name: CI on: push: branches: [main] pull_request: workflow_dispatch: jobs: check: runs-on: linux-x86_64 steps: - uses: https://code.forgejo.org/actions/checkout@v4 - uses: https://code.forgejo.org/actions/cache@v4 with: path: | ~/.cargo/registry target key: cargo-linux-${{ hashFiles('Cargo.lock') }} restore-keys: cargo-linux- # Forgejo auto-injects GITHUB_TOKEN (GH Actions compatibility), scoped # to this Forgejo instance. Nix auto-detects that env var and assumes # it's a github.com credential, so it sends it to api.github.com when # fetching nixpkgs tarballs for devbox - which rejects it with 401. # Clearing it here falls back to unauthenticated (fine for public # nixpkgs fetches, same as this succeeds locally with no token set). - run: devbox run check env: GITHUB_TOKEN: "" # Ships the static musl binary (flake.nix packages.static) the way # `nix run .#release-static` already does from a dev machine: one release # per commit landing on main, tagged by its short hash, created if absent # and with its asset replaced if present. Gated on `check` so a failing # build or test on main is never published - unlike a tag push, which only # happens once a human has already decided a commit is good, a push to # main is not itself that decision. # # `nix build`/`nix run` draw from the Nix store and its binary cache, not # from ~/.cargo/registry or ./target, so there is nothing here for the # `check` job's cache to help with. release: needs: check if: github.event_name == 'push' && github.ref == 'refs/heads/main' runs-on: linux-x86_64 steps: - uses: https://code.forgejo.org/actions/checkout@v4 # forge.token is Forgejo Actions' auto-injected, repo-scoped # credential - the CI equivalent of running this app locally with # FORGEJO_TOKEN set in .env. - run: nix run .#release-static env: FORGEJO_TOKEN: ${{ forge.token }} GITHUB_TOKEN: ""