diff --git a/.gitea/workflows/fuzz.yml b/.gitea/workflows/fuzz.yml index ef4334b..0802bc5 100644 --- a/.gitea/workflows/fuzz.yml +++ b/.gitea/workflows/fuzz.yml @@ -22,9 +22,9 @@ jobs: runs-on: fedora timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - uses: actions/checkout@v7 - - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 + - uses: actions/setup-go@v6 with: go-version-file: go.mod cache: true diff --git a/.gitea/workflows/race.yml b/.gitea/workflows/race.yml index 9635f71..4728c47 100644 --- a/.gitea/workflows/race.yml +++ b/.gitea/workflows/race.yml @@ -22,9 +22,9 @@ jobs: runs-on: fedora timeout-minutes: 45 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - uses: actions/checkout@v7 - - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 + - uses: actions/setup-go@v6 with: go-version-file: go.mod cache: true @@ -34,4 +34,4 @@ jobs: run: dnf install -y gcc - name: Race - run: go test -race -count=1 -timeout 30m ./... + run: go test -race -count=1 -timeout 10m ./... diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index c4e5934..9105297 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -4,8 +4,8 @@ # carries the CHANGELOG section as its body and nothing else. The gates still run first, # in their own job and once, minus the race detector: race never runs on a push path or a # tag, and the local gate raced this tree before the tag was cut. The write permission -# sits on the release job alone, and the version contract these steps implement is in the -# `release` skill. +# sits on the release job alone, and the version the binary reports is the one the +# toolchain records from the tag, with nothing injected. # # Every step is one command, so the step that fails is the gate that failed, and no shell # option has to be trusted for the run to stop. The scripted steps are Perl, not shell and @@ -31,9 +31,9 @@ jobs: runs-on: fedora timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - uses: actions/checkout@v7 - - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 + - uses: actions/setup-go@v6 with: # The module is the source of truth for the version, so it cannot drift. go-version-file: go.mod @@ -77,7 +77,7 @@ jobs: - name: Tests # Keep the pattern equal to `packages` in the project's justfile. - run: go test -count=1 -timeout 30m -coverprofile=coverage.out ./... + run: go test -count=1 -timeout 10m -coverprofile=coverage.out ./... - name: Coverage floor run: | @@ -103,7 +103,7 @@ jobs: contents: read releases: write steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - uses: actions/checkout@v7 - name: Install Perl # The runner images are minimal and Perl is not guaranteed. The install is a diff --git a/.gitea/workflows/test.yml b/.gitea/workflows/test.yml index a407cc9..353ef50 100644 --- a/.gitea/workflows/test.yml +++ b/.gitea/workflows/test.yml @@ -44,9 +44,9 @@ jobs: runs-on: fedora timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - uses: actions/checkout@v7 - - uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 + - uses: actions/setup-go@v6 with: # The module is the source of truth for the version, so it cannot drift. go-version-file: go.mod @@ -80,7 +80,7 @@ jobs: - name: Tests # Scope the pattern to the packages that hold the logic when a thin cmd/ drags the # total under the floor, and keep it equal to `packages` in the project's justfile. - run: go test -count=1 -timeout 30m -coverprofile=coverage.out ./... + run: go test -count=1 -timeout 10m -coverprofile=coverage.out ./... - name: Coverage floor run: |