mirror of
https://github.com/max-sixty/worktrunk.git
synced 2026-09-14 20:00:38 +08:00
4c5a3f8293020ab4e708947e91d0e263ce00e9ed
443 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
e8b96e67d3 |
chore: bump taiki-e/install-action from 2.87.5 to 2.87.6 (#4040)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.87.5 to 2.87.6. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.87.6</h2> <ul> <li> <p>Update <code>rafn@latest</code> to 0.1.6.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.3.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.57.1.</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.87.6] - 2026-09-05</h2> <ul> <li> <p>Update <code>rafn@latest</code> to 0.1.6.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.3.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.57.1.</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/7b8d4719ee4aaa279bdf55df38dacb9ebfe12a6c"><code>7b8d471</code></a> Release 2.87.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/a67fcd18912da6d4796bca317d5cab21011e4100"><code>a67fcd1</code></a> Update wasm-bindgen manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/efe69d32714f20bb09c75259e13aff27b522a932"><code>efe69d3</code></a> Update uv manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/ce51454fc8877f04f22b2f56d89ea2651ed30e39"><code>ce51454</code></a> Update tombi manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/e3284bdb652397d2e383409c416379d54965a495"><code>e3284bd</code></a> Update <code>rafn@latest</code> to 0.1.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/50bb7c8acf710975ea99f8a03c5c0908eb81a222"><code>50bb7c8</code></a> Update <code>editorconfig-checker@latest</code> to 3.11.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/2e1a951416180a0bba89f6085bdc643badc7bcf6"><code>2e1a951</code></a> Update <code>dprint@latest</code> to 0.57.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/2d664e31d201ebb33db21aa8f8ed354b56349426"><code>2d664e3</code></a> Update <code>convco@latest</code> to 0.7.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/5f8ff1a44efd92cf3d48505f1adfee33393eb853"><code>5f8ff1a</code></a> ci: Disable debian 11</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.87.5...v2.87.6">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ae8017d962 |
chore: bump taiki-e/install-action from 2.87.3 to 2.87.5 (#4027)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.87.3 to 2.87.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.87.5</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.30.3.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.9.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.50.1.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.5.1.</p> </li> <li> <p>Update <code>release-plz@latest</code> to 0.3.161.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.5.2.</p> </li> <li> <p>Update <code>oxfmt@latest</code> to 1.81.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.9.1.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.15.0.</p> </li> <li> <p>Update <code>git-cliff@latest</code> to 2.14.1.</p> </li> <li> <p>Update <code>cargo-zigbuild@latest</code> to 0.23.4.</p> </li> <li> <p>Update <code>cargo-deb@latest</code> to 3.8.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.12.</p> </li> </ul> <h2>2.87.4</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.8.</p> </li> <li> <p>Update <code>protoc@latest</code> to 3.36.1.</p> </li> <li> <p>Update <code>coreutils@latest</code> to 0.11.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.87.5] - 2026-09-04</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.30.3.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.9.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.50.1.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.5.1.</p> </li> <li> <p>Update <code>release-plz@latest</code> to 0.3.161.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.5.2.</p> </li> <li> <p>Update <code>oxfmt@latest</code> to 1.81.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.9.1.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.15.0.</p> </li> <li> <p>Update <code>git-cliff@latest</code> to 2.14.1.</p> </li> <li> <p>Update <code>cargo-zigbuild@latest</code> to 0.23.4.</p> </li> <li> <p>Update <code>cargo-deb@latest</code> to 3.8.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.12.</p> </li> </ul> <h2>[2.87.4] - 2026-09-02</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.8.</p> </li> <li> <p>Update <code>protoc@latest</code> to 3.36.1.</p> </li> <li> <p>Update <code>coreutils@latest</code> to 0.11.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/5bf6ce016fd2e72eefc647cbca1e4213f65955b8"><code>5bf6ce0</code></a> Release 2.87.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/c8f75a38a93ab127e88c6d8381743690a2a685ef"><code>c8f75a3</code></a> Update <code>vacuum@latest</code> to 0.30.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/c5d511325cdf275237f3fdab11e994191ea82c3e"><code>c5d5113</code></a> Update <code>uv@latest</code> to 0.12.9</li> <li><a href="https://github.com/taiki-e/install-action/commit/c1adc108841026dc473cf9a02dd1ffc368ba01cc"><code>c1adc10</code></a> Update <code>typos@latest</code> to 1.50.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/34dbe155f9867cd34c3db175970cbcbcb8f143d5"><code>34dbe15</code></a> Update <code>tombi@latest</code> to 1.5.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/e0276b791665d4be4b21cdd2b49a6df6954e435d"><code>e0276b7</code></a> Update <code>release-plz@latest</code> to 0.3.161</li> <li><a href="https://github.com/taiki-e/install-action/commit/8b5d7c437e30a7ede5d7f61b6eeff87f3c39ebe7"><code>8b5d7c4</code></a> Update rclone manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/ef1233b5d19e57bf51f767ee7e487c6d6afa78b3"><code>ef1233b</code></a> Update rafn manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/128fbfbf6cdabf877da9ba64e5ecefc0d3241ae1"><code>128fbfb</code></a> Update <code>prek@latest</code> to 0.5.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/b5eb8fb65087e999e18210212f6f3615bf9dc3c5"><code>b5eb8fb</code></a> Update <code>oxfmt@latest</code> to 1.81.0</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.87.3...v2.87.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
15e7658bd9 |
chore: update tend workflows (0.1.24 → 0.2.0) (#4035)
Nightly regeneration of the tend workflow files, picking up the 0.1.x → 0.2.0 release. **tend version:** 0.1.24 → 0.2.0 ## Notable changes - **Runtime switch and a per-workflow enable gate.** Every generated workflow now reads `.config/tend.yaml` at job start and skips when tend is disabled, so turning tend off no longer needs a workflow edit (max-sixty/tend#1132). - **`ci-fix` gets a concurrency group per branch and watched workflow.** A red branch that fails every push collapses into one session instead of one per commit, and a red `publish-site` can't starve behind a stream of red `ci` (max-sixty/tend#1148). - **Runner logic moved out of Bash and skills into Python**, with new Claude effort/harness arguments and experimental Codex subscription auth threaded through the generated workflows (max-sixty/tend#1158, max-sixty/tend#1161, max-sixty/tend#1159). - **Review and approval fixes**: a standing bot approval is now dismissed when a review withholds its verdict, and when another PR merging invalidates it (max-sixty/tend#1136, max-sixty/tend#1139). - **Notifications acknowledge each resolved thread** rather than marking the whole repository read, and secret listings are paginated so a second page can't pass as clean (max-sixty/tend#1121, max-sixty/tend#1137). Full comparison: https://github.com/max-sixty/tend/compare/0.1.24...0.2.0 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
b9293cb26a |
Cancel superseded PR release checks (#4023)
Cancel superseded cargo-dist plan checks when a pull request receives a newer commit. Tag-triggered releases use a unique concurrency group and keep cancellation disabled, so actual releases cannot cancel one another. > _This was written by Codex on behalf of max-sixty_ |
||
|
|
3df836aa7e |
ci: bump pinned worktrunk to 0.76.0 (#4016)
Weekly CI pin bump. Only `worktrunk` drifted since last week — every other `baptiste0928/cargo-install` pin (cargo-affected `0.4.0`, cargo-insta `1.48.0`, cargo-nextest `0.9.143`, cargo-llvm-cov `0.9.0`, cargo-msrv `0.19.3`, cargo-udeps `0.1.61`, lychee `0.24.2`), plus `setup-nu` `0.115.1` and the `.codex/cloud.sh` / `setup-web` pins (pre-commit `4.6.2`, PowerShell `7.6.5`), is already at the latest upstream release. - **worktrunk** `=0.75.0` → `=0.76.0` (3 sites: `ci.yaml` ×2, `nightly.yaml`) Compatibility: worktrunk `0.76.0` declares `rust-version = 1.97`, matching the pinned toolchain (`rust-toolchain.toml` channel `1.97.0`), so it builds under `baptiste0928/cargo-install`. This is the `wt` that runs the suite (`wt hook pre-merge`) on all three platforms, so it goes on its own PR — its own matrix is the only place the bump gets tested. The 0.76.0 breaking changes are in `wt switch --execute` argv handling, retired `commit.generation` config keys, and the library API; none of them touch `wt hook pre-merge`. <details><summary>Checks that found no drift</summary> - **MSRV/toolchain**: current stable is `1.98.1`, so latest−1 is `1.97`, already what `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`, and `rust-toolchain.toml` pin. The `nightly-2026-08-01` pins in `nightly.yaml` are ~5 weeks old, inside the three-month window. - **Runner images**: `ubuntu-24.04`, `macos-26`, and `windows-2025` each still equal their `-latest` label in the `actions/runner-images` availability table; `ubuntu-24.04-arm` and `macos-26-intel` follow those rows. Ubuntu 26.04 is badged preview, so not a bump target. - **`dependabot.yaml` typescript ignore**: `npm view @astrojs/check peerDependencies.typescript` is still `^5.0.0 || ^6.0.0` against a current `typescript` major of 7, so the major-version ignore entry stays (#3877). </details> Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
74f74749aa |
chore: bump taiki-e/install-action from 2.87.2 to 2.87.3 (#4005)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.87.2 to 2.87.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.87.3</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.30.0.</p> </li> <li> <p>Update <code>ubi@latest</code> to 0.12.0.</p> </li> <li> <p>Update <code>protoc-gen-connect-openapi@latest</code> to 0.25.8.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.16.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 2.1.0.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.57.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.87.3] - 2026-09-01</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.30.0.</p> </li> <li> <p>Update <code>ubi@latest</code> to 0.12.0.</p> </li> <li> <p>Update <code>protoc-gen-connect-openapi@latest</code> to 0.25.8.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.16.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 2.1.0.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.57.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/0758d235715de2f3551eacc980d9ae8fce9342c3"><code>0758d23</code></a> Release 2.87.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/88efe43bfd45d48641dfceaa8d61d410c820021a"><code>88efe43</code></a> Update <code>zizmor@latest</code> to 1.30.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/2880e0286789726ce93d833e73f37a1465d1299a"><code>2880e02</code></a> Update uv manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/64a78f77b5812aa8c129138b11e9b96df3b9228f"><code>64a78f7</code></a> Update <code>ubi@latest</code> to 0.12.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/bc9ef8893585745dfab4c8f76b36bb67f1d2a47f"><code>bc9ef88</code></a> Update typos manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/1fbc342e7489bf534948958ea2c18db550e4a6a2"><code>1fbc342</code></a> Update protoc manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/4543d7b568aaedc538cce9875094502487f9f2cf"><code>4543d7b</code></a> Update <code>protoc-gen-connect-openapi@latest</code> to 0.25.8</li> <li><a href="https://github.com/taiki-e/install-action/commit/12472d93d6d1bd4f34df6aadc2d91b75e1ac2760"><code>12472d9</code></a> Update prek manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/608f8a9a770c32695b090f1ebd8814ad53abd4bc"><code>608f8a9</code></a> Update oxfmt manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/31c81b722b6e9548b69c0385902715b846329581"><code>31c81b7</code></a> Update <code>mise@latest</code> to 2026.8.16</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.87.2...v2.87.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
03d1a4dd3c |
chore: bump taiki-e/install-action from 2.87.1 to 2.87.2 (#3986)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.87.1 to 2.87.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.87.2</h2> <ul> <li> <p>Update <code>typos@latest</code> to 1.50.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.5.0.</p> </li> <li> <p>Update <code>shfmt@latest</code> to 3.14.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.87.2] - 2026-08-30</h2> <ul> <li> <p>Update <code>typos@latest</code> to 1.50.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.5.0.</p> </li> <li> <p>Update <code>shfmt@latest</code> to 3.14.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/1ed6d7be6168f6c9046541087ff549b6bc581fdf"><code>1ed6d7b</code></a> Release 2.87.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/0fbfc5b541ba726278965a75a3fd222af703b279"><code>0fbfc5b</code></a> Update <code>typos@latest</code> to 1.50.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/5f68cef2c452eb3fcb5dccbbcd5f6d192a13a892"><code>5f68cef</code></a> Update <code>tombi@latest</code> to 1.5.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/d46a5ec40dd3eef68104c5b342f24e599519675f"><code>d46a5ec</code></a> Update <code>shfmt@latest</code> to 3.14.0</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.87.1...v2.87.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
a02df64ffe |
chore: bump taiki-e/install-action from 2.86.7 to 2.87.1 (#3978)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.86.7 to 2.87.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.87.1</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.7.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.49.1.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.51.1.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.5.0.</p> </li> <li> <p>Update <code>d2@latest</code> to 0.8.2.</p> </li> <li> <p>Update <code>cargo-zigbuild@latest</code> to 0.23.3.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.11.</p> </li> </ul> <h2>2.87.0</h2> <ul> <li> <p>Support <code>kache</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1980">#1980</a>, thanks <a href="https://github.com/ChrisJr404"><code>@ChrisJr404</code></a>)</p> </li> <li> <p>Update <code>vacuum@latest</code> to 0.30.1.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.6.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.14.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.2.</p> </li> </ul> <h2>2.86.8</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 48.0.1.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.258.0.</p> </li> <li> <p>Update <code>oxfmt@latest</code> to 1.80.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.12.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 2.0.0.</p> </li> <li> <p>Update <code>cargo-zigbuild@latest</code> to 0.23.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.87.1] - 2026-08-29</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.7.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.49.1.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.51.1.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.5.0.</p> </li> <li> <p>Update <code>d2@latest</code> to 0.8.2.</p> </li> <li> <p>Update <code>cargo-zigbuild@latest</code> to 0.23.3.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.11.</p> </li> </ul> <h2>[2.87.0] - 2026-08-27</h2> <ul> <li> <p>Support <code>kache</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1980">#1980</a>, thanks <a href="https://github.com/ChrisJr404"><code>@ChrisJr404</code></a>)</p> </li> <li> <p>Update <code>vacuum@latest</code> to 0.30.1.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.6.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.14.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.2.</p> </li> </ul> <h2>[2.86.8] - 2026-08-26</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 48.0.1.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.258.0.</p> </li> <li> <p>Update <code>oxfmt@latest</code> to 1.80.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.12.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 2.0.0.</p> </li> <li> <p>Update <code>cargo-zigbuild@latest</code> to 0.23.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/742a3317eac7bd62f91cd888b4eead5e784ba833"><code>742a331</code></a> Release 2.87.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/c5b69cd73ba573d80324cdcd0b052ca509084b22"><code>c5b69cd</code></a> Update <code>uv@latest</code> to 0.12.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/85e6400c85d74d612698536feafd9e20f40aa257"><code>85e6400</code></a> Update <code>typos@latest</code> to 1.49.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/91f3a12371baac5722df4e5c6d42937d16656ffe"><code>91f3a12</code></a> Update tombi manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/160f8b13c099dc3c9067e0658c0da7ac925a00ff"><code>160f8b1</code></a> Update <code>syft@latest</code> to 1.51.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/aa48d3e72e94215619c754df53a143cdaabefc8b"><code>aa48d3e</code></a> Update shfmt manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/06671d277ce58cccc6fe7f9d6509e0327c53f4f3"><code>06671d2</code></a> Update <code>prek@latest</code> to 0.5.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/8060a83f169920516f09e1cf1c58677cec39b6c7"><code>8060a83</code></a> Update <code>d2@latest</code> to 0.8.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/74cae3c341a52a9e510e2f660ed813b801bff6dd"><code>74cae3c</code></a> Update <code>cargo-zigbuild@latest</code> to 0.23.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/a65402f15d24476e19123aafa105daa804db68c0"><code>a65402f</code></a> Update <code>cargo-rdme@latest</code> to 2.2.2</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.86.7...v2.87.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
