Repository navigation
docs: say what CI and the release workflow really do - #32
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Docs only. Several pages still described the repository as it was before
ci.ymlexisted and before the release moved to the shared signing workflow (#31).docs/internals/contributing.md: no longer says there is no CI or that Windows and macOS are only compile-verified. It now says whatci.ymlruns (build andcargo teston Linux, Windows and macOS, a build at Rust 1.90, thecolony.jsoncheck) and what it still does not (rustfmt and clippy, for the reasons in the header ofci.yml). Also drops a broken sentence fragment claiming the startup failure message insrc/main.rsis French; it is English.docs/internals/packaging.md: the release build is no longer described as the only check Windows and macOS get. Adds a paragraph sayingscripts/sign-release.shis a manual fallback no workflow uses.docs/project/roadmap.md: "Run the tests in CI" moves to Done; Next now lists the part that is really missing, gating rustfmt and clippy. The signed-releases entry describes the shared sign-and-publish workflow and the pending SignPath Authenticode.scripts/sign-release.sh(comment only): its header said to use it in CI; it now says releases do not use it and it is the manual fallback. It also pointed at asrc/signing.rsthat is Colony's, not Grape's.scripts/README.md: "Strict mode (as in CI)" for clippy was wrong; CI does not run clippy.README.md,docs/guide/install.md: each binary ships with.sig,.metaand.meta.sig(as the v0.4.1 release does), not just.sig.contributing.md,architecture.md,roadmap.mdand one comment inci.ymlsaid 50 tests insrc/and 19 of 23 player tests ignored; it is 65 (2 ignored) and 20 of 25. Theci.ymlchange is that comment only.SECURITY.md: replaces GitHub's unfilled template (versions 4.0 to 5.1 that never existed) with a real policy: only the latest release is supported, report privately through GitHub's private vulnerability reporting, which is enabled on this repository.Proven locally
.github/workflows/ci.yml,.github/workflows/release.ymland the pinnedsign-and-publish.ymlof Project-Colony-Resources (619460f), including thatsign-release.shwrites the same.metaformat.gh api repos/Project-Colony/Grape/private-vulnerability-reportingreturns{"enabled":true}..sig,.metaand.meta.sigeach.cargo fmt --checkandcargo clippy --all-targets -- -D warningsboth fail onmainas well (rustfmt.toml uses nightly-only options; clippy reports 385 errors in the lib), which is exactly whatci.ymland the updated docs say. This PR touches no Rust code.cargo testpasses on Linux: 63 + 2 ignored insrc/, 20 cache, 20 Last.fm, 5 + 20 ignored player tests. Those counts are what the docs now say.bash -n scripts/sign-release.shpasses,ci.ymlstill parses as YAML, and no added line has an em or en dash.What only CI or a release can prove