mirror of
https://github.com/carbon-language/carbon-lang.git
synced 2026-09-29 10:44:58 +01:00
This is trying to reduce how much we run tidy over due to poor performance of tidy. It's opening the door for issues where a header file is modified in a way that introduces tidy issues in a different target. However, that's not the typical tidy issue we see. There may also be a risk where a source file indirectly becomes a source file for a target in a way that `same_pkg_direct_rdeps` doesn't return, but I'm not sure that's applicable for how we use targets. An example of this locating a diagnostic error can be found in the "Add tidy issue" commit's run (which I cancelled before it finished running, but note the error): https://github.com/carbon-language/carbon-lang/actions/runs/13932649182/job/38993348130?pr=5144
Workflows
Hardening
Workflows are hardened using Step Security tool. Findings for the "Harden Runner" steps are available online.
Allowed endpoints
Most jobs only have a few endpoints, but due to tools which do downloads, a few have significantly more. These are:
- pre_commit.yaml (Bazel, pre-commit)
- nightly_release.yaml (Bazel)
- tests.yaml (Bazel)
When updating one of these, consider updating all of them.
We try to keep allowed-endpoints with one per line. Prettier wants to wrap
them, which we fix this with prettier-ignore.
Testing
We keep around an action-test branch in carbon-lang, which can be used to test
triggers with push: configurations. For example:
on:
push:
branches: [action-test]