126f022416 |
ci: bump Windows runner images from windows-2022 to windows-2025 (#3974)
## Summary `windows-2022` was deliberately held back, and the reason recorded in `ci.yaml`'s header no longer holds. The comment reads "Pinned because windows-2025 lacks D: drive" — but GitHub reversed that removal: [actions/runner-images#12744](https://github.com/actions/runner-images/issues/12744) announced that from 2025-08-18 the Windows Server 2025 image again exposes a `D:\` drive, with the working directory back on `D:\`, explicitly reversing [#12416](https://github.com/actions/runner-images/issues/12416). `windows-2022` has also fallen off the `windows-latest` label, so the pin is due on the ordinary weekly rule too. This moves the four `windows-2022` matrix entries to `windows-2025` and rewrites the header comment, which no longer needs a hold-back line. Split from the week's other pin bumps ([#3971](https://github.com/max-sixty/worktrunk/pull/3971)) so a red Windows matrix decides only this bump. The `D:\` drive is what prompted the change because the workflows use it: `ci.yaml`, `affected.yaml`, and `nightly.yaml` each run a `Use fast D: drive for temp files (Windows)` step that creates `D:\tmp` and points `TEMP`/`TMP` at it. Those steps are unchanged and keep working, since #12744 restored exactly that drive. ## The label also swaps the MSVC toolset `D:\` is not the only variable this bump moves. `windows-2025` is no longer the Visual Studio 2022 image: [actions/runner-images#14017](https://github.com/actions/runner-images/issues/14017) moved `windows-latest` and `windows-2025` onto the Windows Server 2025 + VS 2026 image in June 2026. The availability table now carries a single Windows Server 2025 row whose three labels — `windows-latest`, `windows-2025`, `windows-2025-vs2026` — all resolve to `Windows2025-VS2026-Readme.md`. So CI's Windows legs compile with the VS 2026 toolset after this PR. The second-order effect is that CI and the release build no longer share a toolset. `dist` computes the release matrix itself and is untouched here: v0.69.2 built `x86_64-pc-windows-msvc` on `build-local-artifacts (windows-2022, …)`, and `windows-2022` is not deprecated, so `dist` keeps picking it. Nothing now exercises the toolset the shipped binary is compiled and linked with. That is a real gap, but a low-risk one and a separate decision from this bump — nothing in the tree pins a VS path (`build.rs` is vergen-only; the `cc` / `find-msvc-tools` route discovers VS through vswhere), and `affected tests (windows, advisory)` is green on this head. Aligning the release runner is a release-matrix change that belongs in its own PR. ## Verification This PR's own `test (windows)`, `full-tests (windows-2025, windows)`, and `affected tests (windows, advisory)` legs are the only place this gets tested — the weekly runner is Linux. Two failure shapes to look for if Windows goes red, not one: - **`D:`-shaped** — the `D:\tmp` step fails to create the directory, meaning #12744's restoration doesn't apply to this repo's runners and the pin should go back. - **Toolset-shaped** — a compile or link failure from the VS 2026 move. [#14004](https://github.com/actions/runner-images/issues/14004) is an open report of this same label swap breaking hardcoded VS 2022 paths; nothing here hardcodes one, but a future Windows-only break is as likely to be this shape as the first. The throughput question this description originally left open is answered: no measurable regression. Every Windows leg here lands inside the same-day `windows-2022` spread from the sibling pin PRs, and the advisory leg is the fastest of the five — durations are tabulated in [the first review](https://github.com/max-sixty/worktrunk/pull/3974#pullrequestreview-5064565794). The remaining bias runs against this PR, not for it: `save-if` gates the rust-cache write to `main`, so this run restored a cache written on `windows-2022`. [#12647](https://github.com/actions/runner-images/issues/12647)'s reported slowdown does not reproduce here. `ci.yaml`'s header comment now keeps each pin on its own line, so this PR's edit and [#3973](https://github.com/max-sixty/worktrunk/pull/3973)'s `macos-15` → `macos-26` edit stay on separate lines. They are still adjacent lines, so whichever lands second needs a one-hunk resolution keeping both — details in [this comment](https://github.com/max-sixty/worktrunk/pull/3974#issuecomment-5476167137). The three matrix files auto-merge clean. <details><summary>Availability table rows this reads from</summary> From `actions/runner-images` `README.md`: - Windows Server 2025 — `windows-latest`, `windows-2025`, `windows-2025-vs2026`; Included Software links `images/windows/Windows2025-VS2026-Readme.md` - Windows Server 2022 — `windows-2022` (no `-latest`), linking `images/windows/Windows2022-Readme.md` `windows-2022` is not badged `deprecated` yet, but it is now the older of the two GA images, which the weekly rule treats as next due. That it is undeprecated is also why `dist` still selects it for the release build. </details> --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
94e609c8fb |
ci: bump macOS runner images from macos-15 to macos-26 (#3973)
## Summary `macos-15` has fallen off the `macos-latest` label — `actions/runner-images` now resolves it to macOS 26 Arm64 — so the pin is due under the weekly rule that bumps any image the availability table no longer lists against `-latest`. This moves the four `macos-15` matrix entries to `macos-26` and the one `macos-15-intel` release runner to `macos-26-intel`. Split from the week's other pin bumps ([#3971](https://github.com/max-sixty/worktrunk/pull/3971)) so a red macOS matrix decides only this bump. The architecture split is preserved exactly: `macos-26` is the arm64 image (what `macos-latest` now points at, matching `macos-15`'s old role), and `macos-26-intel` is the x64 image that `nightly.yaml`'s `x86_64-apple-darwin` release target needs. ## Verification This PR's own `test (macos)`, `full-tests (macos-26, macos)`, `affected tests (macos, advisory)`, and `release-target (x86_64-apple-darwin)` legs are the only place this gets tested — the weekly runner is Linux. Worth reading those results before merging rather than treating the label swap as mechanical: a runner image bump moves Xcode, the system toolchain, and the preinstalled git, any of which the PTY and shell-integration suites can notice. <details><summary>Availability table rows this reads from</summary> From `actions/runner-images` `README.md`: - macOS 26 Arm64 — `macos-latest`, `macos-26`, `macos-26-xlarge` - macOS 26 — `macos-latest-large`, `macos-26-intel`, `macos-26-large` - macOS 15 Arm64 — `macos-15`, `macos-15-xlarge` (no `-latest`) - macOS 15 — `macos-15-large`, `macos-15-intel` (no `-latest`) - macOS 14 — badged `deprecated` macOS 15 is not badged deprecated yet, but it is now the older of the two GA images, which is what the weekly rule treats as next due. `ubuntu-24.04` is untouched here: it is still exactly what `ubuntu-latest` resolves to. </details> Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
9bcc071222 |
ci: bump pinned Nushell to 0.115.1 (#3972)
## Summary Weekly pin bump: Nushell 0.115.0 → 0.115.1 across all seven pinned sites. Split from the week's other pin bumps ([#3971](https://github.com/max-sixty/worktrunk/pull/3971)) because the shell-integration suite runs `--all-features`, so a Nushell version change can move PTY snapshots — on its own branch, a red matrix decides only this bump. Sites moved together, per the weekly checklist: the five `hustcer/setup-nu` `version:` inputs (`coverage.yaml`, `nightly.yaml`, `benchmarks.yaml`, and both `.github/actions/{test,tend}-setup/action.yaml`), plus the two places that pin Nushell outside `.github/` and are kept level with `test-setup` — `.codex/cloud.sh`'s `NU_VERSION` and `Taskfile.yaml`'s `setup-web`. ## Verification The version is the current upstream release (`nushell/nushell` `0.115.1`, published 2026-08-23). This PR's own `test (linux|macos|windows)` and `full-tests` legs are where the snapshot question actually gets answered — I have not run the PTY suite against 0.115.1 locally, since the weekly runner installs no Nushell. <details><summary>Upstream changes in 0.115.1</summary> A patch release, mostly completion and config fixes. Nothing that obviously touches the prompt or wrapper surfaces worktrunk's snapshots capture, but the completion and REPL changes are the ones to watch if a snapshot does move: - `fix(config): merge keybindings by name and key instead of name alone` (#18870) - `feat(completions): add a background-completions opt-out` (#18764) - `fix(completions): keep the REPL usable when a completer runs fzf or input list` (#18881) - `Completor Fixes` (#18868) - `allow $ans to still work after invalid operation` (#18863) - `fix update to work better with custom values` (#18865) - `allow boolean comparison with semver` (#18854) - `Update h2 do to RUSTSEC-2026-0258` (#18875) </details> Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
5f06e55332 |
chore(ci): weekly renovation 2026-08-31 (#3971)
## Summary Weekly CI renovation. One cargo-install pin had drifted; everything else in the weekly checklist is already current. Rust stable is 1.98.0, so MSRV and the development toolchain stay at 1.97 (latest stable − 1) — last week's bump already landed them there. - **`worktrunk`: 0.74.0 → 0.75.0** — `ci.yaml` ×2, `nightly.yaml` ×1. `rust-version` 1.97, exactly the pinned toolchain. Toolchain compatibility for every pinned crate against 1.97.0: `cargo-affected` 0.4.0 (1.94), `cargo-insta` 1.48.0 (1.66.0), `cargo-nextest` 0.9.143 (1.91), `cargo-llvm-cov` 0.9.0 (1.87), `cargo-msrv` 0.19.3 (1.91.1), `lychee` 0.24.2 (1.88.0), `worktrunk` 0.75.0 (1.97), `cargo-udeps` 0.1.61 (unspecified). All build under 1.97.0. <details><summary>Everything else the weekly pass checked, and why it isn't here</summary> - **MSRV + toolchain** — stable is 1.98.0 (released 2026-08-18), so the target is 1.97. `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`, and `rust-toolchain.toml` are all already at 1.97. No change, so no `flake.lock` refresh either. - **Pinned nightlies** — `nightly-2026-08-01` ×2 in `nightly.yaml`. One month old; the rule bumps only past three months. - **Other cargo-install pins** — `cargo-affected`, `cargo-insta`, `cargo-nextest`, `cargo-llvm-cov`, `cargo-msrv`, `cargo-udeps`, `lychee` all match their current crates.io release. - **Codex Cloud / `setup-web`** — `pre-commit` 4.6.2, `cargo-insta` 1.48.0, `cargo-nextest` 0.9.143, PowerShell 7.6.5 all current. Nushell has drifted and is handled separately, below. - **`ubuntu-24.04`** — still what `ubuntu-latest` resolves to, so it stays. Ubuntu 26.04 is badged `preview`, which is not a bump target. - **Dependabot's `typescript` major ignore** — stays. `@astrojs/check` still declares `peer typescript@"^5.0.0 || ^6.0.0"` and the current `typescript` major is 7, so the entry is still the only thing keeping a TypeScript 7 lockfile from breaking `npm ci`. - **LLM model pins in docs** — `claude-haiku-4.5` and `gpt-5.6-luna` are both still the fastest/smallest in their vendor's current family. OpenAI's models page describes Luna as "fast and affordable … at the lowest cost in the family"; the only smaller Codex model, `gpt-5.3-codex-spark`, is a Pro-only research preview and not a good default recommendation. - **Statusline cache-check** — clean. `wt config state logs profile` reports `same_context_duplicates: []` and 0 extra calls on a `wt list statusline --format=claude-code` render. </details> Three findings from this pass are **not** in this PR, because each can turn a whole CI leg red and belongs on its own branch: the Nushell bump (moves PTY snapshots) and the two runner-image bumps (`macos-15` and `windows-2022` have both fallen off their `-latest` label). Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
cf734e3b33 |
chore: update tend workflows (0.1.22 → 0.1.24) (#3969)
Nightly regeneration of tend's workflow files, picking up two upstream releases. **tend version:** 0.1.22 → 0.1.24 ### Notable changes - **The frequent poll now repairs conflicted bot PRs**, not just unread notifications — the `tend-notifications` boot gate gained a GraphQL query that test-merges open bot PRs and looks for deferral markers in recent comments, so a conflicted PR wakes the queue instead of waiting for the nightly sweep ([max-sixty/tend#1108](https://github.com/max-sixty/tend/pull/1108)). - **Review gating tightened**: `APPROVE` is now conditioned on the author stating merge readiness rather than the draft flag alone, the posting preflight is bound to the outward action, and the code-review pass became its own step gated at submit ([max-sixty/tend#1087](https://github.com/max-sixty/tend/pull/1087), [max-sixty/tend#1107](https://github.com/max-sixty/tend/pull/1107), [max-sixty/tend#1080](https://github.com/max-sixty/tend/pull/1080)). - **Generator fixes that change this repo's YAML**: an adopter's `prompt:` may now span more than one line (the `|2` block-indent markers in the diff), pre-check setup guards are preserved, and the `concurrency.queue` actionlint ignore is written out ([max-sixty/tend#1103](https://github.com/max-sixty/tend/pull/1103), [max-sixty/tend#1106](https://github.com/max-sixty/tend/pull/1106), [max-sixty/tend#1095](https://github.com/max-sixty/tend/pull/1095)). - **`uv` is provisioned for agent sessions**, and Gist-backed Claude memory ships as experimental ([max-sixty/tend#1109](https://github.com/max-sixty/tend/pull/1109), [max-sixty/tend#1110](https://github.com/max-sixty/tend/pull/1110)). - Pinned harness versions moved with the releases: Claude 2.1.251, Codex 0.151.0, uv 0.12.7. ### A second commit, outside the usual regen `tend init` now also writes `.github/actionlint.yaml` (the `concurrency.queue` ignore from max-sixty/tend#1095). The nightly recipe stages only `.github/workflows` and `.config`, so it landed untracked and would be re-created on every future run — the second commit tracks it. This repo runs no actionlint job or pre-commit hook, so the file is inert here; it only suppresses a false positive for anyone linting these workflows locally. Full compare: https://github.com/max-sixty/tend/compare/0.1.22...0.1.24 --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
97d3adb7a5 |
chore: update tend workflows (0.1.20 → 0.1.22) (#3960)
Automated nightly regeneration of tend's workflow files. **tend version:** 0.1.20 → 0.1.22 ## Notable changes - **Notifications now run off a recovery queue** (max-sixty/tend#1074). The pre-check drops the old layered inbox sweep (shadowed-run and closed-bot-PR marking) in favour of a single paginated snapshot taken before a 10-minute cutoff, passes that cutoff through to the agent, and keeps repository watching enabled with an idempotent `PUT .../subscription` on every cycle. The job also gains a serial `tend-notifications` concurrency group. - **`tend-review` re-targets instead of skipping** (max-sixty/tend#1082). The "skip when the live HEAD is already examined" gate step and its `if:` guards are gone; a live session now re-targets when HEAD moves. The concurrency group adds `queue: max` so a push can't evict a pending `ready_for_review` run. - **Skills check the default branch for a landed fix before opening a PR** (max-sixty/tend#1070), and `review-runs` gains the run census as a second stranded-trigger drain input (max-sixty/tend#1073). - **Poll/rerun script fixes** (max-sixty/tend#1053, max-sixty/tend#1055): `tend-review` no longer gates the CI poll, and an unresolvable commit fails fast rather than passing silently. - **Generator fixes**: `watched_workflows` and `branches` are validated as string lists (max-sixty/tend#1076), and block prompts no longer get padded blank lines (max-sixty/tend#1090). Full upstream diff: https://github.com/max-sixty/tend/compare/0.1.20...0.1.22 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
1c5c63ba91 |
Update Tend workflows to 0.1.20 (#3940)
