Provision Whitaker through install-whitaker - #372
Conversation
Replace the hand-rolled Whitaker provisioning with the shared-actions install-whitaker action, pinned to 6dea5677 (shared-actions #522), the revision the concordat QG-002 rule lists as compliant. The action installs the exact installer version it pins from a digest-verified release archive, never builds from source, and leaves the lint suite a rolling release. The lint invocation is unchanged.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (3)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Summary
WalkthroughThe CI workflow now installs Whitaker version 0.2.9 through an updated pinned shared action. Test support and the supply-chain contract reflect the new version and pin. ChangesWhitaker installer update
Priority: ⬇️ Low Change: Other Merge Risk: ⚪ Minimal · up to The Whitaker update is mergeable with no concrete current-head risk identified. Caution Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional.
❌ Failed checks (1 error, 1 warning)
✅ Passed checks (13 passed)
Full details: Developer DocumentationExplanation The pull request changes the Whitaker CI tooling: it raises Resolution Update Full details: Testing (Unit And Behavioural)Explanation The pull request changes the externally observable GitHub Actions workflow and the Whitaker installation network boundary, but it adds no end-to-end or execution-level test. The updated Resolution Add a workflow-level smoke or end-to-end test that invokes the pinned
Whitaker’s pin moves on, Comment |
Reviewer's guide (collapsed on small PRs)Reviewer's GuideWhitaker provisioning now uses the shared Flow diagram for reviewed Whitaker action pinningflowchart TD
Workflow["CI workflow"] --> ActionRef["install-whitaker@6cec89ba"]
ActionRef --> PinCheck["every_shared_action_reference_is_pinned"]
PinCheck --> Exception["WHITAKER_ACTION_SHA reviewed exception"]
ActionRef --> Contract["installer-version 0.2.9"]
Contract --> Tests["cargo test --test workflow_contracts"]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 46313e0837
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The developers' guide named only the two coverage actions as shared-action pin exceptions. install-whitaker is a third, held to WHITAKER_ACTION_SHA because QG-002 accepts a later main commit that leaves the action unchanged, and its installer-version input is asserted at 0.2.9.
|
Answering the Testing (Unit And Behavioural) error row: it asks for a test that executes the install-whitaker action. That execution is covered where the action lives: shared-actions' own contract and test suite install Whitaker through the action (digest verification, --no-source-fallback, the Windows and no-prebuilt-release cases), and the QG-002 rule in concordat audits every consumer's use of it. This pull request changes only the pin and the installer-version input, and the repository's own contract (supply_chain.rs) asserts both and was mutation-proved: pointing the step back at the old commit fails every_shared_action_reference_is_pinned. An act-style run of the workflow is waived across the estate for the same reason (rust-prover-tools #132, hecate #113, ghillie #149), because it would rebuild the action's coverage inside every consumer. The Developer Documentation warning is fixed at 4a31cff. |
Provision Whitaker only through the shared-actions
install-whitakeraction, so the repository passes concordat's QG-002 rule.leynos/shared-actions/.github/actions/install-whitakerpinned to6cec89bac47a21cf756d68d638a9a510998e57f8(shared-actions #546; QG-002 accepts it because install-whitaker is content-identical to the reviewed 6dea5677, #522, at that commit, per concordat Update reqwest requirement from 0.11.27 to 0.13.4 #249).whitaker-installer0.2.9, verifies the release archive against a pinned digest, passes--no-source-fallback, and takesgithub.tokenitself. The lint suite stays a rolling release.More than a pin (review-gated)
installer-versioninput stays (tests/contracts/supply_chain.rsasserts it) and is raised from 0.2.7 to the action's 0.2.9 floor; the test follows.every_shared_action_reference_is_pinnedholds each action to a reviewed commit with named exceptions intests/support/workflow_estate.rs.install-whitakernow sits at6cec89ba, so it joins that table as its own exception (WHITAKER_ACTION_SHA) rather than moving the estate-wide constant, which would repin every other action.6cec89bais a shared-actions main commit that leavesinstall-whitakercontent-identical to the reviewed6dea5677, the set concordat's QG-002 accepts.c5a54701failsevery_shared_action_reference_is_pinned.cargo test --test workflow_contractspasses (185); the rest of the suite is untouched.QG-002 proof
Summary by Sourcery
Use the reviewed shared install-whitaker action to provision Whitaker and satisfy the repository’s workflow supply-chain requirements.
Enhancements:
install-whitakeraction with its pinned installer version and release verification.Documentation:
Tests: