make build + make validate on GitHub Actions, plus a determinism check: the committed tree must be byte-identical to the build output, or the push fails. The mirror now guards itself. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,26 @@
|
|||||||
|
name: check
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
check:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
- uses: actions/setup-python@v5
|
||||||
|
with:
|
||||||
|
python-version: "3.12"
|
||||||
|
# Standard library only — no dependencies to install.
|
||||||
|
- name: Build (deterministic regeneration)
|
||||||
|
run: make build
|
||||||
|
- name: Verify the build changed nothing
|
||||||
|
run: |
|
||||||
|
if ! git diff --quiet; then
|
||||||
|
echo "::error::make build produced a diff — committed tree is not the deterministic build output"
|
||||||
|
git diff --stat
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
- name: Validate (OKF + schema + link integrity)
|
||||||
|
run: make validate
|
||||||
Reference in New Issue
Block a user