Updates all eight generated Tend workflows from 0.1.19 to 0.1.20. The new release preserves setup-added tool paths across the Claude sandbox boundary, fixing the `uv: command not found` failures that stopped triage and notification recovery before the agent started. Verified with: - `uvx tend@0.1.20 check` - `cargo run -- hook pre-merge --yes` (4,722 tests passed, one skipped; docs, doctests, clippy, formatting, lockfile, and repository hooks passed) Upstream fix: [max-sixty/tend#1071](https://github.com/max-sixty/tend/pull/1071) Release: [Tend 0.1.20](https://github.com/max-sixty/tend/releases/tag/0.1.20) > _This was written by Codex on behalf of max-sixty_ |
||
|
|
e5f9589c5c |
Polish mobile docs terminals (#3936)
## Summary - re-record and publish both mobile homepage demos with restored ANSI colors - preserve exact ANSI roles in every snapshot-backed website terminal while keeping Markdown portable - wrap source and command snippets on mobile, contain fixed terminal tables, and add real WebKit layout and contrast regressions The corrected GIFs are already published in `max-sixty/worktrunk-assets` at `4de7bde`. ## Testing - `cargo run -- hook pre-merge --yes` (4,721 tests passed, 1 skipped) - `npm --prefix docs run check` - `npm --prefix docs test` - `npm --prefix docs run build` - `npm --prefix docs run test:site` - independent frame review of both mobile GIF themes - independent architecture, systematic, and adversarial reviews Closes #3930 Closes #3931 > _This was written by Codex on behalf of max-sixty._ |
||
|
|
37141b8eb1 |
chore: update tend workflows (0.1.18 → 0.1.19) (#3932)
Automated nightly regeneration of tend's workflow files. **tend version:** 0.1.18 → 0.1.19. The diff is the eight `.github/workflows/tend-*.yaml` files, each with its generation stamp and its `max-sixty/tend/claude@` action ref moved to the new release — no other workflow-body changes. **Notable changes** - **Sandbox setup gains the agent's GitHub context** (max-sixty/tend#1057, max-sixty/tend#1059) — `sandbox_setup` commands now see `GITHUB_WORKFLOW` and the same GitHub context the agent gets. This repo runs a `sandbox_setup` block in `.config/tend.yaml` (the `cargo-insta` / `cargo-nextest` / `pre-commit` install plus its five-tool probe), so the change lands here directly. Related sandbox guidance: the CI agent is now told it runs unprivileged and where root lives (max-sixty/tend#1041), what its PATH couldn't reach is named (max-sixty/tend#1047), and runner-home setup is explicit (max-sixty/tend#1048). - **Instruction-file pinning and checkout hygiene** (max-sixty/tend#1005, max-sixty/tend#1029) — every instruction file the CLIs read is pinned at any depth on both harnesses, and the harness's own `settings.local.json` is excluded from the adopter checkout. - **CI-monitoring scripts** (max-sixty/tend#999, max-sixty/tend#1046) — `poll-pr-checks.sh` pages the check rollup instead of refusing past 100 contexts, and rejects an unusable SHA before entering the poll loop. Headroom rather than a live fix here — the current `main` head carries 70 check runs and PR #3926's head 24, both under the old limit, but the count grows with every workflow job added. - **Skill behavior** — review stops at the review on PRs the bot itself authored (max-sixty/tend#1007) and scales depth to what checking the change requires; nightly leaves the `tend-outage` tracker for `review-runs` to drain (max-sixty/tend#1021) and confirms a resolved PR actually left the conflicted state before polling CI (max-sixty/tend#1032); ci-fix filters the outage-escalation query by title rather than label alone (max-sixty/tend#1015). - **Plain titles required from tend workflows** (max-sixty/tend#1022, max-sixty/tend#1060) — PRs and issues opened by tend workflows now use plain titles rather than a Conventional Commits prefix. This PR still carries the `chore:` prefix because the recipe that generated it ships with the currently-pinned 0.1.18 action; the next nightly, running 0.1.19, will use the new convention. Full upstream diff: https://github.com/max-sixty/tend/compare/0.1.18...0.1.19 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
55c767121e |
chore: bump taiki-e/install-action from 2.86.5 to 2.86.7 (#3928)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.86.5 to 2.86.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.86.7</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.4.1.</p> </li> <li> <p>Update <code>rafn@latest</code> to 0.1.5.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.22.0.</p> </li> </ul> <h2>2.86.6</h2> <ul> <li> <p>Update <code>dprint@latest</code> to 0.56.1.</p> </li> <li> <p>Update <code>cargo-lambda@latest</code> to 1.9.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.10.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.86.7] - 2026-08-24</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.4.1.</p> </li> <li> <p>Update <code>rafn@latest</code> to 0.1.5.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.22.0.</p> </li> </ul> <h2>[2.86.6] - 2026-08-23</h2> <ul> <li> <p>Update <code>dprint@latest</code> to 0.56.1.</p> </li> <li> <p>Update <code>cargo-lambda@latest</code> to 1.9.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.10.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/b6ff580856c41316412a0b9b60540fbc6f8c82cc"><code>b6ff580</code></a> Release 2.86.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/a4b7b62b9a19e0f4ccdd66d907a8fd1fb87dee6a"><code>a4b7b62</code></a> Update <code>tombi@latest</code> to 1.4.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/7f5d2c4648161944a16a7e4acc4eff13e832be28"><code>7f5d2c4</code></a> Update <code>rafn@latest</code> to 0.1.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/0223cb3e411bc958fcd486d0aee439f1817cad11"><code>0223cb3</code></a> Update mise manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/80434f8e6e467e69b8ef0017167271c45b531e70"><code>80434f8</code></a> Update kingfisher manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/45d93f47ad62589021d77e7b0c74ffd8fc297f4a"><code>45d93f4</code></a> Update cargo-zigbuild manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/7754905a58d4fc87b239c41a353de74d18b96e04"><code>7754905</code></a> Update <code>cargo-binstall@latest</code> to 1.22.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/6cd13508893c0e7eab5f273c2575d3859bd7229a"><code>6cd1350</code></a> Release 2.86.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/0110a1ec6672caea804fdcdc2ad4a3492a498f7a"><code>0110a1e</code></a> Update tombi manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/48a83f919f059547ee259ffdc644a09317221853"><code>48a83f9</code></a> Update rafn manifest</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.86.5...v2.86.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
6b0c0d0f4c |
ci(tend): assert nix reaches the sandbox alongside the rest of the toolchain (#3909)
`.config/tend.yaml`'s sandbox probe asserted four of the five tools the agent needs. `nix` — installed by `tend-setup` for the weekly `flake.lock` refresh — sat outside it, so a regression in that install would have surfaced only once `tend-weekly` reached for `nix flake update` and found nothing. That gap is not hypothetical: PR #3428 (`bump MSRV and toolchain to 1.96`) was the bot, and it updated `Cargo.toml`, `rust-toolchain.toml` and `tests/helpers/wt-perf/Cargo.toml` while leaving `flake.lock` stale, because `nix` wasn't there. `nix` reaches the sandbox by the route `nu` does: `install-nix-action`'s multi-user daemon install puts `/nix/var/nix/profiles/default/bin` on `$GITHUB_PATH`, a system path the sandbox PATH derivation carries across verbatim. So it needs no `sandbox_setup:` line of its own, only the probe entry. The error message now points at `.github/CLAUDE.md`'s "Sandbox toolchain" section, since the old "wt hook pre-merge cannot run" is false for a weekly-only tool. The probe entry couples the install to every workflow: only `tend-weekly` runs `nix`, but the probe runs everywhere, so the step can no longer be gated to one. The `Install Nix` comment records that, in place of the cost argument that used to carry the question. Also here: `.github/CLAUDE.md` stated the sandbox PATH rule as existence-only, where tend additionally requires the sandbox UID to traverse the directory — the test that decides whether a root-owned `/nix` carries across, and so the one a reader of that section will want. <details> <summary>Why the install isn't cached, and why it isn't gated to <code>tend-weekly</code></summary> Measured from `##[end-action … duration_ms]` markers in four real tend run logs. `Install Nix` takes **3.46 / 3.97 / 4.13 / 4.24 s** against **~46–50 s** for the whole `tend-setup` composite, of which the `rust-cache` restore alone is 26.0–28.5 s and apt (zsh, fish) is 10.9–12.9 s. Within those 4 s, roughly half is downloading and unpacking the 25.8 MiB tarball and the rest is creating the nixbld users, `/etc/nix`, the store, and the `nix-daemon` systemd unit. That second half is root-level system state no restored `/nix` reproduces, so the install itself is not cacheable. Caching the *store* on top would serve only the weekly job's flake fetches while costing a restore in every workflow. The multi-user daemon install is also what makes `nix` reach the sandbox at all, so the faster single-user installers are not substitutes. `nixbuild/nix-quick-install-action` (~1 s) does `sudo install -d -o "$USER" /nix` and puts only `$HOME/.nix-profile/bin` on `$GITHUB_PATH` — which the `/home/runner` → `/home/tend-sandbox` rewrite drops, so `nix` would leave the sandbox PATH entirely. Self-installation by the agent was considered and rejected. The sandbox user has no sudo, and the official Nix binary hardcodes its ELF interpreter to `/nix/store/…-glibc-2.42-67/lib/ld-linux-x86-64.so.2`, so it cannot run without a root-created `/nix`. A statically linked `nix` does work for these two commands with no root — verified, using the automatic `~/.local/share/nix/root` chroot store — but no maintained build is published (`NixOS/nix` has no GitHub releases; `releases.nixos.org` serves no static variant; Hydra's `buildStatic` download URL now redirects to the manual), and a chroot store cannot build anything. Gating the install to `tend-weekly` was also rejected. It saves 4 s of a ~46 s setup on a public repo with free Actions minutes, `tend-ci-fix` watches `nightly` (which hosts the `nix-flake` job) and would lose the ability to reproduce a red nix build, and — because `sandbox_setup:` is top-level only in tend's config and cannot see which workflow it is in — gating would force dropping the probe entry that this PR adds. max-sixty/tend#1057 removes that last constraint for future cases. </details> ## Testing The probe loop was exercised both ways locally under `bash -eo pipefail`: exit 0 with all five names resolvable, exit 1 naming the first missing one otherwise. `uvx tend@latest init` (0.1.18, matching the pinned action) regenerates all eight workflows with exactly the one changed line each, and re-running it is a no-op. `pre-commit run --all-files` and `cargo test --test integration test_docs_are_in_sync` pass. The probe line itself can only run after merge: the `tend` environment admits only `main`, so `workflow_dispatch` from this branch is refused, and `tend-review` here runs under `pull_request_target` against the base ref, so it exercises `main`'s four-tool probe. The premise underneath it is verified, though — this PR's own `tend-review` session runs as `tend-sandbox` with `main`'s `tend-setup` behind it, which already installs Nix, so it checked the route directly: `command -v nix` resolves to `/nix/var/nix/profiles/default/bin/nix` (2.35.2), `nix flake --help` works with `experimental-features = nix-command flakes` inherited from the system-wide `/etc/nix/nix.conf`, and `nix store info` reports `Store URL: daemon`. So the added name cannot turn the eight workflows red, and the weekly recipe's two commands work from the sandbox rather than just its binary being present. > _This was written by Claude Code on behalf of max-sixty_ Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
f2ae1c5fb5 |
chore(ci): weekly renovation 2026-08-23 (#3880)
## Summary Weekly CI renovation. Rust stable moved to 1.98.0 on 2026-08-20, so MSRV and the development toolchain go to 1.97 (latest stable − 1); one cargo-install pin had drifted. Everything else is already current. - **MSRV + toolchain: 1.96 → 1.97** — `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`, `rust-toolchain.toml` (`1.97.0`), plus the `flake.lock` refresh the channel bump requires. - **`cargo-llvm-cov`: 0.8.7 → 0.9.0** — `coverage.yaml`. MSRV 1.87, well under the pinned toolchain. Toolchain compatibility for every other pinned crate against 1.97.0: `cargo-affected` 0.4.0 (1.94), `cargo-insta` 1.48.0 (1.66.0), `cargo-nextest` 0.9.143 (1.91), `cargo-llvm-cov` 0.9.0 (1.87), `cargo-msrv` 0.19.3 (1.91.1), `lychee` 0.24.2 (1.88.0), `worktrunk` 0.74.0 (1.96), `cargo-udeps` 0.1.61 (unspecified). All build under 1.97.0. - **Pinned nightly: `nightly-2026-03-01` → `nightly-2026-08-01`** — `nightly.yaml` ×2. Not drift: the MSRV bump *broke* these two jobs, see below. - **The skill's `flake.lock` recipe** — the in-session Nix install it pointed at can never run. The setup step that fixes that lives in #3891, not here; see below. The remaining commits are fallout from the same sweep: `cargo-llvm-cov` 0.9.0 changes the shape of the `--show-missing-lines` column `tests/CLAUDE.md` sends you to during a codecov investigation, and the weekly statusline cache-check has been reporting two duplicates that are artifacts of its own `-vv` flag. ## The MSRV bump broke two nightly jobs; that is fixed here `check-unused-dependencies` and `minimal-versions` each pin their own toolchain, and `nightly-2026-03-01` is `1.96.0-nightly` — so raising `rust-version` to 1.97 made cargo refuse the workspace outright, before either job ran its actual check: ``` error: rustc 1.96.0-nightly is not supported by the following packages: worktrunk@0.74.0 requires rustc 1.97 ``` Both are now on `nightly-2026-08-01` (`1.99.0-nightly`), which clears the new MSRV with headroom rather than landing on it. Reproduced locally in both directions: `cargo +nightly-2026-03-01 check` fails with the error above, `cargo +nightly-2026-08-01 check` passes. The coupling is easy to miss because neither failure mentions udeps or minimal versions, so both lines now say so, and the weekly MSRV file table gained a row for the pins. The rule on that row is a date, not a version: bump only when the pinned date is more than three months old. Nightly runs two channels ahead of stable and MSRV tracks stable − 1, so a pin that recent is still a release above the new MSRV — which makes staleness checkable from the pinned date alone, where reading it off the rustc version means fetching that day's `channel-rust-nightly.toml`. `nightly-2026-03-01` was five and a half months old, which is exactly what the rule catches. ## The `flake.lock` bump was computed by hand — and the recipe that forced that is fixed here `rust-toolchain.toml` moving to `1.97.0` forces a lock refresh: the locked `rust-overlay` (`4a408e1f`, 2026-06-02) carries stable manifests only up to `1.96.0`, so `nix flake check` cannot resolve the new channel. `rust-overlay` is bumped to `f60c1b57` (2026-08-23), which has `1.97.0.nix`. `nixpkgs` and `crane` are left alone — only `rust-overlay` has to know about the new channel, and a full `nix flake update` is a wider change than this PR needs. This session could not run `nix flake update`: the weekly runner has no Nix, and the agent runs as a sandbox user with no sudo, so the installer the skill pointed at stops at `sudo: a password is required`. The lock entry was therefore computed directly from the NAR serialisation, and the method was validated first by recomputing the **existing** `rust-overlay` entry from its own revision and getting `sha256-7mDa7OBAaf7MU6ZovT9ENfD62kH911SsSazBb4KTDF0=` back byte-for-byte — the value already in `flake.lock`. The same script then produced the new entry. That should not have been the answer, and it no longer is. #3891 has merged (`2960bfb`), so `tend-setup` installs Nix and next week's refresh runs `nix flake update rust-overlay` for real. This branch briefly carried its own `cachix/install-nix-action@v31` step in the same file; `adbeb76` dropped it in favour of #3891's, which asserts the multi-user install branch directly and doesn't couple to `github.workflow == 'tend-weekly'`, a gate that stops firing if the generated workflow is renamed. `.github/actions/tend-setup/action.yaml` on this branch is byte-identical to `main`. What stays here is the skill side: the in-session install recipe and the NAR-serialisation fallback are both deleted, because the Determinate installer they rest on cannot run in the sandbox. Both PRs rewrote that section and converged on nearly the same wording, so they merged clean while both were open — but #3891's squash collapsed its five commits into one, and its last two had moved the "if `nix` isn't on the PATH" line and folded the flake-input rationale into the code block. That turned the section into the merge's one conflict, resolved by taking `main`'s wording wholesale; the section is now byte-identical to `main`'s, and this branch's own additions to that file are untouched by it. That is a strong check but not the real one. `nightly`'s `nix-flake` job runs `nix flake check` and fires on this PR (the paths filter matches `rust-toolchain.toml`, `Cargo.toml`, and `flake.lock`), so it is the gate that actually proves the lock evaluates. **It has now run on this head and passed**, so the computed