Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .github/workflows/docker-build-cloud.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,8 @@ on:
default: "."
type: string
build-args:
description: "Docker build arguments (multiline format: KEY1=value1\nKEY2=value2)"
description:
"Docker build arguments (multiline format: KEY1=value1\nKEY2=value2)"
default: ""
type: string
attest:
Expand Down
7 changes: 4 additions & 3 deletions .github/workflows/docker-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@ on:
workflow_call:
inputs:
build-args:
description: "Docker build arguments (multiline format: KEY1=value1\nKEY2=value2)"
description:
"Docker build arguments (multiline format: KEY1=value1\nKEY2=value2)"
default: ""
type: string
image-name:
Expand Down Expand Up @@ -149,8 +150,8 @@ jobs:
context: ${{ inputs.context }}
file: ${{ inputs.dockerfile }}
platforms: ${{ inputs.platform }}
load: true # Make the image available on runner
push: false # Don't push yet, wait for security checks
load: true # Make the image available on runner
push: false # Don't push yet, wait for security checks
tags: ${{ inputs.image-name }}:${{ inputs.image-tag }}

- name: Run Trivy vulnerability scanner
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/docker-promote.yml
Original file line number Diff line number Diff line change
Expand Up @@ -214,8 +214,8 @@ jobs:
image-ref: ${{ env.IMAGE }}@${{ steps.tested.outputs.digest }}
format: table
ignore-unfixed: true
vuln-type: 'os,library'
severity: 'CRITICAL,HIGH'
vuln-type: "os,library"
severity: "CRITICAL,HIGH"
hide-progress: true
exit-code: 1
# same scanner version as the CI build, so a finding here means the
Expand Down
28 changes: 14 additions & 14 deletions .github/workflows/propose-safe-multisig-tx.yml
Original file line number Diff line number Diff line change
@@ -1,45 +1,45 @@
name: 'Propose Safe Multisig Transaction'
name: "Propose Safe Multisig Transaction"
on:
workflow_call:
inputs:
safe-address:
description: 'Address of the Safe contract'
description: "Address of the Safe contract"
required: true
type: string
transaction-to:
description: 'Target address of the transaction'
description: "Target address of the transaction"
required: true
type: string
transaction-value:
description: 'Value to send in the transaction (in wei, default: 0)'
description: "Value to send in the transaction (in wei, default: 0)"
required: false
default: '0'
default: "0"
type: string
transaction-data:
description: 'Transaction data/calldata'
description: "Transaction data/calldata"
required: true
type: string
dry-run:
description: 'If true, validate and prepare the transaction without proposing it'
description: "If true, validate and prepare the transaction without proposing it"
required: false
default: false
type: boolean
secrets:
rpc-url:
description: 'RPC URL for the blockchain network'
description: "RPC URL for the blockchain network"
required: true
safe-proposer-private-key:
description: 'Private key of the proposer wallet'
description: "Private key of the proposer wallet"
required: true
safe-api-key:
description: 'Safe API key for transaction service'
description: "Safe API key for transaction service"
required: true
outputs:
tx-hash:
description: 'Hash of the Safe transaction'
description: "Hash of the Safe transaction"
value: ${{ jobs.propose-transaction.outputs.tx-hash }}
tx-details:
description: 'Created transaction details'
description: "Created transaction details"
value: ${{ jobs.propose-transaction.outputs.tx-details }}

jobs:
Expand All @@ -48,7 +48,7 @@ jobs:
outputs:
tx-hash: ${{ steps.safe-transaction.outputs.tx-hash }}
tx-details: ${{ steps.safe-transaction.outputs.tx-details }}

steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand All @@ -58,7 +58,7 @@ jobs:
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '22'
node-version: "22"

- name: Install dependencies
run: npm ci
Expand Down
16 changes: 8 additions & 8 deletions .github/workflows/rust-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,19 +4,19 @@ on:
workflow_call:
inputs:
rust-version:
description: 'Rust version to use'
default: 'stable'
description: "Rust version to use"
default: "stable"
type: string
working-directory:
description: 'The directory to run jobs from'
default: '.'
description: "The directory to run jobs from"
default: "."
type: string
enable-cache:
description: 'Enable caching of dependencies'
description: "Enable caching of dependencies"
default: true
type: boolean
publish-crates-io:
description: 'Publish package to crates.io'
description: "Publish package to crates.io"
default: false
type: boolean
secrets:
Expand All @@ -26,7 +26,7 @@ on:
env:
CARGO_TERM_COLOR: always
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}

jobs:
build_and_publish:
runs-on: ubuntu-latest
Expand Down Expand Up @@ -80,7 +80,7 @@ jobs:
- name: Check documentation
working-directory: ${{ inputs.working-directory }}
env:
RUSTDOCFLAGS: '-D warnings'
RUSTDOCFLAGS: "-D warnings"
run: cargo doc --locked --no-deps --document-private-items

- name: Validate package
Expand Down
33 changes: 0 additions & 33 deletions .github/workflows/validate-release-please-config.yml

This file was deleted.

