudly here
# rather than at the OCaml link step in a downstream PR.
run: |
test -f tools/vendor/tree-sitter-affinescript/src/parser.c \
test -f tools/vendor/tree-sitter-rescript/src/parser.c \
|| { echo "error: parser.c not produced by tree-sitter generate" >&2; exit 1; }
echo "parser.c size: $(wc -c < tools/vendor/tree-sitter-affinescript/src/parser.c) bytes"
echo "parser.c size: $(wc -c < tools/vendor/tree-sitter-rescript/src/parser.c) bytes"
- name: Smoke-parse a sample .res file
# Sanity-check that the grammar actually parses a non-trivial
# AffineScript source. Picks the existing res-to-affine test fixture
Expand All @@ -358,6 +374,6 @@
exit 0
fi
fixture_abs="$(realpath "${fixtures[0]}")"
( cd tools/vendor/tree-sitter-affinescript \
( cd tools/vendor/tree-sitter-rescript \
&& tree-sitter parse --quiet "${fixture_abs}" > /dev/null )
echo "smoke-parsed: ${fixtures[0]}"
Loading