lock resolves the 1.97.0 channel and the flake's checks build under it. Flagging the provenance anyway, since a hand-written lock entry deserves a second look on review. <details><summary>How the hash was computed</summary> Nix serialises the unpacked flake input as a NAR and reports SHA-256 of that stream in SRI form. The format is length-prefixed strings padded to 8 bytes, with directory entries in bytewise-sorted order; a ~90-line Python script reproduces it from the GitHub tarball with the top-level `<repo>-<rev>` directory stripped, which is the same tree Nix hashes. ``` rust-overlay 4a408e1fc99ad517b4cb402fd0de7464f40c05e1 (currently locked) computed sha256-7mDa7OBAaf7MU6ZovT9ENfD62kH911SsSazBb4KTDF0= in lock sha256-7mDa7OBAaf7MU6ZovT9ENfD62kH911SsSazBb4KTDF0= ✓ rust-overlay f60c1b57ff805a46b5175c76fc981fb4f81efbcc (new) computed sha256-r4LDUF+zmJnkftvCVkCrUhSJazsf6EVJF+V2l4/MYbI= lastModified 1787454509 (committer date 2026-08-23T03:08:29Z) ``` </details> ## Already up to date - `cargo-affected` 0.4.0, `cargo-insta` 1.48.0, `cargo-nextest` 0.9.143, `cargo-msrv` 0.19.3, `cargo-udeps` 0.1.61, `lychee` 0.24.2, `worktrunk` 0.74.0 (matches the newest crates.io release) - Nushell 0.115.0 — all four call sites, and `dev/codex.sh` - Codex Cloud pins in `dev/codex.sh`: pre-commit 4.6.2, cargo-insta 1.48.0, cargo-nextest 0.9.143, PowerShell 7.6.5; `setup-web`'s own Nushell and PowerShell pins agree - Runner images `ubuntu-24.04` and `windows-2022` (the latter deliberately pinned — actions/runner-images#12677) ## Found, not bumped: `macos-15` is no longer what `macos-latest` resolves to `ci.yaml`'s header comment says `ubuntu-24.04, macos-15` are "pinned to current -latest equivalents". That is still true of Ubuntu but no longer of macOS: `macos-latest` now resolves to **macOS 26 arm64**, and `macos-15` has become the older of the two GA images — which, under the runner-images deprecation policy ("deprecation of the oldest image label begins once the newest OS image label has been released to GA"), is the one that starts aging out next. `macos-14` already carries the deprecated badge. Not bumped here, because it is an OS upgrade rather than a version pin, and this repo drives PTY and shell-integration snapshots on macOS that a new image and Xcode can move. There is also nothing this session can do to check it — the only macOS available to it is the `test (macos)` job on a PR, and a red macOS matrix would have blocked the MSRV bump alongside it. Flagging rather than guessing at the timing: whether to take macOS 26 now or wait for the deprecation announcement is a call about this repo's snapshot surface. Happy to open it as its own PR if you want the signal. ## CI Fully green on `7940a97`, the first merge of `main`: all 33 non-skipped checks, including `msrv`, all three `test` legs, `full-tests` on every platform, `nix-flake`, `minimal-versions`, `check-unused-dependencies`, `check-docs`, `link-check`, `feature-powerset`, and `codecov/patch`. That head is where the hand-written lock entry and the nightly pins were proven against the current `main`. `main` has since moved four commits (#3886, #3893, #3895, #3897) and is merged in again at `d8d1553`, alongside the nightly-pin rule above. #3895 touches `nightly.yaml`, so the pins were re-checked after that merge: still exactly two sites, `minimal-versions` and `check-unused-dependencies`, both on `nightly-2026-08-01`. Locally `pre-commit run --all-files` and `test_docs_are_in_sync` pass on this head. ## Weekly checks that produced no change - **LLM model pins** — no drift. `gpt-5.6-luna` is still how OpenAI's models page positions the "fast and affordable … lowest cost in the family" 5.6 variant; `gpt-5.3-codex-spark` is a Pro-only research preview, not a default. `haiku` / `claude-haiku-4.5` is still the smallest current Anthropic model. - **Statusline cache-check** — clean. `command_count` was 27, which includes the three calls the `-vv` diagnostic collector makes after the render, so the render itself is ~24 against a ~29 baseline measured before the recipe used `-vv`. The two duplicates the report flagged (`gh --version`, `git worktree list --porcelain`) are that same collector, not the render. Both the baseline arithmetic and the trap are now written down in the skill. - **Agent app integration surfaces** — nothing that changes what Worktrunk consumes. Claude Code 2.1.239 fixed `metadata.pluginRoot` resolution, but `.claude-plugin/marketplace.json` names an explicit `./plugins/worktrunk` source rather than a bare name, so it is unaffected; the `WorktreeCreate`/`WorktreeRemove` hooks and the statusline stdin schema are unchanged (`workspace.git_worktree` and `workspace.repo` exist but predate this window by several hundred releases). Codex, Gemini CLI, and OpenCode shipped only routine releases. - **README month** — already "August 2026". - **Dependency PRs** — none open. <details><summary>Verification</summary> - `rustup` resolves the new channel: `cargo 1.97.0 (c980f4866 2026-06-30)`, `rustc 1.97.0 (2d8144b78 2026-07-07)`, `clippy 0.1.97`. - `cargo clippy --all-targets --all-features -- -D warnings` passes on 1.97.0 — the check that matters most for a toolchain bump, since it compiles every target and feature under the new rustc and holds the new clippy to zero warnings. Doctests passed too. - Unit tests pass on 1.97.0: 979 + 11 + 1, zero failures. - Integration tests: 2000 passed, 1 failed — `test_copy_ignored_preserves_file_executable_permissions`, which expects `0644` and got `0664`. That is this sandbox's `umask 0002`, not the toolchain; the `test (linux|macos|windows)` matrix is the real gate. - `cargo run -- hook pre-merge --yes` is not a clean local signal on this runner: it ends on `pre-commit: exit status: 127` because pre-commit isn't installed in the tend sandbox, unrelated to the bump. - `cargo msrv verify` was not run locally (it rebuilds the graph per candidate); `ci.yaml`'s `msrv` job covers it. - Every version above was read from its upstream source of truth: `cargo info` / crates.io for the cargo tools, `static.rust-lang.org/dist/channel-rust-stable.toml` for Rust stable (1.98.0, 2026-08-20), the `nushell/nushell` and `PowerShell/PowerShell` release APIs, PyPI for pre-commit, `actions/runner-images` README for the image labels, and the vendors' own model pages for the LLM pins. - `rust-overlay` at the currently-locked revision was confirmed to stop at `1.96.0.nix`, and at the new revision to contain `1.97.0.nix` — this is why the lock has to move at all. </details> > _This was written by Claude Code on behalf of max-sixty_ --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> Co-authored-by: Maximilian Roos <m@maxroos.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
56bfa70af0 |
chore: bump taiki-e/install-action from 2.86.3 to 2.86.5 (#3893)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.86.3 to 2.86.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.86.5</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.4.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.257.1.</p> </li> <li> <p>Update <code>protoc@latest</code> to 3.36.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.10.</p> </li> <li> <p>Update <code>cargo-dinghy@latest</code> to 0.8.6.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 48.0.0.</p> </li> </ul> <h2>2.86.4</h2> <ul> <li> <p>Update <code>oxfmt@latest</code> to 1.79.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.8.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.14.0.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.56.0.</p> </li> <li> <p>Update <code>cargo-about@latest</code> to 0.9.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.9.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.86.5] - 2026-08-21</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.4.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.257.1.</p> </li> <li> <p>Update <code>protoc@latest</code> to 3.36.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.10.</p> </li> <li> <p>Update <code>cargo-dinghy@latest</code> to 0.8.6.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 48.0.0.</p> </li> </ul> <h2>[2.86.4] - 2026-08-20</h2> <ul> <li> <p>Update <code>oxfmt@latest</code> to 1.79.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.8.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.14.0.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.56.0.</p> </li> <li> <p>Update <code>cargo-about@latest</code> to 0.9.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.9.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/ba47c86ac325773530516bb756137ac718732518"><code>ba47c86</code></a> Release 2.86.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/5e0b59bc928f672ccd1072a19b6815d0cf5b21cb"><code>5e0b59b</code></a> Update <code>zola@latest</code> to 0.23.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/60dfdd7edfbb113f6254c9b3889a61fb3e20baf4"><code>60dfdd7</code></a> Update <code>wasm-tools@latest</code> to 1.257.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/c262502059d0289897f7720971cb62c8b83217f1"><code>c262502</code></a> Update <code>protoc@latest</code> to 3.36.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/4985cbc05f60164fac55ad0f7e788c0a97fd2aed"><code>4985cbc</code></a> Update <code>mise@latest</code> to 2026.8.10</li> <li><a href="https://github.com/taiki-e/install-action/commit/e782b6cb9189134d57cdae9cdf8ac0ae4c62384c"><code>e782b6c</code></a> Update <code>cargo-dinghy@latest</code> to 0.8.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/e891b49f0d0c25fc74d5bf0f29a720e43c063750"><code>e891b49</code></a> Update biome manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/394bb5ddf8b2bba382638dadf8c93ff59b9b3fb5"><code>394bb5d</code></a> Update wasmtime manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/a2a5f6e99e1a31540baa0468acfa302cff0f359f"><code>a2a5f6e</code></a> Release 2.86.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/5afbb1a197d47fef2a5793727b494b64e09ac265"><code>5afbb1a</code></a> Update wasm-tools manifest</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.86.3...v2.86.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
df2bc6e7f1 |
Require Git 2.43 and test it nightly (#3895)
Worktrunk now uses Git 2.43 as its tested support baseline and checks the version once before dispatching a command. Git 2.43 is Ubuntu 24.04's system package, so CI can exercise the full supported range with an exact nightly row. This is a policy cutoff rather than a feature boundary; Git-dependent commands on older versions fail centrally instead of accumulating compatibility branches. The Git-independent `config shell` namespace remains available so shell startup and generated integration still work while Git is upgraded. The existing nightly full-test matrix gains an exact Git 2.43.0 row. Test fixtures that isolate PATH retain the runner-selected Git instead of falling back to an older platform Git. `wt step relocate` uses `git switch` because Git 2.43 does not support `git checkout --end-of-options`, and the worktree-registration test now lets each Git version generate metadata it can consume. Tested with the full 4,680-test suite on exact Git 2.43.0 and the normal development environment. Also validated the Ubuntu 24.04 amd64 package installation and the workflow with `actionlint`. > _This was written by Codex on behalf of @max-sixty_ |
||
|
|
68cc911eb2 |
ci(tend): reach the pre-merge gate's tools from inside the sandbox (#3897)
The agent tend runs as, `tend-sandbox`, could not reach `cargo-insta`, `cargo-nextest`, or `pre-commit` — all three of the tools `cargo run -- hook pre-merge --yes` invokes. That command is what `CLAUDE.md` and `.claude/skills/running-tend/SKILL.md` tell the bot to verify its work with, and in the sandbox it died at `✗ pre-merge command failed: pre-commit: exit status: 127`. Tend derives the sandbox's PATH from the runner's, rewriting a leading `/home/runner` to `/home/tend-sandbox` and keeping an entry only where the rewritten directory exists. `useradd -m` seeds the sandbox home from `/etc/skel`, so a toolchain baked into the runner image has a sibling there and survives; anything `tend-setup` installs at runtime into the runner's home has none and is dropped, with nothing logged. `baptiste0928/cargo-install` forces `--root $HOME/.cargo-install/<crate>` and `uv tool install` writes to the runner's `~/.local/bin`, so all three went the second way. `uv` itself stayed reachable only because `astral-sh/setup-uv` puts it under `/opt/hostedtoolcache`, a system path the rewrite leaves alone. `sandbox_setup:` runs as the sandbox user once its PATH is built, with `~/.local/bin` already first on it. `pre-commit` installs into the sandbox's own home so uv's shim shebang resolves there; the cargo binaries are copied from where `tend-setup` already built them, at the versions pinned there. The closing probe is the assertion — `sandbox-setup.sh` runs the block under `bash -eo pipefail`, so a tool that goes missing again fails the job and files a `tend-outage` issue naming it, rather than degrading quietly. A fourth tool needed the same treatment by a different route. The gate's `insta` step runs `--all-features`, which turns on `shell-integration-tests`; that needs `nu` as much as zsh and fish, and two tests `.expect()` it outright. `tend-setup` apt-installed only zsh and fish, so the probe would have cleared the agent to run a gate that then died on a missing shell. `hustcer/setup-nu` installs under `/opt/hostedtoolcache`, a system path the derivation carries across verbatim, so `nu` needs no `sandbox_setup:` line — it just needed installing. Pinned at 0.115.0, level with `test-setup` and `dev/codex.sh`; `running-tend`'s weekly pin-bump recipe enumerates the `setup-nu` call sites, so it gains the fifth. The remaining `shell-integration-tests` prerequisites — bash, zsh, fish, pwsh, jq — all resolve from `/usr/bin`, which the derivation keeps, so they were never affected. The probe deliberately covers only the four tools `tend-setup` provisions for the agent rather than everything the gate touches. The generated `tend-*.yaml` files are `uvx tend@latest init` output (still 0.1.18); the only change in each is the `sandbox_setup:` block. #3891 landed mid-review and appended its Nix steps at the same end-of-file anchor as the nushell step, so this branch carries a merge resolving that — keeping both, nushell next to the shells it belongs with. Its Nix comment restated the "system PATH entries carry into the sandbox verbatim" rule that this PR centralizes in `.github/CLAUDE.md`, which would have left the rule written three times in one file, so it now points there and keeps only what's specific to Nix. Every #3891 step is unchanged. <details><summary>Evidence, and what it cost</summary> Sandbox PATH, captured from the agent's own launch env in tend-weekly run 32630901712: ``` /home/tend-sandbox/.local/bin:/opt/hostedtoolcache/uv/0.12.5/x86_64:/opt/pipx_bin:/home/tend-sandbox/.cargo/bin:/usr/local/.ghcup/bin:/home/tend-sandbox/.dotnet/tools:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games ``` `error: no such command: insta` appears in runs 31332910927, 31465475753 and 32436240803; `pre-commit: command not found` in 32662391023. Across 3,057 captured Bash calls the bot never once invoked `cargo nextest`, and substituted `cargo test` with `INSTA_UPDATE=always` or `INSTA_FORCE_UPDATE=1` fifteen times — which writes snapshots rather than checking them, and never runs `--check` or `--unreferenced reject`. Since 2026-06-18, when #3122 moved the repo to tend 0.1.6 and the agent first ran sandboxed, 16 of 197 bot PRs pushed a first commit with the `lint` job red. Over the same window 4 of 350 of the maintainer's own PRs did. #3845 is the shape: a closure `cargo fmt` wanted on one line, caught by CI rather than locally. Verified by simulating the block under `bash -eo pipefail` against a fake runner home, in both directions: all three tools land on PATH and it exits 0; remove one and it prints the `::error::` naming it and exits 1. Two things changed after that test — `install -D` is GNU-only, so the parent directory is created explicitly, and `command -v a b c` exits 0 when any one resolves, so the assertion is a loop rather than a single call. </details> > _This was written by Claude Code on behalf of max-sixty_ --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
2960bfba2a |
ci(tend-setup): install Nix so the weekly bot can refresh flake.lock (#3891)
The weekly MSRV/toolchain bump has to refresh `flake.lock` after moving
`rust-toolchain.toml`, and `running-tend` told the bot to install Nix
inside its own session with the Determinate installer. That could never
work: tend runs the agent as a sandbox user created with plain `useradd`
and never granted sudo, so an installer that has to create `/nix` fails
on every run. The `nix eval` check below it was downstream of the same
dead installer.
Nix now gets provisioned in the layer that does have root.
`.github/actions/tend-setup` runs as `runner` before the tend action
starts, so `cachix/install-nix-action` succeeds there — the same action
`nightly.yaml`'s `nix-flake` job already uses. The skill's recipe
becomes `nix flake update` plus `nix eval`.
The codecov section also loses its parenthetical blessing "pre-built
single-script installers like Determinate Nix's", which pointed at the
recipe this removes.
