Repository navigation
chore: bump crossbeam-epoch to 0.9.20 for RUSTSEC-2026-0204 #103
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| branches: [main] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| env: | |
| # cargo's available_parallelism() reads the node's 32 threads, not the pod's | |
| # cgroup CPU quota, so a cold (cache-miss) build fans out ~22-way and can | |
| # OOM-kill the linker in the 5Gi cachekit runner — the same failure that hit | |
| # cachekit-rs (#25/#26). Cap parallel jobs so peak RSS stays under the cap. | |
| CARGO_BUILD_JOBS: "4" | |
| jobs: | |
| test: | |
| name: ${{ matrix.rust }} / ${{ matrix.os }} | |
| runs-on: ${{ matrix.runner }} | |
| # Fail fast instead of hanging ~10min to GitHub's heartbeat if a runner wedges. | |
| timeout-minutes: 20 | |
| continue-on-error: ${{ matrix.rust == 'beta' }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # Full OS matrix for stable only; MSRV and beta on self-hosted only | |
| include: | |
| # MSRV - ensures we don't use newer Rust features | |
| - rust: "1.85" | |
| os: ubuntu-latest | |
| runner: cachekit | |
| # Stable - primary target, all platforms | |
| - rust: stable | |
| os: ubuntu-latest | |
| runner: cachekit | |
| - rust: stable | |
| os: macos-latest | |
| runner: macos-latest | |
| - rust: stable | |
| os: windows-latest | |
| runner: windows-latest | |
| # Beta - early warning (allowed to fail) | |
| - rust: beta | |
| os: ubuntu-latest | |
| runner: cachekit | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@3c5f7ea28cd621ae0bf5283f0e981fb97b8a7af9 # master | |
| with: | |
| toolchain: ${{ matrix.rust }} | |
| components: ${{ matrix.rust != '1.85' && 'rustfmt, clippy' || '' }} | |
| - name: Cache cargo registry | |
| uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 | |
| with: | |
| cache-all-crates: true | |
| # Formatting and clippy only on stable (lints evolve between versions) | |
| - name: Check formatting | |
| if: matrix.rust == 'stable' | |
| run: cargo fmt --check | |
| - name: Run clippy | |
| if: matrix.rust != '1.85' | |
| run: cargo clippy --all-features -- -D warnings | |
| - name: Run tests (all features) | |
| run: cargo test --all-features | |
| - name: Run FFI tests | |
| if: matrix.rust == 'stable' | |
| run: cargo test --features ffi | |
| security: | |
| runs-on: cachekit | |
| timeout-minutes: 20 | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | |
| - name: Install Rust toolchain | |
| uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable | |
| - name: Cache cargo registry | |
| uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 | |
| with: | |
| cache-all-crates: true | |
| - name: Install security tools | |
| run: cargo install cargo-deny cargo-audit | |
| - name: Check dependencies (licenses & security advisories) | |
| run: cargo deny check | |
| - name: Run cargo audit | |
| run: cargo audit |