name: CI on: pull_request: branches: ["**"] # Lets `hive-forge ci-rerun` re-trigger CI via the workflow-dispatch API # without an empty commit. No effect on the PR-triggered runs above. workflow_dispatch: jobs: check: name: nix flake check runs-on: [hive-ci] # Bound the job so a wedged build fails in minutes instead of # hanging until the runner's 3h cap (or, when the runner itself # deadlocks, never). 30 min is well above a cold-cache rebuild # (~15 min observed) and well under the 3h hard cap — tune if a # legit cold build ever trips it. timeout-minutes: 30 steps: - uses: actions/checkout@v3 - name: check # Runs all flake checks: formatting (treefmt+rustfmt), cargo test, # cargo clippy, and module evaluation. No --no-build: the checks # derivations are the canonical source of truth. run: nix flake check tracker-tags: name: tracker-tag lint runs-on: [hive-ci] # Pure git+grep — seconds normally; a few minutes is already a hang. timeout-minutes: 5 steps: - uses: actions/checkout@v3 - name: lint # Flags hash-number tracker tags in source (hive convention is # prose, not tags — /knowledge/hive-rules.md). Its own job, and # IS a required check on the forge (branch protection) — a hit # blocks merge. See scripts/check-issue-refs.sh. run: sh scripts/check-issue-refs.sh comment-blocks: name: comment-block lint runs-on: [hive-ci] # Pure git+awk — seconds. timeout-minutes: 5 steps: - uses: actions/checkout@v3 - name: lint # Flags contiguous comment blocks over 30 lines (a giant prose # block belongs in docs/ as implementation notes, not in source). # Own job, and IS a required check on the forge (branch # protection) — a hit blocks merge. See # scripts/check-comment-blocks.sh. run: sh scripts/check-comment-blocks.sh