<details>
<summary>Why the sandbox agent sees <code>nix</code> without a
<code>sandbox_path:</code> entry</summary>
Installing as `runner` is necessary but not sufficient — the agent runs
as a different UID with a `PATH` tend derives from the runner's. Each
link was checked against a source or a live run rather than assumed:
| Link | Evidence |
|------|----------|
| The action performs a multi-user install and appends
`/nix/var/nix/profiles/default/bin` to `$GITHUB_PATH` | `install-nix.sh`
takes the daemon branch when `/run/systemd/system` exists, then `echo
"/nix/var/nix/profiles/default/bin" >> "$GITHUB_PATH"`. The nightly
`nix-flake` job's log shows `installer options: … --daemon
--daemon-user-count 8` |
| tend keeps that entry verbatim | `proxy/setup-sandbox.sh` rewrites
only PATH entries under the runner's home to the sandbox's own copy;
other entries survive if they exist and `sudo -u <sandbox> test -x`
passes |
| …and it does so in practice | A live sandbox `PATH` captured in
tend-weekly run `32630901712` keeps `/opt/pipx_bin`,
`/opt/hostedtoolcache/uv/0.12.5/x86_64`, `/usr/local/.ghcup/bin` and
`/usr/local/bin` verbatim, while rewriting `.cargo/bin` and
`.dotnet/tools` to `/home/tend-sandbox/…`.
`/nix/var/nix/profiles/default/bin` is the first shape, not the second |
| The sandbox UID can traverse it | Nix's `install-multi-user.sh`
creates `/nix`, `/nix/var`, `/nix/var/nix`, `/nix/var/nix/profiles` with
`install -dv -m 0755`, and `/nix/store` with `-m 1775` |
| An unprivileged, non-trusted user can drive the daemon | The daemon's
listening socket is created with `.socketMode = 0666` |
| Fetching works through tend's MITM proxy | `libfetchers/tarball.cc`
fetches in the evaluating client, not the daemon, so it inherits the
sandbox's `https_proxy`. `FileTransferSettings::getDefaultSSLCertFile()`
honours `SSL_CERT_FILE`, which the sandbox sets to the bundle
`update-ca-certificates` put the proxy CA into |
`.config/tend.yaml` is untouched. The first weekly run after this merges
is what confirms the chain end to end.
</details>
A second step then strips a credential the install would otherwise leave
lying around, while `runner` is still the only unprivileged user on the
machine — tend does not create the sandbox user until its own action
starts.
`install-nix.sh` writes `access-tokens = github.com=<job token>` into
`/etc/nix/nix.conf` whenever it can see one, and the action's
`action.yml` passes `GITHUB_TOKEN: ${{ github.token }}` unconditionally,
so `github_access_token: ""` does not suppress it — the script falls
through to the job token. The installer creates `/etc/nix` at `0555` and
`nix.conf` at `0644`, so a sandboxed agent could `cat` a token carrying
`contents: write` and `pull-requests: write`.
That matters more than it first appears. The agent already wields the
bot's identity on GitHub, because the proxy injects it per-request — but
it never *holds* a secret, and nothing blocks egress, so a token in a
readable file could be carried to any host through the CONNECT tunnel.
The step deletes the line and fails if one survives. Nix loses nothing
by it, since the proxy overwrites `Authorization` on every sandbox
request to `github.com`, `codeload.github.com`, and `api.github.com`
regardless of what nix sends.
`DeterminateSystems/nix-installer-action` would avoid the write instead
of undoing it — `github-token: ""` maps to `null` and the
`access-tokens` line is then never appended. That was weighed against a
second Nix installer in the repo, with its own pin for the weekly bump
pass to track, and against `nightly.yaml`'s `nix-flake` job wanting the
opposite (it passes `access-tokens` deliberately, for the rate limit).
One installer plus an explicit scrub won.
Cost is ~4 s, measured off the `Install Nix` step in nightly run
`32592923294`, so every tend workflow pays it rather than gating on
which one is running.
The recipe names the input — `nix flake update rust-overlay` — so a
toolchain-scoped PR doesn't also relock nixpkgs, and says what to do
when `nix` is absent (report that `tend-setup` regressed; don't
hand-compute a lock entry, which is how this failed the first time).
### Overlaps [#3880](https://github.com/max-sixty/worktrunk/pull/3880)
That PR arrived at the same fix independently while this branch was in
flight, then dropped its own `install-nix-action` step; it no longer
touches `.github/actions/tend-setup/action.yaml` at all. Both still edit
the same section of `running-tend`, and they merge without conflict
(`git merge-tree --write-tree`, zero markers) because the wording
converged. #3880 carries the weekly work this unblocks — the MSRV bump,
`flake.lock`, and nightly's `rustup` pins — and its recipe now calls a
`nix` only this PR installs, so it wants this to land first.
> _This was written by Claude Code on behalf of max-sixty_
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
||
|
|
de4e7940b9 |
fix(docs): pin typescript to ^6 so npm ci resolves (#3877)
`publish-docs` is red on `main`: `@astrojs/check@0.9.10` declares `peer typescript@"^5.0.0 || ^6.0.0"`, so the TypeScript 7 lockfile that landed in #3870 makes `npm ci` fail with `ERESOLVE` before any docs step runs. This reverts `docs/package.json` + `docs/package-lock.json` to their pre-bump state and tells Dependabot to skip TypeScript majors until `@astrojs/check` accepts `^7`. Verified locally with `npm ci` and `npm run check`. ## Problem [Run 32615600271](https://github.com/max-sixty/worktrunk/actions/runs/32615600271) failed at the **Install docs dependencies** step of `.github/actions/docs-build`: ``` npm error While resolving: @astrojs/check@0.9.10 npm error Found: typescript@7.0.2 npm error Could not resolve dependency: npm error peer typescript@"^5.0.0 || ^6.0.0" from @astrojs/check@0.9.10 ``` `check-docs` had already failed the same way on #3870 itself ([run 32558778950](https://github.com/max-sixty/worktrunk/actions/runs/32558778950/job/97003062280)), so the breakage merged rather than appearing after it. Every `publish-docs` run since is red — `64efa5e5d` and `be2c088a6` (current `main`) — and every subsequent run will be, because the failure is in dependency installation, not in anything docs content can change. There is no upstream fix to move to: `0.9.10` is the latest `@astrojs/check`, and its peer range still excludes `^7`. ## Solution Three parts, two durable: 1. **Revert the bump.** `docs/package.json` goes back to `typescript: "^6.0.3"` and `docs/package-lock.json` is restored byte-for-byte to `8e405bced` (#3870's merge base) rather than regenerated — #3870 is the only commit to touch either file since, and the local npm is 10.9.8 against CI's 11.17.0, which would otherwise strip `libc` metadata from ~20 optional dependency entries as unrelated churn. The lockfile diff is exactly the inverse of #3870's. 2. **Stop it recurring.** An `ignore` entry for `typescript` `version-update:semver-major` under the `/docs` npm ecosystem. Without it Dependabot reproposes the identical bump next week, and the fix is a revert each time. Minor and patch TypeScript 6 updates still flow through the `docs-site` group; the comment names the condition for removing the entry. 3. **Give that condition a reader.** The `ignore` entry suppresses the only proposal Dependabot would ever make for it, so nothing surfaces when `@astrojs/check` widens its peer range — and the rule is version-agnostic, so it would go on blocking a TypeScript major `@astrojs/check` fully supports. The weekly **CI Pin Bumps** pass is where versions Dependabot can't see get revisited, and it currently says to skip `docs/package.json` outright; `.claude/skills/running-tend/SKILL.md` now names this entry as the exception that pass owns, with the `npm view` check to run and the condition for deleting it. Pinning at the manifest is the right level here — the alternative fixes (`npm ci --legacy-peer-deps` in the composite action, or an `overrides` block) would silence the peer conflict for *every* dependency rather than the one that is genuinely incompatible, and would let a real breakage install quietly. ## Testing Ran the CI install and check steps locally against the fixed tree, in `docs/`: <details><summary>Verification output</summary> ``` $ rm -rf node_modules && npm ci --ignore-scripts added 450 packages, and audited 451 packages in 5s found 0 vulnerabilities NPM_CI_EXIT=0 $ npm run check [check] Getting diagnostics for Astro files in /home/runner/work/worktrunk/worktrunk/docs... Result (7 files): - 0 errors - 0 warnings - 0 hints CHECK_EXIT=0 ``` `npm ci` left the lockfile unmodified, confirming manifest and lockfile agree. The remaining `docs-build` steps (`npm test`, `npm run build`, `npm run test:site`) need the `worktrunk-assets` clone, so CI covers those — `check-docs` on this PR exercises the whole action. </details> Fixes #3879 — the scheduled `nightly` run auto-filed it for the same `ERESOLVE` on `link-check` ([run 32621228902](https://github.com/max-sixty/worktrunk/actions/runs/32621228902)). --- Automated fix for [failed run](https://github.com/max-sixty/worktrunk/actions/runs/32615600271) --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
e3adde218f |
ci: share the docs build action (#3874)
PR validation, nightly link checking, and docs publishing each had their own copy of the Astro setup and build steps. This moves that sequence into one local composite action and makes all three jobs run the same checks, asset fetch, build, and built-site tests. The workflow path filters now include the shared action, so changes to it exercise PR validation and the publishing path. The single `setup-node` pin is v7, superseding the three-copy bump in #3869. Tested with the full docs command sequence, Actionlint, YAML validation, and action metadata validation. > _This was written by Codex on behalf of @max-sixty_ |
||
|
|
8e405bced9 |
docs: rebuild the site with Astro and Starlight (#3866)
The docs now build with Astro and Starlight instead of Zola. This removes the Tera 2 migration blocker from #3827 while keeping the published routes, anchors, generated references, metadata, and crawler URLs stable. It replaces the approach closed in #3840. ## What changed - Move the site into Starlight, with a custom Worktrunk homepage and a shared copper, gold, paper, and ink design system. - Keep generated docs as portable Markdown. The Rust sync pipeline no longer needs Zola shortcodes, template escaping, ANSI-to-HTML conversion, or reverse transforms for skill and README output. - Preserve terminal semantics and command-only copying, add responsive handling for short wide tables, retain stable heading IDs, and give repeated command-reference headings useful search labels. - Move docs CI and publishing to Node, Astro, and built-site contract tests. The tests cover public routes, links, assets, metadata, navigation, tables, terminal frames, and compatibility aliases. - Record demo themes from isolated environments, add a mobile core demo, and test the recording contract. The matching mobile assets are published in `max-sixty/worktrunk-assets`. Closes #3827. ## Verification - `cargo run -- hook pre-merge --yes` (4,660 tests) - `npm --prefix docs run check` - `npm --prefix docs test` (9 tests) - `npm --prefix docs run build` (16 pages) - `npm --prefix docs run test:site` (12 tests) - `pytest docs/demos/tests/test_recording.py` (4 tests) > _This was written by Codex on behalf of max-sixty_ |
||
|
|
ad803987ad |
chore: bump taiki-e/install-action from 2.86.2 to 2.86.3 (#3862)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.86.2 to 2.86.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.86.3</h2> <ul> <li> <p>Update <code>prek@latest</code> to 0.4.14.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.5.1.</p> </li> <li> <p>Update <code>cargo-llvm-cov@latest</code> to 0.9.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.86.3] - 2026-08-18</h2> <ul> <li> <p>Update <code>prek@latest</code> to 0.4.14.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.5.1.</p> </li> <li> <p>Update <code>cargo-llvm-cov@latest</code> to 0.9.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/5b4d68e2e660441203ab128a23676f1e4faf1532"><code>5b4d68e</code></a> Release 2.86.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/82754b800cccabcaf4235c23ec7928b52ecf3581"><code>82754b8</code></a> Update <code>prek@latest</code> to 0.4.14</li> <li><a href="https://github.com/taiki-e/install-action/commit/e90445abe560105799df7c7d631cf8cd6b97c958"><code>e90445a</code></a> Update <code>osv-scanner@latest</code> to 2.5.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/a7016b999bbc1e1c1590e629abc56decf9014516"><code>a7016b9</code></a> Update mise manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/330a629dce907cc92a7d2f6c530ec3a1fc4372c2"><code>330a629</code></a> Update <code>cargo-llvm-cov@latest</code> to 0.9.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/5582db7a6a920e00c05bbdd554d533fdc6e592d5"><code>5582db7</code></a> Update biome manifest</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.86.2...v2.86.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
9c37aae5b9 |
ci(tend-setup): bound apt-get so a wedged mirror can't burn the job cap (#3855)
Five tend jobs on 2026-08-18/19 hung in `tend-setup`'s `sudo apt-get update` and were killed at GitHub's 360-minute job cap, each burning six hours without ever booting the agent. The two calls are now bounded with `timeout 300`, so an unreachable mirror fails the job in five minutes instead of six hours. Verification is the next tend run: a healthy `apt-get update` on these runners takes ~15 s, so a green setup step confirms the bound is headroom rather than a new failure mode. The cost isn't only compute. `tend-review` [32095910705](https://github.com/max-sixty/worktrunk/actions/runs/32095910705) was the only review #3843 was ever going to get — `pull_request_target` doesn't re-fire without a push, and that dependabot PR merged at 15:52Z with `reviews: []` while its review job sat in apt. That is the "missed review, not late review" case [max-sixty/tend#962](https://github.com/max-sixty/tend/issues/962) was closed pending; I've posted the evidence there, since the job-level `timeout-minutes` question it raises belongs upstream and is a sizing call, not a bug fix. <details><summary>Evidence: the five wedged runs</summary> All five died in the same step (`__self.__run_2`, `Install shells (zsh, fish)`), with the same `duration_ms` — ~21.59 M, i.e. the 360-minute cap — and the same terminal `##[error]The operation was canceled.` GitHub reports a job-timeout kill as `cancelled`, which is why none of them show as `failure`. | run | workflow | started | killed | step duration | what it stranded | |---|---|---|---|---|---| | [32095910705](https://github.com/max-sixty/worktrunk/actions/runs/32095910705) | tend-review | 08-18 03:33Z | 09:33Z | 21,591,590 ms | #3843 merged unreviewed | | [32223334370](https://github.com/max-sixty/worktrunk/actions/runs/32223334370) | tend-nightly | 08-19 06:25Z | 12:25Z | 21,587,692 ms | one nightly sweep (next tick recovered) | | [32226926018](https://github.com/max-sixty/worktrunk/actions/runs/32226926018) | tend-mention | 08-19 07:14Z | 13:15Z | 21,608,063 ms | `max-sixty`'s "can we simplify?" on #3846 | | [32230273316](https://github.com/max-sixty/worktrunk/actions/runs/32230273316) | tend-review-runs | 08-19 07:57Z | 13:57Z | 21,596,592 ms | the 08-19 sweep (this run's window widened to 48 h to cover it) | | [32232437597](https://github.com/max-sixty/worktrunk/actions/runs/32232437597) | tend-notifications | 08-19 08:24Z | 14:24Z | 21,593,512 ms | one poll (next tick recovered) | The last log line before each six-hour silence is mid-`apt-get update`, in the mirror-fallback loop — repeated `Ign:` against `azure.archive.ubuntu.com`, then `Get:` against `archive.ubuntu.com`, then nothing: ``` 2026-08-19T07:59:14.1259813Z Ign:14 http://azure.archive.ubuntu.com/ubuntu noble-updates/main amd64 Packages 2026-08-19T07:59:14.1262122Z Ign:15 http://azure.archive.ubuntu.com/ubuntu noble-updates/main Translation-en [ ~6 hours of nothing ] 2026-08-19T13:57:55.8550938Z ##[error]The operation was canceled. ``` Because the kill lands before the tend action's failure handler, none of the five uploaded a session-log artifact or filed a `tend-outage` row — the outage issue was empty all window, and only the run census caught them. The stranded mention did recover, but slowly and by accident: `tend-notifications` [32258453408](https://github.com/max-sixty/worktrunk/actions/runs/32258453408) picked up the unanswered comment at 13:30Z and replied at 13:36Z, 6 h 22 m after it was posted, at $3.00. The safety net worked; it isn't a substitute for the job not wedging. </details> <details><summary>Why `timeout(1)` and not `timeout-minutes`</summary> `timeout-minutes` isn't among the keys accepted on a step inside a composite action — [the metadata-syntax reference](https://docs.github.com/en/actions/reference/workflows-and-actions/metadata-syntax) lists `run`, `shell`, `if`, `name`, `id`, `env`, `working-directory`, `uses`, `with`, `continue-on-error` and nothing else — so the bound has to live in the `run:` body. `sudo timeout …` rather than `timeout sudo …` puts the timer inside the privileged process, so it can signal apt directly. `-k 30` is what makes the bound a bound: plain `timeout` sends SIGTERM and then gives up, so an apt — or one of the acquire-method children it spawns — that doesn't die on that signal would run the step back out to the 360-minute cap with a bound in place that reads as if it applied. Either exit fails the step: 124 when SIGTERM lands it, 137 after the SIGKILL escalation. Scoped to `tend-setup` because that's where the five occurrences are and where no human is watching a wedged job. The same unbounded `sudo apt-get update` appears in `.github/actions/test-setup/action.yaml`, `nightly.yaml` (×2), `coverage.yaml`, and `benchmarks.yaml` — identical exposure, zero observed occurrences, and a hang there is loud because it blocks a PR someone is waiting on. Happy to widen if you'd rather have it uniform; it seemed like your call rather than mine. </details> --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
8118d1a145 |
chore: bump taiki-e/install-action from 2.86.1 to 2.86.2 (#3854)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.86.1 to 2.86.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.86.2</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.5.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.6.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.86.2] - 2026-08-17</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.5.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.6.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/b6b84cf49ebfe0176417bdce007c624f0db37f20"><code>b6b84cf</code></a> Release 2.86.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/822eb9a731103a6afbfa603ab7ff02185a124607"><code>822eb9a</code></a> Update <code>uv@latest</code> to 0.12.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/5c017c5438cad8fb6e9855caae3622dd889862ee"><code>5c017c5</code></a> Update prek manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/f3371b0ada03f6dd26a8a4d2572a504f06b34f82"><code>f3371b0</code></a> Update osv-scanner manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/be4eb9e9090a465654bd22c6ce1fbbbc51fc9bba"><code>be4eb9e</code></a> Update <code>mise@latest</code> to 2026.8.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/235fcbc6389f3fe88ef2441ea5c2b2789683ab85"><code>235fcbc</code></a> Update <code>cargo-tarpaulin@latest</code> to 0.37.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/1d8477e1cae9b584346998400732cf21d82c0a66"><code>1d8477e</code></a> Update cargo-llvm-cov manifest</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.86.1...v2.86.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
a06102fdd5 |
ci(tend-setup): restore the shared rust cache instead of dropping it (#3846)
`tend-setup`'s rust-cache step never restored anything: it looked up
`prefix-key: hashFiles('Cargo.lock')` with no `shared-key`, and computed
its environment hash before `Set build environment` ran, while the
shared cache it could restore is published as `v1-rust`/`shared` with
`CARGO_TERM_COLOR`/`CARGO_INCREMENTAL`/`RUSTFLAGS` already set. This
points it at the shared keys and moves that env step above the cache
step, so a tend job computes
`v1-rust-shared-Linux-x64-6966df26-<lockfile hash>` — the exact key
`test` writes from main. Verified by reproducing rust-cache's key
arithmetic offline: the same hash function that yields today's missing
`dc9f6f9f` from the tend job's environment yields the writer's
`6966df26` from the post-fix one.
