7c2f6c696b
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) | action | major | `v7.6.0` → `v8.0.0` | --- ### Release Notes <details> <summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary> ### [`v8.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v8.0.0): 🌈 Immutable releases and secure tags [Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v7.6.0...v8.0.0) ### This is the first immutable release of `setup-uv` 🥳 All future releases are also immutable, if you want to know more about what this means checkout [the docs](https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases). This release also has two breaking changes #### New format for `manifest-file` The previously deprecated way of defining a custom version manifest to control which `uv` versions are available and where to download them from got removed. The functionality is still there but you have to use the [new format](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/customization.md#format). #### No more major and minor tags To increase **security** even more we will **stop publishing minor tags**. You won't be able to use `@v8` or `@v8.0` any longer. We do this because pinning to major releases opens up users to supply chain attacks like what happened to [tj-actions](https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/). > \[!TIP] > Use the immutable tag as a version `astral-sh/setup-uv@8.0.0` > Or even better the githash `astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57` #### 🚨 Breaking changes - Remove update-major-minor-tags workflow [@​eifinger](https://redirect.github.com/eifinger) ([#​826](https://redirect.github.com/astral-sh/setup-uv/issues/826)) - Remove deprecrated custom manifest [@​eifinger](https://redirect.github.com/eifinger) ([#​813](https://redirect.github.com/astral-sh/setup-uv/issues/813)) #### 🧰 Maintenance - Shortcircuit latest version from manifest [@​eifinger](https://redirect.github.com/eifinger) ([#​828](https://redirect.github.com/astral-sh/setup-uv/issues/828)) - Simplify inputs.ts [@​eifinger](https://redirect.github.com/eifinger) ([#​827](https://redirect.github.com/astral-sh/setup-uv/issues/827)) - Bump release-drafter to v7.1.1 [@​eifinger](https://redirect.github.com/eifinger) ([#​825](https://redirect.github.com/astral-sh/setup-uv/issues/825)) - Refactor inputs [@​eifinger](https://redirect.github.com/eifinger) ([#​823](https://redirect.github.com/astral-sh/setup-uv/issues/823)) - Replace inline compile args with tsconfig [@​eifinger](https://redirect.github.com/eifinger) ([#​824](https://redirect.github.com/astral-sh/setup-uv/issues/824)) - chore: update known checksums for 0.11.2 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​821](https://redirect.github.com/astral-sh/setup-uv/issues/821)) - chore: update known checksums for 0.11.1 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​817](https://redirect.github.com/astral-sh/setup-uv/issues/817)) - chore: update known checksums for 0.11.0 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​815](https://redirect.github.com/astral-sh/setup-uv/issues/815)) - Fix latest-version workflow check [@​eifinger](https://redirect.github.com/eifinger) ([#​812](https://redirect.github.com/astral-sh/setup-uv/issues/812)) - chore: update known checksums for 0.10.11/0.10.12 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​811](https://redirect.github.com/astral-sh/setup-uv/issues/811)) </details> --- ### Configuration 📅 **Schedule**: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/astral-sh/uv). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My45NC4xIiwidXBkYXRlZEluVmVyIjoiNDMuOTQuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiYnVpbGQ6c2tpcC1kb2NrZXIiLCJidWlsZDpza2lwLXJlbGVhc2UiLCJpbnRlcm5hbCJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
267 lines
9.2 KiB
YAML
267 lines
9.2 KiB
YAML
on:
|
|
workflow_call:
|
|
inputs:
|
|
save-rust-cache:
|
|
required: false
|
|
type: string
|
|
default: "true"
|
|
