From 83610c920bdfe99b5fff5c87df55d49645f44c7e Mon Sep 17 00:00:00 2001 From: Kyle Tse Date: Fri, 25 Sep 2026 11:52:02 +0000 Subject: [PATCH] ci: plain-language check on added lines; third-party actions pinned by commit SHA --- .github/workflows/bench.yml | 4 ++-- .github/workflows/ci.yml | 19 ++++++++++++++----- .github/workflows/demo.yml | 6 +++--- .github/workflows/docs.yml | 2 +- .github/workflows/release.yml | 8 ++++---- 5 files changed, 24 insertions(+), 15 deletions(-) diff --git a/.github/workflows/bench.yml b/.github/workflows/bench.yml index 8753d05..12dca64 100644 --- a/.github/workflows/bench.yml +++ b/.github/workflows/bench.yml @@ -27,8 +27,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: dtolnay/rust-toolchain@stable - - uses: Swatinem/rust-cache@v2 + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 - uses: actions/setup-node@v7 with: node-version: '22' diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index abee3f5..27e01d3 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -15,6 +15,15 @@ concurrency: cancel-in-progress: true jobs: + plain-language: + name: plain language + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7 + with: + fetch-depth: 0 + - uses: SylphxAI/.github/.github/actions/plain-language@64598b859231c51f32d0be39630f36893d84f204 + test: name: test (${{ matrix.os }}) runs-on: ${{ matrix.os }} @@ -24,8 +33,8 @@ jobs: os: [ubuntu-latest, macos-latest, windows-latest] steps: - uses: actions/checkout@v7 - - uses: dtolnay/rust-toolchain@stable - - uses: Swatinem/rust-cache@v2 + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 - run: cargo test --workspace --locked checks: @@ -33,13 +42,13 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: oven-sh/setup-bun@v2 + - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 with: bun-version: '1.4.0' - - uses: dtolnay/rust-toolchain@stable + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable with: components: clippy, rustfmt - - uses: Swatinem/rust-cache@v2 + - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 - run: bun install --frozen-lockfile - name: Manifests agree on one version and one tagline env: diff --git a/.github/workflows/demo.yml b/.github/workflows/demo.yml index 8390dcb..b7edd06 100644 --- a/.github/workflows/demo.yml +++ b/.github/workflows/demo.yml @@ -16,8 +16,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: dtolnay/rust-toolchain@stable - - uses: Swatinem/rust-cache@v2 + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable + - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 - uses: actions/setup-node@v7 with: node-version: '22' @@ -33,7 +33,7 @@ jobs: echo "$PWD/target/release" >> "$GITHUB_PATH" # Warm the per-version caches so the recording shows query time, not indexing. for p in next14 next15 pydantic1 pydantic2; do target/release/lockdocs index -C bench/projects/$p >/dev/null; done - - uses: charmbracelet/vhs-action@v2 + - uses: charmbracelet/vhs-action@f6d7db07a432fcd3b06772628d36a57f96d95dcf # v2 with: path: docs/demo.tape - uses: actions/upload-artifact@v7 diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index fcd2a7a..4b0fced 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -24,7 +24,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - - uses: oven-sh/setup-bun@v2 + - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 with: bun-version: '1.4.0' - run: bun install --frozen-lockfile diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8993f3c..c583da1 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -54,14 +54,14 @@ jobs: - { key: win32-x64-msvc, os: windows-latest, target: x86_64-pc-windows-msvc, bin: lockdocs.exe } steps: - uses: actions/checkout@v7 - - uses: dtolnay/rust-toolchain@stable + - uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable with: targets: ${{ matrix.target }} - - uses: Swatinem/rust-cache@v2 + - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 with: key: ${{ matrix.target }} - if: matrix.zig - uses: mlugg/setup-zig@v2 + uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2 with: version: 0.14.1 - if: matrix.zig @@ -103,7 +103,7 @@ jobs: with: node-version: '22' registry-url: 'https://registry.npmjs.org' - - uses: oven-sh/setup-bun@v2 + - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 with: bun-version: '1.4.0' - run: bun scripts/check-version.ts