One behavior change rides along: `RUSTDOCFLAGS=-Dwarnings` is dropped
rather than worked around. It is the only var here no cache writer sets,
so above the cache step it poisons the key and below it needs a second
env step — and it is redundant either way, since both rustdoc gates set
it inline in `.config/wt.toml` (`doctest`, `doc`), which is what
ci.yaml's `fast-checks` already relies on; that workflow sets no
`RUSTDOCFLAGS` of its own.
<details><summary>The key arithmetic, and how it was verified</summary>
## What was wrong
The shared cache is written by the jobs that call `test-setup` without
`save-cache: false` — `test` and `fast-checks` in ci.yaml, `full-tests`
in nightly.yaml — which publish the Linux entry as
`v1-rust-shared-Linux-x64-6966df26-709538b9` (1034 MB, [run
32157064498](https://github.com/max-sixty/worktrunk/actions/runs/32157064498)).
The nightly tend job
([32106850263](https://github.com/max-sixty/worktrunk/actions/runs/32106850263))
computed `dac153ac…d7975-nightly-Linux-x64-dc9f6f9f-709538b9` and
printed `No cache found.` Three independent mismatches:
1. **prefix** — `hashFiles('Cargo.lock')` vs `v1-rust`.
2. **shared-key** — absent, so rust-cache substitutes the job name
(`nightly`, `handle`, `review`, …) where the writer has `shared`.
3. **env hash** — `dc9f6f9f` vs `6966df26`. Both jobs list the same two
toolchains and the same lockfile hash (`709538b9`); the difference is
entirely which `CARGO*`/`RUST*` vars were exported by the time the cache
step ran. The writer's are `CARGO_INCREMENTAL`, `CARGO_TERM_COLOR`,
`RUSTFLAGS`; the tend job's was `CARGO_INCREMENTAL` alone, because `Set
build environment` sat at the *end* of the composite.
## Verification
rust-cache builds that hash in
[`src/config.ts`](https://github.com/Swatinem/rust-cache/blob/v2/src/config.ts):
sha1 over each installed toolchain's `<release> <host> <commit-hash>`,
then each matching `KEY=VALUE` in sorted key order, truncated to 8 hex
chars. Replaying it against the environments both jobs logged reproduces
both observed hashes exactly, which is what makes the third prediction
trustworthy:
```python
import hashlib
rust = ["1.96.0 x86_64-unknown-linux-gnu ac68faa20c58cbccd01ee7208bf3b6e93a7d7f96",
"1.97.1 x86_64-unknown-linux-gnu 8bab26f4f68e0e26f0bb7960be334d5b520ea452"]
def env_hash(pairs):
h = hashlib.sha1()
for r in rust: h.update(r.encode())
for k, v in sorted(pairs): h.update(f"{k}={v}".encode())
return h.hexdigest()[:8]
INCR = ("CARGO_INCREMENTAL", "0")
COLOR = ("CARGO_TERM_COLOR", "always")
FLAGS = ("RUSTFLAGS", "-C debuginfo=0")
DOC = ("RUSTDOCFLAGS", "-Dwarnings")
env_hash([INCR]) # dc9f6f9f — tend today, matches the logged miss
env_hash([INCR, COLOR, FLAGS]) # 6966df26 — the writer, and this PR
env_hash([INCR, COLOR, DOC, FLAGS]) # 2c91e6ea — RUSTDOCFLAGS kept above the step
```
The third line is why `RUSTDOCFLAGS` had to be dealt with rather than
left alongside the other three: it sorts between `CARGO_TERM_COLOR` and
`RUSTFLAGS`, and no writer sets it, so including it produces a key
nothing has written — the same silent miss, differently caused.
`cache-bin` is the fourth field that had to move, and it is not part of
the key string: it decides the *paths* list, and `actions/cache` derives
an entry's version from those paths — so the old `cache-bin: true` (six
paths, including `~/.cargo/bin`) would have missed the writer's
three-path entry even with a correct key. One incidental detail, since
it explains an odd line in the logs: `CARGO_INCREMENTAL` shows up in the
tend job's considered set even before anything exported it, because
rust-cache's own `restore.ts` calls
`core.exportVariable("CARGO_INCREMENTAL", 0)` first. It is equal on both
sides either way; the composite exports it regardless, to keep the three
in step with ci.yaml's `env:` block for the builds that follow.
There is no live check before merge, and that's worth being explicit
about: every tend workflow runs this composite against the **base** tree
— tend-review is `pull_request_target`, and the scheduled workflows
check out `main` — so this PR's own tend runs still load main's version
and log the old `dac153ac…-review-Linux-x64-dc9f6f9f` key and `No cache
found.` The first tend run after this merges is the confirmation; a
wrong answer shows up as a `No cache found.` line in that job's Cache
Configuration group.
## Cost
A restore moves ~1 GB and takes ~35 s, against ~13 s previously spent
computing a key nothing had written. Compiling sessions win that back
many times over (the nightly session ran 5 `cargo test` invocations plus
clippy and fmt; a Zola-migration session ran 17, with one `--lib --bins`
+ integration block occupying 15.6 min of its 68). No workflow pays it
on an idle tick. `tend-notifications` polls every ~15 min, but its
`actions/checkout` and `tend-setup` steps carry the same
`steps.check.outputs.count != '0' || github.event_name ==
'workflow_dispatch'` condition as the agent step, so a poll that finds
nothing to process skips the composite entirely. Every run that restores
the cache is a run that boots a session — which is where the compiles
are — so the per-workflow carve-out an earlier revision of this
description offered isn't needed.
## History
The key had been untouched since the action was created in #1273
(2026-03-05). #3323 (2026-06-29) introduced the `v1-rust`/`shared`
scheme and moved every other consumer onto it — nightly.yaml's two
restore-only blocks and benchmarks.yaml read identically today — but
didn't reach this file. Observed as a miss on three consecutive daily
sweeps (2026-08-16/17/18), recorded in #3691. The composite was renamed
`claude-setup` → `tend-setup` by #3849 while this PR was open; main is
merged in here, so the change lands on the new path.
</details>
---------
Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
|
||
|
|
50a5edb412 | ci: rename the claude-setup composite to tend-setup (#3849) | ||
|
|
e3c28a0290 |
chore: bump taiki-e/install-action from 2.85.13 to 2.86.1 (#3843)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.13 to 2.86.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.86.1</h2> <ul> <li>Fix an issue where <code>oxfmt</code> was accidentally installed as <code>oxfmt-{target}{exe}</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1969">#1969</a>)</li> </ul> <h2>2.86.0</h2> <ul> <li>Support <code>oxfmt</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1967">#1967</a>, thanks <a href="https://github.com/rami3l"><code>@rami3l</code></a>)</li> </ul> <h2>2.85.14</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.4.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.74.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.4.0.</p> </li> <li> <p>Update <code>mdbook-mermaid@latest</code> to 0.17.1.</p> </li> <li> <p>Update <code>cargo-xwin@latest</code> to 0.23.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.86.1] - 2026-08-15</h2> <ul> <li>Fix an issue where <code>oxfmt</code> was accidentally installed as <code>oxfmt-{target}{exe}</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1969">#1969</a>)</li> </ul> <h2>[2.86.0] - 2026-08-15</h2> <ul> <li>Support <code>oxfmt</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1967">#1967</a>, thanks <a href="https://github.com/rami3l"><code>@rami3l</code></a>)</li> </ul> <h2>[2.85.14] - 2026-08-15</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.4.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.74.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.4.0.</p> </li> <li> <p>Update <code>mdbook-mermaid@latest</code> to 0.17.1.</p> </li> <li> <p>Update <code>cargo-xwin@latest</code> to 0.23.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/288e746965032cfcc232e09af2daf5f23c14d780"><code>288e746</code></a> Release 2.86.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/6012fb0aebafca00cab83d4d647a7d93eae73c49"><code>6012fb0</code></a> Fix oxfmt installation</li> <li><a href="https://github.com/taiki-e/install-action/commit/b27e114ddbae5cc01df19a22cf70a124d5177567"><code>b27e114</code></a> Release 2.86.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/23e8349bb2b39235d3d2f20e8692c84c2c19786c"><code>23e8349</code></a> Update changelog</li> <li><a href="https://github.com/taiki-e/install-action/commit/806f6f7d021b2f83ae8750bd40fa31a91f799a9c"><code>806f6f7</code></a> Support oxfmt on riscv64 Linux</li> <li><a href="https://github.com/taiki-e/install-action/commit/57e465d0bab9888b206abc1071dca4e7db674c69"><code>57e465d</code></a> Support oxfmt (<a href="https://redirect.github.com/taiki-e/install-action/issues/1967">#1967</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/decb84fb327e5b809630c914eb4d1ca67cf59966"><code>decb84f</code></a> Release 2.85.14</li> <li><a href="https://github.com/taiki-e/install-action/commit/1ed90f15b01a8dac288cdede295301e854277a20"><code>1ed90f1</code></a> Update <code>uv@latest</code> to 0.12.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/a2f49bf3cf4c9261f4d5f314c4ed8cab6bc0443a"><code>a2f49bf</code></a> Update <code>trivy@latest</code> to 0.74.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/0d6d274830c10c84ea749eb36e20bd5a5246092b"><code>0d6d274</code></a> Update <code>tombi@latest</code> to 1.4.0</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.13...v2.86.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
61d80b3ab8 |
chore: bump clechasseur/rs-cargo from 5.0.7 to 5.0.8 (#3829)
Bumps [clechasseur/rs-cargo](https://github.com/clechasseur/rs-cargo) from 5.0.7 to 5.0.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/clechasseur/rs-cargo/releases">clechasseur/rs-cargo's releases</a>.</em></p> <blockquote> <h2>v5.0.8</h2> <p>New patch release with updated dependencies to fix some vulnerabilities.</p> <h2>What's Changed</h2> <ul> <li>chore(deps): bump undici from 6.27.0 to 6.28.0 in the npm_and_yarn group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/clechasseur/rs-cargo/pull/435">clechasseur/rs-cargo#435</a></li> <li>chore(deps): bump the npm_and_yarn group across 1 directory with 1 update by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/clechasseur/rs-cargo/pull/436">clechasseur/rs-cargo#436</a></li> <li>fix: <code>npm update</code> to get fixes, update <code>@clechasseur/rs-actions-core</code> to 8.0.4, bump version to 5.0.8 by <a href="https://github.com/clechasseur"><code>@clechasseur</code></a> in <a href="https://redirect.github.com/clechasseur/rs-cargo/pull/437">clechasseur/rs-cargo#437</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/clechasseur/rs-cargo/compare/v5.0.7...v5.0.8">https://github.com/clechasseur/rs-cargo/compare/v5.0.7...v5.0.8</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/clechasseur/rs-cargo/commit/9a5c570d3347f8dee3916c8871f3ffaf38909956"><code>9a5c570</code></a> fix: <code>npm update</code> to get fixes, update <code>@clechasseur/rs-actions-core</code> to 8.0....</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/24c8a774d7e015322005aaca3336016bdc670085"><code>24c8a77</code></a> chore(deps): bump the npm_and_yarn group across 1 directory with 1 update (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/436">#436</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/b2652e1335c7ec927c51a006790e235ad741e1a7"><code>b2652e1</code></a> chore(deps): bump undici in the npm_and_yarn group across 1 directory (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/435">#435</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/44bc6e9a0a8b85197cd377ad859fac1e3e9408bd"><code>44bc6e9</code></a> chore(deps): update dependency rollup to ^4.62.4 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/432">#432</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/e914260698d7251b9589c737040ea88189e1d07e"><code>e914260</code></a> chore(deps): update dependency oxlint to ^1.77.0 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/434">#434</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/952abcd19408ed276d2cb062ba1e680b5d564a1e"><code>952abcd</code></a> chore(deps): update actions/checkout action to v7.0.1 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/431">#431</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/ebc623c7b9c4498bbb97ab84d0d7ef333f5645e0"><code>ebc623c</code></a> chore(deps): update dependency ts-jest to ^29.4.12 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/428">#428</a>)</li> <li><a href="https://github.com/clechasseur/rs-cargo/commit/260bce3fe16b97604f986f900f052ddf2996f71c"><code>260bce3</code></a> chore(deps): update dependency oxlint to ^1.75.0 (<a href="https://redirect.github.com/clechasseur/rs-cargo/issues/430">#430</a>)</li> <li>See full diff in <a href="https://github.com/clechasseur/rs-cargo/compare/v5.0.7...v5.0.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
9c13f6e7d4 |
chore: bump taiki-e/install-action from 2.85.11 to 2.85.13 (#3828)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.11 to 2.85.13. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.13</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.3.3.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.5.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.113.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.4.</p> </li> <li> <p>Update <code>bpf-linker@latest</code> to 0.11.0.</p> </li> </ul> <h2>2.85.12</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.3.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.256.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.10.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.51.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.13.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.4.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.8.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.13] - 2026-08-13</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.3.3.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.5.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.113.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.4.</p> </li> <li> <p>Update <code>bpf-linker@latest</code> to 0.11.0.</p> </li> </ul> <h2>[2.85.12] - 2026-08-12</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.3.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.256.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.10.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.51.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.13.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.4.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.8.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/82cd3e7658a6f96c86c0234aeeda1748937cb0a1"><code>82cd3e7</code></a> Release 2.85.13</li> <li><a href="https://github.com/taiki-e/install-action/commit/4dd6c67d0ecd1fab76c6cecc5931e1239cc16add"><code>4dd6c67</code></a> Update <code>tombi@latest</code> to 1.3.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/91cb1bb28383045bb69f87d336ede6db3c61927b"><code>91cb1bb</code></a> Update <code>mise@latest</code> to 2026.8.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/83d968e89df664219ce13abb14808207a131cc64"><code>83d968e</code></a> Update <code>kingfisher@latest</code> to 1.113.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/f7ab7f5d0a3e5a8120f10f39cfc442b2f40642b0"><code>f7ab7f5</code></a> Update cargo-xwin manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/3faddd9e3002e0d2922192f5808a78c4118eb58c"><code>3faddd9</code></a> Update <code>cargo-shear@latest</code> to 1.13.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/b4cb4b238691473c8bf1425b4d38120d5058dfc2"><code>b4cb4b2</code></a> Update <code>bpf-linker@latest</code> to 0.11.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/b20dedce73af6905cdc30d6611090c9b67557c8d"><code>b20dedc</code></a> Release 2.85.12</li> <li><a href="https://github.com/taiki-e/install-action/commit/952d13c8bb10d7e37f96fa2c8131338550a62663"><code>952d13c</code></a> ci: Skip cargo-rdme on x86_64 macOS</li> <li><a href="https://github.com/taiki-e/install-action/commit/c8724e7258d0b8f8188a94aec0c00ae9da81edd7"><code>c8724e7</code></a> Update <code>zola@latest</code> to 0.23.3</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.11...v2.85.13">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1b278042de |
chore(ci): weekly renovation 2026-08-16 (#3826)