10 changes: 5 additions & 5 deletions .github/workflows/lint.yml → .github/workflows/verify-all.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
name: Lint
name: Verify all

on:
push:
Expand All @@ -7,14 +7,14 @@ on:

permissions: {}

# Cancelling a push to main would leave that commit unlinted.
# Cancelling a push to main would leave that commit unverified.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}

jobs:
lint:
name: Lint
name: Verify all
runs-on: ubuntu-latest
permissions:
contents: read # required for checkout
Expand All @@ -27,5 +27,5 @@ jobs:
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
with:
minimum_release_age: 7d
- name: Run lint
run: mise run lint
- name: Run verify-all
run: mise run verify-all
36 changes: 0 additions & 36 deletions .github/workflows/verify-workflow-sha256.yml

This file was deleted.

24 changes: 24 additions & 0 deletions .mise/locks/npm-prettier/3.9.8/aube-lock.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
lockfileVersion: '9.0'

settings:
autoInstallPeers: true
excludeLinksFromLockfile: false

importers:

.:
dependencies:
prettier:
specifier: 3.9.8
version: 3.9.8

packages:

prettier@3.9.8:
resolution: {integrity: sha512-WRFq3Wn3WId7LLROfMLdH7xaFr2jR62wU8nLO6rQUOLOxNZUviyJQs1M0iIhLexSFy+L+w0ch66wtoO2jRjG0A==}
engines: {node: '>=14'}
hasBin: true

snapshots:

prettier@3.9.8: {}
7 changes: 7 additions & 0 deletions .mise/locks/npm-prettier/3.9.8/package.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{
"name": "mise-npm-install",
"private": true,
"dependencies": {
"prettier": "3.9.8"
}
}
5 changes: 5 additions & 0 deletions .prettierignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# generated files
## release-please
*/CHANGELOG.md
## mise
.mise/
3 changes: 3 additions & 0 deletions .prettierrc.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"proseWrap": "never"
}
45 changes: 37 additions & 8 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -1,34 +1,63 @@
# Contributing

## Verifying your changes

All dev tools are pinned in `mise.toml` and `mise.lock`. Install them with [mise](https://mise.jdx.dev):

```sh
mise install --locked
```

Then, before pushing, run:

```sh
mise run verify-all
```

CI runs the same command on every pull request and on every push to `main`. It runs these tasks:

- `lint`: runs all linters (see [Linting](#linting))
- `lint:format`: checks formatting with Prettier
- `lint:actionlint`: lints GitHub Actions workflows with actionlint
- `lint:shellcheck`: lints shell scripts with shellcheck
- `check-checksums`: checks that `workflow-sha256` files match their workflows (see [Editing a reusable workflow](#editing-a-reusable-workflow))
- `check-release-please-config`: validates `release-please-config.json`, checking that every package declares a component and that keys are ordered

You can run any of these on its own, e.g. `mise run lint:shellcheck`. Run `mise tasks` to list all tasks.

## Editing a reusable workflow

Each shared reusable workflow is backed by a Component directory `<name>/` that release-please versions independently. Release-please only sees changes under `<name>/`, so a commit that only edits the workflow file is otherwise invisible to it.

After editing any `.github/workflows/<name>.yml` for a workflow listed in `release-please-config.json`, run:

```sh
bash scripts/compute-workflow-sha256.sh
mise run update-checksums
```

This regenerates `<name>/workflow-sha256`, a checksum of the workflow file. Commit the resulting diff alongside your workflow change — this is what makes the change visible to release-please for that Component.
This formats the repository (see [Formatting](#formatting)), then runs `scripts/compute-workflow-sha256.sh`, which regenerates `<name>/workflow-sha256`, a checksum of the workflow file. Commit the resulting diff alongside your workflow change — this is what makes the change visible to release-please for that Component.

CI enforces this on every pull request via `bash scripts/compute-workflow-sha256.sh --check`, which fails if any `workflow-sha256` file is out of date.
`mise run verify-all` enforces this through the `check-checksums` task, which fails if any `workflow-sha256` file is out of date.

## Linting
## Formatting

Workflows are linted with [actionlint](https://github.com/rhysd/actionlint), which also runs [shellcheck](https://github.com/koalaman/shellcheck) on inline `run:` scripts. Shell scripts committed to the repository (`*.sh`, e.g. under `scripts/`) are linted with shellcheck directly. Both tools are pinned in `mise.toml` and `mise.lock`. Install them with [mise](https://mise.jdx.dev):
Files are formatted with [Prettier](https://prettier.io), using its default settings. Generated files (release-please changelogs, mise files) are excluded via `.prettierignore`. Format the repository with:

```sh
mise install --locked
mise run format
```

Then:
> [!IMPORTANT] Formatting can rewrite workflow files, which changes their checksum. After editing a workflow, run `mise run update-checksums` instead of `mise run format` alone, so `workflow-sha256` files are computed from the formatted content.

## Linting

Workflows are linted with [actionlint](https://github.com/rhysd/actionlint), which also runs [shellcheck](https://github.com/koalaman/shellcheck) on inline `run:` scripts. Shell scripts committed to the repository (`*.sh`, e.g. under `scripts/`) are linted with shellcheck directly. Formatting is checked with `prettier --check`. Run all linters with:

```sh
mise run lint
```

CI runs the same command on every pull request and on every push to `main`.
`mise run verify-all` includes this step.

## Updating dependencies

Expand Down
Loading
Loading