Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,10 @@ version: 2
updates:
# GitHub Actions - always include
- package-ecosystem: "github-actions"
# Ruby is banned for this estate: bump the action, or delete it? Delete.
ignore:
- dependency-name: "ruby/setup-ruby"
- dependency-name: "actions/jekyll-build-pages"
directory: "/"
schedule:
interval: "weekly"
Expand Down
68 changes: 0 additions & 68 deletions .github/workflows/jekyll.yml

This file was deleted.

62 changes: 62 additions & 0 deletions .github/workflows/pages.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
# SPDX-License-Identifier: MPL-2.0
#
# Generated by scripts/estate-ruby-exit.mjs — Ruby-free Pages deploy.
# Replaces the Jekyll workflow (ruby/setup-ruby or actions/jekyll-build-pages):
# Ruby is banned for this estate, see hyperpolymath/verisimdb-data ADR-0002.
name: Deploy Pages site

on:
push:
branches: ["main", "master"]
workflow_dispatch:

permissions:
contents: read
pages: write

Check warning on line 15 in .github/workflows/pages.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Move this write permission from workflow level to job level.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_a2ml-validate-action2&issues=AaDDEisn3uREZRvh07YF&open=AaDDEisn3uREZRvh07YF&pullRequest=21
id-token: write

Check warning on line 16 in .github/workflows/pages.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Move this write permission from workflow level to job level.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_a2ml-validate-action2&issues=AaDDEisn3uREZRvh07YG&open=AaDDEisn3uREZRvh07YG&pullRequest=21

concurrency:
group: "pages"
cancel-in-progress: false

jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/[email protected]
- name: Setup Pages
id: pages
uses: actions/[email protected]
- name: Build site and prove reproducibility
env:
BASE_PATH: ${{ steps.pages.outputs.base_path }}
run: |
set -euo pipefail
if command -v bun >/dev/null 2>&1; then runtime="bun run"; else runtime="node"; fi
echo "build runtime: $runtime"
$runtime scripts/build-site.mjs --config site.json --baseurl "$BASE_PATH" | tee /tmp/build-1.log
rm -rf _site
$runtime scripts/build-site.mjs --config site.json --baseurl "$BASE_PATH" | tee /tmp/build-2.log
first=$(sed -n 's/.*\(sha256=[0-9a-f]\{64\}\).*/\1/p' /tmp/build-1.log | head -1)
second=$(sed -n 's/.*\(sha256=[0-9a-f]\{64\}\).*/\1/p' /tmp/build-2.log | head -1)
if [ -z "$first" ] || [ "$first" != "$second" ]; then
echo "::error::site build is not reproducible ($first vs $second)"
exit 1
fi
- name: Upload artifact
uses: actions/[email protected]
with:
path: _site
include-hidden-files: true

deploy:
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
runs-on: ubuntu-latest
needs: build
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/[email protected]
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -103,3 +103,6 @@ sync_report*.txt

# Hypatia scan cache (local-only)
.hypatia/

# Pages output
/_site/
Loading
Loading