## Summary Weekly CI renovation check found the following updates: - `worktrunk`: 0.72.0 → 0.74.0 (MSRV 1.96, compatible with our 1.96.0) — `ci.yaml` ×2, `nightly.yaml` - `nushell`: 0.114.1 → 0.115.0 — `nightly.yaml`, `benchmarks.yaml`, `coverage.yaml`, `actions/test-setup`, and `scripts/codex-cloud/Taskfile.yaml` - `pre-commit`: 4.6.1 → 4.6.2 — `scripts/codex-cloud/Taskfile.yaml` - `PowerShell`: 7.6.4 → 7.6.5 — `scripts/codex-cloud/Taskfile.yaml` and the root `Taskfile.yaml`'s `setup-web` task The Codex Cloud archive checksums were recomputed from the new upstream tarballs, and the resulting `Taskfile.yaml` digest (`f14dbc89…`) is copied into both README launcher commands. The `setup-web` PowerShell pin came in as a follow-up commit: the initial sweep only grepped `.rs`/`.md`/`.toml` for stale versions, so the root `Taskfile.yaml`'s `PWSH_VERSION="7.6.4"` was missed. Nothing tests the two PowerShell pins against each other, so that one drifts silently — worth a note for future renovation runs. The `powershell_7.6.5-1.deb_amd64.deb` asset the `setup-web` branch downloads is present in the v7.6.5 release. ## Already up to date - Rust stable is 1.97.1, so MSRV and toolchain stay at 1.96 (latest stable − 1) — `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`, `rust-toolchain.toml` need no change, and `flake.lock` is untouched. - `cargo-insta` 1.48.0, `cargo-nextest` 0.9.143, `cargo-llvm-cov` 0.8.7, `cargo-msrv` 0.19.3, `cargo-affected` 0.4.0, `cargo-udeps` 0.1.61, `lychee` 0.24.2 - Task 3.52.0 (mise, Codex Cloud) - Runner images: ubuntu-24.04, macos-15, windows-2022 ## Held back: zola 0.22.1 → 0.23.3 Not bumped. Zola 0.23.0 shipped [Tera2 + refactoring](https://github.com/getzola/zola/pull/3105), which is a templating-engine swap rather than a routine release. Building `docs/` with the 0.23.3 binary fails at the first line of `templates/base.html`: ``` ERROR error: Unknown tag --> base.html:1:4 | 1 | {% import "macros.html" as macros %} | ^^^^^^ ``` `templates/base.html` and `templates/macros.html` are the two files that use the `import`/`macro` pair, so the migration looks small, but it is template work with its own review rather than a pin bump — kept out of this PR so the rest can land. Raised separately. <details><summary>Verification</summary> - Every version above was read from the upstream source of truth: `crates.io` for the cargo tools, `nushell/nushell` and `PowerShell/PowerShell` releases, PyPI for pre-commit, and `static.rust-lang.org/dist/channel-rust-stable.toml` for Rust stable (1.97.1). - Checksums were computed from the downloaded archives and the extracted binaries were run (`nu --version` → `0.115.0`); the archive layouts (`nu-<ver>-x86_64-unknown-linux-gnu/nu`, top-level `pwsh`) are unchanged, so the `install_binary` paths still resolve. - All six edited YAML files parse. - The nushell bump was exercised against the shell-integration suite: `cargo test --features shell-integration-tests --test integration -- nushell` with 0.115.0 on `PATH`. 13 of 14 pass; `test_nushell_install_target_is_a_vendor_autoload_dir` fails — but it fails identically on the currently-pinned 0.114.1, and passes on *both* versions when run alone. It is a pre-existing shared-state race in the sandbox, not a regression from this bump: the test asserts against the real user `$nu.vendor-autoload-dirs` entry rather than one under its temp `HOME` (nu resolves the home dir from the passwd database, so the test's `HOME` override does not move it), and a sibling uninstall test in the same filter removes `wt.nu` from that shared directory. Noted rather than fixed here — it is unrelated to the pins. - The zola failure above was reproduced with the official 0.23.3 `x86_64-unknown-linux-gnu` release binary against this repo's `docs/`. </details> --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
1e2e05cfb4 |
chore: update tend workflows (0.1.17 → 0.1.18) (#3824)
Automated nightly regeneration of tend's workflow files, picking up tend 0.1.18. **tend version:** 0.1.17 → 0.1.18 Notable changes: - `tend-mention`: both halves of the 👀 reaction now live in the `handle` job. Previously `verify` added the eyes and `handle` removed them, so a burst of mentions on one thread could cancel a queued `handle` — which allocates no runner and runs no steps, `always()` included — leaving the reaction stranded (max-sixty/tend#990). - `tend-review` / `tend-triage`: the eyes-removal lookup now paginates (`--paginate`, `per_page=100`). A thread with more than 30 reactions could push the bot's own eyes off the first page, so the removal silently found nothing (max-sixty/tend#990). - `tend check`: the secret audit now reports only org secrets this repo can actually read, instead of every org secret (max-sixty/tend#994). - `running-in-ci` skill: notes that fork PR reviews reach no successor session, and scopes PR-description claims to the merge base (max-sixty/tend#985, max-sixty/tend#992). Full comparison: https://github.com/max-sixty/tend/compare/0.1.17...0.1.18 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
e3b3482fd0 |
chore: update tend workflows (0.1.15 → 0.1.17) (#3822)
Automated nightly regeneration of tend's workflow files. **tend version:** 0.1.15 → 0.1.17 **Notable changes** - 👀 reactions now mark a session in flight: the bot reacts when an issue or PR is opened, and the reaction comes off when the session ends (max-sixty/tend#974, max-sixty/tend#979). - Mention gating was reworked — coarser pre-check gates, tested poll scripts, and an anchor-based run window replace the hand-rolled matching (max-sixty/tend#965, max-sixty/tend#971). - Self-initiated fixes are now gated on cost as well as evidence, so the bot doesn't open a PR whose value doesn't justify the session (max-sixty/tend#960). - `tend check` reads the bot's own bypass verdict on repos where the actor list is withheld, instead of reporting a false FAIL (max-sixty/tend#976). - Weekly no longer trusts a re-anchored approval on a rebased dependency PR (max-sixty/tend#890), and review-reviewers is paused as a scheduled sweep, kept as a manual spot-check (max-sixty/tend#966). Compare: https://github.com/max-sixty/tend/compare/0.1.15...0.1.17 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
c31e827cba |
chore: update tend workflows (0.1.14 → 0.1.15) (#3814)
Automated nightly regeneration of tend's workflow files. **tend version:** 0.1.14 → 0.1.15 **Notable changes** - **Rate-limit handling**: a maintainer can approve past the spike limit (max-sixty/tend#874), and `tend-mention` now skips comments on `tend-rate-limit`-labelled issues as well as `tend-outage` ones — the same self-trigger loop guard, widened to every issue tend files about its own health. - **Review flow**: a push is queued behind an examined-HEAD gate instead of cancelling the in-flight review (max-sixty/tend#903), the review is submitted before a fix is pushed (max-sixty/tend#834), a force-push triggers a re-review rather than trusting the re-anchored SHA (max-sixty/tend#884), and the `/code-review` second pass is unconditional (max-sixty/tend#937). - **CI monitoring**: both the check poll and the `gh run rerun --failed` poll now end terminally when the cap is hit instead of reading as done (max-sixty/tend#876, max-sixty/tend#951), and a failed GitHub-status probe no longer reads as "no incident" (max-sixty/tend#913). - **Nightly**: conflicted bot PRs are test-merged locally instead of filtered on the lazy `mergeable` field (max-sixty/tend#898), and mention runs skip the bot's own review and a third party's content-free approval (max-sixty/tend#916, max-sixty/tend#955). - **`tend check`**: an unreadable ruleset bypass list is reported as unknown rather than ungated (max-sixty/tend#825), environment names are read one per line and addressed encoded (max-sixty/tend#879), and `credential-environments` no longer points at the setting it rejects (max-sixty/tend#900) — this repo currently `SKIP`s that check, so its wording should improve here. Full comparison: https://github.com/max-sixty/tend/compare/0.1.14...0.1.15 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
ab76101b0b |
chore: bump taiki-e/install-action from 2.85.10 to 2.85.11 (#3801)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.10 to 2.85.11. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.11</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.2.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.3.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.5.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.3.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.112.0.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.11] - 2026-08-09</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.2.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.3.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.5.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.3.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.112.0.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/7f4eb899022d8fe70b20c4f3de697aa85c309026"><code>7f4eb89</code></a> Release 2.85.11</li> <li><a href="https://github.com/taiki-e/install-action/commit/c17da6245a7fe549cefa05b31e3614ce0b16c2af"><code>c17da62</code></a> Update <code>zola@latest</code> to 0.23.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/97e8291c2ba440a7119c03ebe3ed1e584a1f9b7f"><code>97e8291</code></a> Update <code>wasm-bindgen@latest</code> to 0.2.127</li> <li><a href="https://github.com/taiki-e/install-action/commit/91f9e5c61a2dc7936a8f404d01b7c1551b9c581a"><code>91f9e5c</code></a> Update <code>uv@latest</code> to 0.12.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/bd0cb00440414f36db2f79bca8e27971bb63b2a3"><code>bd0cb00</code></a> Update <code>osv-scanner@latest</code> to 2.5.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/4def957aa80c252e2d4c61387c6a429d377907d1"><code>4def957</code></a> Update <code>mise@latest</code> to 2026.8.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/3d149dc3890afe4774d158d353b5a3e55fe90f60"><code>3d149dc</code></a> Update <code>kingfisher@latest</code> to 1.112.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/20d4381a5cf6917520fde30f9ff52387410bfb6e"><code>20d4381</code></a> Update <code>editorconfig-checker@latest</code> to 3.10.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/583939ec0c8ee9c523cc60342d3d979ce6730f38"><code>583939e</code></a> codegen: Ignore clippy::assert_is_empty lint</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.85.10...v2.85.11">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ec2aa4d154 |
chore: bump taiki-e/install-action from 2.85.8 to 2.85.10 (#3793)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.8 to 2.85.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.10</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.2.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.7.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.3.</p> </li> <li> <p>Update <code>coreutils@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.3.</p> </li> </ul> <h2>2.85.9</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.1.</p> </li> <li> <p>Update <code>wild@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.2.</p> </li> <li> <p>Update <code>just@latest</code> to 1.58.0.</p> </li> <li> <p>Update <code>jaq@latest</code> to 3.1.1.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.7.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.10] - 2026-08-07</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.2.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.7.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.3.</p> </li> <li> <p>Update <code>coreutils@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.3.</p> </li> </ul> <h2>[2.85.9] - 2026-08-06</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.1.</p> </li> <li> <p>Update <code>wild@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.2.</p> </li> <li> <p>Update <code>just@latest</code> to 1.58.0.</p> </li> <li> <p>Update <code>jaq@latest</code> to 3.1.1.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.7.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/6c6fd71fe4fb72c3697d269963d0e15df8adedad"><code>6c6fd71</code></a> Release 2.85.10</li> <li><a href="https://github.com/taiki-e/install-action/commit/37cec23487191ef9aef8b1315865bd6dc584bef4"><code>37cec23</code></a> Update zola manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/4914ea4fea5759852f8cda51753420130b883d65"><code>4914ea4</code></a> Update <code>uv@latest</code> to 0.12.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/0ce64163d455e35fedc5f5925221d4a71f05c990"><code>0ce6416</code></a> Update <code>tombi@latest</code> to 1.2.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/1f89e2fb52c482b53fcf083bf64b5abd5d6563ab"><code>1f89e2f</code></a> Update osv-scanner manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/65ef13f21e6dd200e402682be3b1bc896f6aa862"><code>65ef13f</code></a> Update kingfisher manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/9f6a5a8ec701c59d62ac1013b92714e7410b2cae"><code>9f6a5a8</code></a> Update <code>cosign@latest</code> to 3.1.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/df08c38f9c0580a749efefc712ba563ff2107db5"><code>df08c38</code></a> Update <code>coreutils@latest</code> to 0.10.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/dc7bb1f807a876bf372de55372b320860efe4019"><code>dc7bb1f</code></a> Update <code>cargo-rdme@latest</code> to 2.2.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9970698e35256036b84ecfb8a70b90fe068a934b"><code>9970698</code></a> Update <code>cargo-crap@latest</code> to 0.4.3</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.8...v2.85.10">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ec574b6c35 |
ci: bump pinned cargo-nextest 0.9.143 and worktrunk 0.72.0 (#3783)
## Summary Weekly CI pin check found the following drift (these inline `version:` strings are invisible to Dependabot — it follows `Cargo.toml` deps and `uses: foo@vN` refs, not pinned versions inside `with:` blocks): - `cargo-nextest`: 0.9.140 → 0.9.143 (MSRV 1.91, compatible with our 1.96) — pinned in `coverage.yaml`, `actions/test-setup`, and `actions/claude-setup`; all three moved together. - `worktrunk`: 0.71.0 → 0.72.0 (MSRV 1.96, compatible with our 1.96) — the CI-installed `wt` that runs `wt hook pre-merge`, bumped to the current release; pinned in `ci.yaml` (×2) and `nightly.yaml`. ## Already up to date - `cargo-affected`: 0.4.0, `cargo-insta`: 1.48.0, `cargo-llvm-cov`: 0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2 - `hustcer/setup-nu` (nushell): 0.114.1 — matches the current nushell release across all four call sites - Runner images: ubuntu-24.04, windows-2022 ## Notes - windows-2022 stays pinned ([actions/runner-images#12677](https://github.com/actions/runner-images/issues/12677) — windows-2025 lacks the D: drive). - **cargo-nextest 0.9.143 has nothing config-facing to adjust.** The 0.9.140 → 0.9.143 range is dynamic-library-search-path fixes (build-dir layout v2, `build.build-dir`, `[[example]]` targets), archive filterset fixes, an opt-in `junit.report-skipped` setting we don't set, and a listing progress bar. The one behavior change — ordering the Cargo artifact directory ahead of `deps` on the dylib search path, matching Cargo since 1.93 — doesn't affect this repo, which links no `dylib` dependency. - **worktrunk 0.72.0 is only exercised through `wt hook pre-merge`** in these three jobs, so the release's `wt merge` / `wt step push` two-tree changes and the `branch_outcome` JSON rename don't reach CI. The relevant one is the opposite direction: 0.72.0 fixes `wt` writing ANSI to a pipe and exiting 101 on `Broken pipe`, which is exactly the non-tty shape these jobs run in. - **`zola` is deliberately left at 0.22.1** — see below. ## Deferred: zola 0.22.1 → 0.23.2 `taiki-e/install-action`'s `tool: zola@0.22.1` in `check-docs` (and the matching pin in `publish-docs.yaml`) is behind, but 0.23.0 is not a routine bump. Upstream calls it "probably the most breaking version of Zola that will happen" ([CHANGELOG](https://github.com/getzola/zola/blob/master/CHANGELOG.md)): **shortcodes are removed entirely** and Tera is updated to v2 with its own [migration guide](https://github.com/Keats/tera/blob/master/MIGRATION.md). `docs/templates/shortcodes/` and `docs/templates/macros.html` both exist, so this needs a real docs-site migration rather than a version-string change, and it would land in the same PR as the live-site publish pin. Left for a separate change; flagging it here so it isn't silently skipped each week. Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
00ab0ffa26 |
Canonicalize benchmark fixtures and variants (#3761)
