ci: pin the actions by version tag and cap the test timeout at 10m

This commit is contained in:
2026-09-22 21:45:25 +02:00
parent eb6ac1ab9d
commit 010a7b2a1e
4 changed files with 14 additions and 14 deletions
+6 -6
View File
@@ -4,8 +4,8 @@
# carries the CHANGELOG section as its body and nothing else. The gates still run first,
# in their own job and once, minus the race detector: race never runs on a push path or a
# tag, and the local gate raced this tree before the tag was cut. The write permission
# sits on the release job alone, and the version contract these steps implement is in the
# `release` skill.
# sits on the release job alone, and the version the binary reports is the one the
# toolchain records from the tag, with nothing injected.
#
# Every step is one command, so the step that fails is the gate that failed, and no shell
# option has to be trusted for the run to stop. The scripted steps are Perl, not shell and
@@ -31,9 +31,9 @@ jobs:
runs-on: fedora
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: actions/checkout@v7
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
- uses: actions/setup-go@v6
with:
# The module is the source of truth for the version, so it cannot drift.
go-version-file: go.mod
@@ -77,7 +77,7 @@ jobs:
- name: Tests
# Keep the pattern equal to `packages` in the project's justfile.
run: go test -count=1 -timeout 30m -coverprofile=coverage.out ./...
run: go test -count=1 -timeout 10m -coverprofile=coverage.out ./...
- name: Coverage floor
run: |
@@ -103,7 +103,7 @@ jobs:
contents: read
releases: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: actions/checkout@v7
- name: Install Perl
# The runner images are minimal and Perl is not guaranteed. The install is a