test-macos:
|
|
required: false
|
|
type: string
|
|
default: "false"
|
|
|
|
permissions: {}
|
|
|
|
env:
|
|
CARGO_INCREMENTAL: 0
|
|
CARGO_NET_RETRY: 10
|
|
CARGO_TERM_COLOR: always
|
|
PYTHON_VERSION: "3.12"
|
|
RUSTUP_MAX_RETRIES: 10
|
|
|
|
jobs:
|
|
# We use the large GitHub actions runners
|
|
# For Ubuntu and Windows, this requires Organization-level configuration
|
|
# See: https://docs.github.com/en/actions/using-github-hosted-runners/about-larger-runners/about-larger-runners#about-ubuntu-and-windows-larger-runners
|
|
|
|
cargo-test-linux:
|
|
timeout-minutes: 10
|
|
runs-on: depot-ubuntu-24.04-16
|
|
name: "cargo test on linux"
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: "Install mold"
|
|
run: ./scripts/install-mold.sh
|
|
|
|
- uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
|
|
with:
|
|
save-if: ${{ inputs.save-rust-cache == 'true' }}
|
|
|
|
- name: "Install Rust toolchain"
|
|
run: rustup show
|
|
|
|
- uses: astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57 # v8.0.0
|
|
with:
|
|
version: "0.11.2"
|
|
|
|
- name: "Install required Python versions"
|
|
run: uv python install
|
|
|
|
- name: "Install secret service"
|
|
run: |
|
|
sudo apt update -y
|
|
sudo apt install -y gnome-keyring
|
|
|
|
- name: "Start gnome-keyring"
|
|
# run gnome-keyring with 'foobar' as password for the login keyring
|
|
# this will create a new login keyring and unlock it
|
|
# the login password doesn't matter, but the keyring must be unlocked for the tests to work
|
|
run: gnome-keyring-daemon --components=secrets --daemonize --unlock <<< 'foobar'
|
|
|
|
- name: "Create btrfs filesystem"
|
|
run: |
|
|
sudo apt-get install -y btrfs-progs
|
|
truncate -s 1G /tmp/btrfs.img
|
|
mkfs.btrfs /tmp/btrfs.img
|
|
sudo mkdir /btrfs
|
|
sudo mount -o loop /tmp/btrfs.img /btrfs
|
|
sudo chown "$(id -u):$(id -g)" /btrfs
|
|
|
|
- name: "Create tmpfs filesystem"
|
|
run: |
|
|
sudo mkdir /tmpfs
|
|
sudo mount -t tmpfs -o size=256m tmpfs /tmpfs
|
|
sudo chown "$(id -u):$(id -g)" /tmpfs
|
|
|
|
- name: "Create minix filesystem (low hardlink limit)"
|
|
run: |
|
|
truncate -s 16M /tmp/minix.img
|
|
mkfs.minix /tmp/minix.img
|
|
sudo mkdir /minix
|
|
sudo mount -o loop /tmp/minix.img /minix
|
|
sudo chown "$(id -u):$(id -g)" /minix
|
|
|
|
- name: "Install cargo nextest"
|
|
uses: taiki-e/install-action@06203676c62f0d3c765be3f2fcfbebbcb02d09f5 # v2.69.6
|
|
with:
|
|
tool: cargo-nextest
|
|
|
|
- name: "Cargo test"
|
|
env:
|
|
# Retry more than default to reduce flakes in CI
|
|
UV_HTTP_RETRIES: 5
|
|
RUST_BACKTRACE: 1
|
|
UV_INTERNAL__TEST_COW_FS: /btrfs
|
|
UV_INTERNAL__TEST_NOCOW_FS: /tmpfs
|
|
UV_INTERNAL__TEST_ALT_FS: /tmpfs
|
|
UV_INTERNAL__TEST_LOWLINKS_FS: /minix
|
|
# Write pending snapshots to a separate directory for artifact upload
|
|
INSTA_UPDATE: new
|
|
INSTA_PENDING_DIR: ${{ github.workspace }}/pending-snapshots
|
|
run: |
|
|
cargo nextest run \
|
|
--cargo-profile fast-build \
|
|
--features test-python-patch,native-auth,secret-service \
|
|
--workspace \
|
|
--profile ci-linux
|
|
|
|
- name: "Upload pending snapshots"
|
|
if: ${{ failure() }}
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: pending-snapshots-linux
|
|
path: pending-snapshots/
|
|
if-no-files-found: ignore
|
|
include-hidden-files: true
|
|
retention-days: 14
|
|
|
|
cargo-test-macos:
|
|
timeout-minutes: 20
|
|
# Only run macOS tests on main without opt-in
|
|
if: ${{ inputs.test-macos == 'true' }}
|
|
runs-on: depot-macos-14
|
|
name: "cargo test on macos"
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
|
|
with:
|
|
save-if: ${{ inputs.save-rust-cache == 'true' }}
|
|
|
|
- name: "Install Rust toolchain"
|
|
run: rustup show
|
|
|
|
- name: "Create HFS+ disk image (no reflink support)"
|
|
run: |
|
|
hdiutil create -size 256m -fs HFS+ -volname NoReflink /tmp/noreflink.dmg
|
|
hdiutil attach /tmp/noreflink.dmg
|
|
echo "HFS_MOUNT=/Volumes/NoReflink" >> "$GITHUB_ENV"
|
|
|
|