Benchmark fixtures still encoded the benchmark that first needed each repository state, which left overlapping recipes and variants after the earlier harness consolidation. This change reduces the fixture catalog to two provenance-based bases: `Generated` builds an ordinary Git repository locally, while `Imported` copies the pinned `rust-lang/rust` corpus. Worktree, branch, and remote-ref populations remain parameters on `Generated`; prune candidates and backdrop are overlays that work with either base. The generated base deliberately combines heterogeneous worktree states, history-spread branches, and optional remote refs so ordinary list, completion, picker, first-output, alias, remove, and prune benchmarks can share it. Imported history-spread branches and clean base-tip worktrees carry their own commits, preserving the base populations without making them incidental prune candidates when overlays advance the default branch. The benchmark matrix now keeps single-factor contrasts: list scaling uses the 1- and 8-worktree endpoints; alias dispatch has a startup floor, two population endpoints, and one warm/cold variable-resolution pair; completion keeps one full-surface case; remove and prune vary cache or hook state only where the command exercises it. Historical recipes, redundant cache rows, and intermediate scaling points are removed. Manual setup paths live under `target/`, and the benchmark guide documents the resulting fixture and cache model. Tests: `cargo run -- hook pre-merge --yes` after merging current `main` (4,571 tests); targeted Criterion test-mode runs; `cargo test -p wt-perf`; benchmark check, clippy, formatting, and diff checks. > _This was written by Codex on behalf of max-sixty_ |
||
|
|
683bc9b91b |
docs(ci): record that the release/signing environments admit any tag (#3775)
The `release` and `signing` deployment branch policies were pinned to `v*` tags; they now admit any tag, and this records that. The "Tag operations" ruleset covers `~ALL` tags, so the `v*` pattern carried no part of the gate — tend's `_tags_admin_gated` credits a tag entry on that ruleset alone and never reads the pattern. What the pattern did do was duplicate `release.yaml`'s own tag filter, which is broader: `**[0-9]+.[0-9]+.[0-9]+*` matches an unprefixed `1.2.3`, which a `v*` policy would then refuse. A release cut under that name would have stopped at `build-local-artifacts` — it names `signing` and waits only on `plan`, so the refusal lands before an artifact is built, not at a publish job. Dropping the pattern removes the only place the two could drift. This also brings the repo onto the shape install-tend's §3 recipe documents (`-f name='*' -f type=tag`), which worktrunk had deviated from. `uvx tend check` still reports 8/8. Also updates a stale `v*` reference in the `signing` job's comment in `release.yaml`. > _This was written by Claude Code on behalf of max-sixty_ --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
2dc9380670 |
docs(ci): the tend environment-deployments gap closed with #3749 (#3764)
Nightly sweep finding: the last paragraph of "Environment protection" in `.github/CLAUDE.md` describes a gap that closed the same night it was written. #3748 added the paragraph saying the generated `tend-*.yaml` files "still carry the bare `environment: tend`" and that `tend check`'s `environment-deployments` "fails until a `uvx tend@latest init` regen lands them on tend ≥ 0.1.14". #3749 merged 3 hours later and did exactly that regen — every generated job now reads `{name: tend, deployment: false}`, and tonight's `tend check` reports `environment-deployments` as `PASS`. Left as-is, the file tells the next reader to expect a failure that no longer happens and a regen that already ran. The rewrite keeps the durable half — the generated files aren't hand-edited, because `uvx tend@latest init` overwrites them — and states the resolution instead of the pending action. <details><summary>Evidence</summary> Current state of the generated files (all eight are identical in shape): ``` $ grep -A2 'environment:' .github/workflows/tend-nightly.yaml environment: name: tend deployment: false ``` Tonight's `tend check`, run by the nightly sweep: ``` PASS environment-deployments — No job files a deployment for the 'tend' environment ``` The three checks still failing (`credential-environments`, `claude-auth`, `repo-secret-allowlist`) are tracked in #3729 and are repository-settings changes, unrelated to this file. #3760 edits the same section but not these lines, so the two don't conflict. </details> No test accompanies this — it's a documentation-only change to a file no test reads. Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
5d4d0e8407 |
docs(ci): record the model credential as environment-scoped (#3760)
Documents `CLAUDE_CODE_OAUTH_TOKEN` moving out of repo-level storage and into the `tend` environment — the last operational secret still sitting where any workflow the repo runs could read it, and the remaining `repo-secret-allowlist` failure after #3748. The environment copy is set; the repo-level copy is deleted once this PR's own `tend-review` run comes back green. That run is the verification. An environment secret outranks a repo-level one of the same name, so a job naming `environment: tend` already reads the new value while both exist — which means the credential is exercised end to end before anything is removed, rather than after. Nothing about who reads the token changes. All eight readers — `triage`, `handle`, `fix-ci`, `nightly`, `review-runs`, `notifications`, `weekly`, `review` — already declare `environment: tend`. The lead sentence of "Environment protection" claimed environments hold "credentials that grant write access". That was never the set — the model credential grants no write access to anything in this repo, and it now lives in one. It states the set directly instead, with the reason `CODECOV_TOKEN` stays outside it. The `tend` row's "Read by" cell also picks up semicolons. `every tend-*.yaml job but relay, append-gist, both create-issue-on-*-failure jobs` reads as one four-item exclusion list, which would say `append-gist` doesn't read the token — it does. > _This was written by Claude Code on behalf of max-sixty_ Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
02a8dc829c |
chore: bump taiki-e/install-action from 2.85.7 to 2.85.8 (#3758)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.7 to 2.85.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.8</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.29.0.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.49.0.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.73.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.6.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.12.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.1.</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.1.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.8] - 2026-08-04</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.29.0.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.49.0.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.73.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.6.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.12.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.1.</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.1.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/cb33e69fad06166ca28a42b2575e4dadabf62ee8"><code>cb33e69</code></a> Release 2.85.8</li> <li><a href="https://github.com/taiki-e/install-action/commit/205431a517a990dfa58a0f22a02abd8cbef31c11"><code>205431a</code></a> Update <code>zizmor@latest</code> to 1.29.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/e734f91b32f269a08deefc4ceb37d4aa4747a26b"><code>e734f91</code></a> Update wild manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/2596ecb10ea03dec655fc75e41a3b0f4dad7bc42"><code>2596ecb</code></a> Update <code>typos@latest</code> to 1.49.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/a44271eb2d867e7b1cf13602d4e4f0a93eec2f5e"><code>a44271e</code></a> Update <code>trivy@latest</code> to 0.73.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9b100e5f66ebcc3ef6c9e7380611a923118c93bd"><code>9b100e5</code></a> Update <code>tombi@latest</code> to 1.2.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/f28498427840d9dc2242c579fe43460aad78fb48"><code>f284984</code></a> Update <code>prek@latest</code> to 0.4.12</li> <li><a href="https://github.com/taiki-e/install-action/commit/3b86746a2ded65050e00646b310ebba2a15bdaf6"><code>3b86746</code></a> Update <code>mise@latest</code> to 2026.8.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/9287d185066eec8a77c1f11905ac9727db063430"><code>9287d18</code></a> Update just manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/32702bef0f7f8c45b9b179686f51a0f2739378c3"><code>32702be</code></a> Update <code>convco@latest</code> to 0.7.1</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.7...v2.85.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
6ad0439d79 |
chore: update tend workflows (0.1.13 → 0.1.14) (#3749)
Automated nightly regeneration of tend's workflow files. **tend version:** 0.1.13 → 0.1.14 ## Notable changes - **Jobs now name the `tend` environment with `deployment: false`** (max-sixty/tend#852), so GitHub stops filing a deployment record per run and posting it on the pull request. This is what the current `tend check` flags as `environment-deployments` (#3729) — regenerating clears it, and max-sixty/tend#853 makes `check` refuse the old shape going forward. - **`id-token: write` dropped from every tend job** — a side effect of removing the claude-smoke workflow and its `tend-manual` environment (max-sixty/tend#820). None of the remaining jobs use OIDC, so the permission was unused. - **`tend-mention` counts bot engagement outside `jq`** (max-sixty/tend#840). `gh api --paginate` applies `--jq` once per page, so `| length` emitted one count per page; past 100 comments the shell variable held `100\n7`, the numeric test errored, and the bot fell through to `should_run=false` — going quiet on exactly its most-engaged threads. - **Review and triage skill fixes** — the review-record guards now ignore synthetic reply containers (max-sixty/tend#835), `/code-review` is ported into a tend-owned skill (max-sixty/tend#819), and triage substitutes the real issue number into its PR-body templates instead of leaving a placeholder (max-sixty/tend#844). - **Outage reporting is more robust** — a stranded outage row now names the trigger it points at (max-sixty/tend#823), and marking a notification read tolerates a transient run-metadata fetch failure (max-sixty/tend#843). Full compare: https://github.com/max-sixty/tend/compare/0.1.13...0.1.14 Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
59c7320a78 |
ci: read TEND_BOT_TOKEN from an environment in every job (#3748)
Closes worktrunk's half of the `tend` environment migration (tend's `TODO.md`, "Finish moving the operational secrets into the `tend` environment", item 2). The environment is a secret scope, not a deploy target: its deployment branch policy is what stops a workflow pushed to a feature branch from reading the bot's PAT. That gate closes only when the repo-level copy of the secret is gone, since a job naming an environment still reads repo-level secrets. worktrunk kept one because these hand-maintained workflows read `TEND_BOT_TOKEN` outside tend's generated set. ## What changed | Job | Environment | Why that one | |---|---|---| | `benchmarks.yaml` `append-gist` (new) | `tend` | `schedule`-gated, so it runs on `main` | | `benchmarks.yaml` `create-issue-on-benchmark-failure` | `tend` | already `schedule`-gated | | `nightly.yaml` `create-issue-on-nightly-failure` | `tend` | already `schedule`-gated | | `release.yaml` `publish-winget` | `release` | runs on a `v*` tag push | | `release.yaml` `publish-homebrew` | `release` | runs on a `v*` tag push | Every job reading `TEND_BOT_TOKEN` now names an environment, so deleting the repo-level copy breaks nothing. ### The gist append moved into its own job The `benchmarks` job has no `if` gate, so putting `tend` on it would refuse a `workflow_dispatch` against a non-`main` ref — on-demand runs against a chosen branch are what that trigger is documented for. A job GitHub skips never requests its environment, so moving the append into a `schedule`-gated `append-gist` job keeps the policy off the dispatch path entirely. It reads `target/criterion` back from the artifact the `benchmarks` job already uploads. `create-issue-on-benchmark-failure` now `needs` both jobs, so a failed append still files an issue — previously it failed the `benchmarks` job directly. ### Why the release jobs get `release`, not `tend` A tag push is not bot-steerable and tag creation and update are already restricted to admins by the "Tag operations" ruleset, so a tag policy is a real boundary. The tag entry cannot go on `tend`: `tend check`'s `check_environment` pins that policy to exactly the protected branches and its `--fix` deletes anything else. `release` already exists with a `v*` tag policy and already holds `AUR_SSH_PRIVATE_KEY`, so no new environment and no new credential — `TEND_BOT_TOKEN` is seeded into it as a second copy. ### `deployment: false` Jobs naming `tend` use the mapping form. GitHub files a deployment record for every job that names an environment, against whatever ref the run belongs to; under `pull_request_target` that is the PR's own head, which is why PR timelines grew a "worktrunk-bot deployed to tend" line on every push. `deployment: false` drops the record and keeps the gate. The release jobs keep their records, which land in no PR timeline. ## Follow-up: one step, after merge `TEND_BOT_TOKEN` is **already seeded into the `release` environment** (read from the local `worktrunk-bot` gh config dir at `~/.config/gh-bots/worktrunk-bot`, so no new credential was minted and nothing was pasted). Verified: the token resolves to `worktrunk-bot` and has push on both `max-sixty/winget-pkgs` and `max-sixty/homebrew-worktrunk`. That leaves one step, and it must come **after** this PR merges: ``` gh secret delete TEND_BOT_TOKEN --repo max-sixty/worktrunk ``` Not before. On `main` today the gist append, both `create-issue-on-*-failure` jobs, and the two publish jobs still read the token with no environment named, so deleting the repo-level copy first would break the next benchmarks cron (03:47 UTC daily). Merging this PR is what makes the deletion safe. ## What this does not fix - `repo-secret-allowlist` still fails on `CLAUDE_CODE_OAUTH_TOKEN`, also at repo level. It cannot be read back either; separate item. - `environment-deployments` still fails on the generated `tend-*.yaml`, which pin tend 0.1.13 and carry the bare `environment: tend`. Those are regenerated by the published tend, and a regen also carries an unrelated `gh api --paginate` fix in `tend-mention.yaml`, so it belongs in its own PR. ## Verification - The `append-gist` script was run end-to-end against a real `benchmark-results-*` artifact from run 30976221483. It emits 40 rows whose `bench` names match the live gist's existing rows exactly, confirming the artifact round-trip preserves paths relative to `target/criterion`. - That a skipped `if` short-circuits the environment gate is confirmed by run 31066000517: `publish-cargo`, which names `environment: release`, completed as *skipped* on a `pull_request` from a non-tag ref rather than failing on the policy. - `actionlint` reports the same eight pre-existing shellcheck notes as `main`; no new findings. `pre-commit` passes. > _This was written by Claude Code on behalf of max-sixty_ |
||
|
|
970976bd32 |
Consolidate benchmark recipes and cases (#3721)
Benchmark fixtures had accumulated around individual call sites, leaving the same repository shapes and command modes expressed several ways. This change makes repository state the organizing concept: benchmark groups select semantic `FixtureRecipe`s, share table-driven cases, and retain separate fixtures only when a controlled contrast, destructive precondition, or disproportionate setup cost requires one. The real-repository list benchmarks now share one pinned `rust-lang/rust` fixture with eight worktrees and fifty branches spread across history. The list matrix keeps default, branch, warm, and cold coverage without maintaining several “real” repository handles. Remove and prune cases share the same case machinery, while the destructive large-repository prune state remains separate. The scheduled workflow now converts Criterion estimates directly with `jq`, removing the one-off Python converter and its tests. The benchmark guide records the canonical-fixture principle and the remaining recipe-to-group mapping. Tests: `cargo run -- hook pre-merge --yes` (4,551 tests); `cargo bench --bench list large_repository -- --test`; `cargo test -p wt-perf`; benchmark check, clippy, formatting, and diff checks. > _This was written by Codex on behalf of max-sixty_. |