mirror of
https://github.com/carbon-language/carbon-lang.git
synced 2026-10-04 22:02:52 +01:00
Run clangd-tidy in parallel with clang-tidy, to experimentally see whether it works reasonably well. These may produce slightly different results, and it's not clear that clangd-tidy will be better, so being cautious about switching. A real possibility here is this is slower in some cases (building compile commands takes ~6m below), but faster in the extremely slow cases (when clang-tidy takes >10m). For contrast: - clang-tidy: https://github.com/carbon-language/carbon-lang/actions/runs/16038096026/job/45254162180?pr=5763 - clangd-tidy: https://github.com/carbon-language/carbon-lang/actions/runs/16038096427/job/45254164217?pr=5763
Workflows
Hardening
Workflows are hardened using Step Security tool. Findings for the "Harden Runner" steps are available online.
Allowed endpoints
Most jobs only have a few endpoints, but due to tools which do downloads, a few have significantly more. These are:
- pre_commit.yaml (Bazel, pre-commit)
- nightly_release.yaml (Bazel)
- tests.yaml (Bazel)
When updating one of these, consider updating all of them.
We try to keep allowed-endpoints with one per line. Prettier wants to wrap
them, which we fix this with prettier-ignore.
Testing
We keep around an action-test branch in carbon-lang, which can be used to test
triggers with push: configurations. For example:
on:
push:
branches: [action-test]