Commit the pnpm-managed Cargo source block. The block is a function of Cargo.lock, so an install regenerates it byte for byte and the tracked `.cargo/config.toml` stops reporting as modified after every install. A new Rust CI step fails if the committed block and the lockfile drift apart. Cargo now resolves every crate through `.pnpm/crates` and falls back to its own registry nowhere, so each job that runs cargo needs an install behind it. Eight did not have one: both cargo-unused jobs, the micro-benchmark, the integrated benchmark's build and executor jobs, and the three release builds. The new `install-crates` action gives them one and narrows the JavaScript half with `--filter pacquet`, which a filter does not do to the Cargo half. The release builds go through `cross`, which mounts the checkout at `/project`. pnpm links each crate into `.pnpm/crates` with a relative symlink, so a store outside the checkout stops resolving under that mount. Those jobs install into a store inside the checkout instead, on Linux, the one host where cross containerizes the build at all. The two workflows that commit no longer discard the block. It is tracked content now, and a run that changes it should carry the change. Claude-Session: https://claude.ai/code/session_01Gg6uVUzLw1MniCLC81TQjP Claude-Session: https://claude.ai/code/session_01HwJS1pAz9HHQpJWEJAiaUu Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
80 lines
3.3 KiB
YAML
80 lines
3.3 KiB
YAML
name: Update Lockfile
|
|
|
|
on:
|
|
schedule:
|
|
- cron: '0 6 * * *' # Daily at 6 AM UTC
|
|
workflow_dispatch: {} # Allow manual triggering
|
|
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
# Serialize runs so a manual dispatch and the daily schedule can't reset and
|
|
# force-push the chore/update-lockfile branch at the same time.
|
|
concurrency:
|
|
group: update-lockfile
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
update-lockfile:
|
|
if: github.repository == 'pnpm/pnpm' # Only run on the main repository, not forks
|
|
runs-on: blacksmith-4vcpu-ubuntu-2404
|
|
timeout-minutes: 30
|
|
env:
|
|
# The husky hooks are a developer safety net; CI has its own gates. Without
|
|
# this, the full install wires the hooks and the pre-push hook runs the TS
|
|
# compile/lint (and, when the remote branch doesn't exist yet, the Rust
|
|
# clippy/doc sweep) during the action's push.
|
|
HUSKY: 0
|
|
steps:
|
|
- name: Checkout Commit
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
# Don't persist the write-scoped token in .git/config. The full install
|
|
# below runs third-party lifecycle scripts from freshly-bumped
|
|
# dependencies; the token is only needed to push, which pnpm/update does
|
|
# through a single-use credential helper.
|
|
persist-credentials: false
|
|
|
|
# pnpm/update's install also installs the Rust dependencies, which runs
|
|
# `cargo`. Provision the pinned toolchain up front so that install does not
|
|
# race a rustup download.
|
|
- name: Initialize Rust before dependency installation
|
|
uses: $/.github/actions/rustup
|
|
with:
|
|
restore-cache: false
|
|
|
|
# pnpm/update runs the install itself, so the action's auto-install would
|
|
# be wasted work.
|
|
- name: Install pnpm
|
|
uses: pnpm/setup@703c52620218391530e48b9e8870d5c0082e1b9b # v2.1.0
|
|
with:
|
|
install: false
|
|
|
|
- name: Update dependencies, Node.js, pnpm, and GitHub Actions
|
|
uses: pnpm/update@fcaa952ef94bad62067a94ac2e5c6234b648e259 #v0.0.0 v0
|
|
with:
|
|
update-deps: latest
|
|
refresh-lockfile: true
|
|
github-actions: true
|
|
update-pnpm: next-12
|
|
# Follow next-12 as soon as a release is published: pnpm 12's default
|
|
# 24-hour minimumReleaseAge would otherwise hold a same-day release
|
|
# back from self-update (the repo's minimumReleaseAgeExclude is
|
|
# deliberately ignored there).
|
|
update-pnpm-minimum-release-age: 0
|
|
post-update: pnpm update-manifests
|
|
branch: chore/update-lockfile
|
|
token: ${{ secrets.UPDATE_LOCKFILE_TOKEN }}
|
|
commit-message: 'chore: update dependencies, Node.js, pnpm, and GitHub Actions'
|
|
pr-title: 'chore: update dependencies, Node.js, pnpm, and GitHub Actions'
|
|
pr-body: |
|
|
This automated PR bumps the project's dependencies and pinned versions:
|
|
|
|
- Updates all dependencies to their latest versions and refreshes the lockfile.
|
|
- Bumps Node.js to the latest 26.x release, propagated into the CI, release, and benchmark workflows via the meta-updater.
|
|
- Bumps pnpm to the latest `next-12` release (`packageManager` and `devEngines.packageManager`).
|
|
- Updates the GitHub Actions pinned in the workflow files.
|
|
|
|
Created by the [pnpm/update](https://github.com/pnpm/update) action.
|