- uses: astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57 # v8.0.0
|
|
with:
|
|
version: "0.11.2"
|
|
|
|
- name: "Install required Python versions"
|
|
run: uv python install
|
|
|
|
- name: "Install cargo nextest"
|
|
uses: taiki-e/install-action@06203676c62f0d3c765be3f2fcfbebbcb02d09f5 # v2.69.6
|
|
with:
|
|
tool: cargo-nextest
|
|
|
|
- name: "Cargo test"
|
|
env:
|
|
# Retry more than default to reduce flakes in CI
|
|
UV_HTTP_RETRIES: 5
|
|
RUST_BACKTRACE: 1
|
|
# macOS tmpdir is on APFS which supports reflink
|
|
UV_INTERNAL__TEST_COW_FS: ${{ runner.temp }}
|
|
# HFS+ RAM disk does not support copy-on-write and is on a different device
|
|
UV_INTERNAL__TEST_NOCOW_FS: ${{ env.HFS_MOUNT }}
|
|
UV_INTERNAL__TEST_ALT_FS: ${{ env.HFS_MOUNT }}
|
|
# Write pending snapshots to a separate directory for artifact upload
|
|
INSTA_UPDATE: new
|
|
INSTA_PENDING_DIR: ${{ github.workspace }}/pending-snapshots
|
|
run: |
|
|
cargo nextest run \
|
|
--cargo-profile fast-build \
|
|
--no-default-features \
|
|
--features test-python,test-python-managed,test-pypi,test-git,test-git-lfs,performance,test-crates-io,native-auth,apple-native \
|
|
--workspace \
|
|
--profile ci-macos
|
|
|
|
- name: "Upload pending snapshots"
|
|
if: ${{ failure() }}
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: pending-snapshots-macos
|
|
path: pending-snapshots/
|
|
if-no-files-found: ignore
|
|
include-hidden-files: true
|
|
retention-days: 14
|
|
|
|
cargo-test-windows:
|
|
timeout-minutes: 15
|
|
runs-on: github-windows-2025-x86_64-16
|
|
name: "cargo test on windows ${{ matrix.partition }} of 3"
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
partition: [1, 2, 3]
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Dev Drive
|
|
run: ${{ github.workspace }}/.github/workflows/setup-dev-drive.ps1
|
|
|
|
# actions/checkout does not let us clone into anywhere outside ${{ github.workspace }}, so we have to copy the clone...
|
|
- name: Copy Git Repo to Dev Drive
|
|
run: |
|
|
Copy-Item -Path "${{ github.workspace }}" -Destination "$Env:UV_WORKSPACE" -Recurse
|
|
|
|
- uses: astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57 # v8.0.0
|
|
with:
|
|
version: "0.11.2"
|
|
|
|
- name: "Install required Python versions"
|
|
run: uv python install
|
|
|
|
- uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
|
|
with:
|
|
workspaces: ${{ env.UV_WORKSPACE }}
|
|
# Use the same cache entry across the partitions
|
|
add-job-id-key: false
|
|
save-if: ${{ inputs.save-rust-cache == 'true' }}
|
|
|
|
- name: "Install Rust toolchain"
|
|
working-directory: ${{ env.UV_WORKSPACE }}
|
|
run: rustup show
|
|
|
|
- name: "Create NTFS test directory (low hardlink limit)"
|
|
run: New-Item -Path "C:\uv" -ItemType Directory -Force
|
|
|
|
- name: "Install cargo nextest"
|
|
uses: taiki-e/install-action@06203676c62f0d3c765be3f2fcfbebbcb02d09f5 # v2.69.6
|
|
with:
|
|
tool: cargo-nextest
|
|
|
|
- name: "Cargo test"
|
|
working-directory: ${{ env.UV_WORKSPACE }}
|
|
env:
|
|
# Retry more than default to reduce flakes in CI
|
|
UV_HTTP_RETRIES: 5
|
|
# Avoid permission errors during concurrent tests
|
|
# See https://github.com/astral-sh/uv/issues/6940
|
|
UV_LINK_MODE: copy
|
|
RUST_BACKTRACE: 1
|
|
UV_INTERNAL__TEST_LOWLINKS_FS: "C:\\uv"
|
|
# Write pending snapshots to a separate directory for artifact upload
|
|
INSTA_UPDATE: new
|
|
INSTA_PENDING_DIR: ${{ github.workspace }}/pending-snapshots
|
|
shell: bash
|
|
run: |
|
|
cargo nextest run \
|
|
--cargo-profile fast-build \
|
|
--no-default-features \
|
|
--features test-python,test-pypi,test-python-managed,native-auth,windows-native \
|
|
--workspace \
|
|
--profile ci-windows \
|
|
--partition hash:${{ matrix.partition }}/3
|
|
|
|
- name: "Upload pending snapshots"
|
|
if: ${{ failure() }}
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: pending-snapshots-windows-${{ matrix.partition }}
|
|
path: pending-snapshots/
|
|
if-no-files-found: ignore
|
|
include-hidden-files: true
|
|
retention-days: 14
|