From 728a7a3f7cbeab7d540735f4f6eb31e210cf198c Mon Sep 17 00:00:00 2001 From: liyunze <50455574+liyunze-coding@users.noreply.github.com> Date: Fri, 25 Sep 2026 13:28:15 +0800 Subject: [PATCH] added pull request check --- .forgejo/workflows/ci.yml | 46 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 .forgejo/workflows/ci.yml diff --git a/.forgejo/workflows/ci.yml b/.forgejo/workflows/ci.yml new file mode 100644 index 0000000..4d78b3e --- /dev/null +++ b/.forgejo/workflows/ci.yml @@ -0,0 +1,46 @@ +name: CI + +# pull_request_target always runs this file from the base branch. A pull request +# cannot replace these steps, which is what `pull_request` would allow after +# someone clicks Approve on a fork. +# +# Forks still are not compiled until a maintainer adds the `ci` label. `cargo +# check` executes build scripts, so review Cargo.toml, Cargo.lock, build.rs, +# and .cargo/config.toml before adding it. New commits do not reuse that label; +# remove it and add it again after reviewing them. +on: + pull_request_target: + types: [opened, synchronize, reopened, labeled] + +jobs: + check: + if: | + forgejo.event.pull_request.head.repo.full_name == forgejo.repository || + (forgejo.event.action == 'label_updated' && forgejo.event.label.name == 'ci') + runs-on: native + steps: + - name: Checkout pull request + uses: https://data.forgejo.org/actions/checkout@v4 + with: + repository: ${{ forgejo.event.pull_request.head.repo.full_name }} + ref: ${{ forgejo.event.pull_request.head.sha }} + persist-credentials: false + + - name: Cargo check + run: | + docker run --rm \ + --read-only \ + --network bridge \ + --cap-drop ALL \ + --security-opt no-new-privileges \ + --pids-limit 512 \ + --memory 4g \ + --tmpfs /tmp:rw,nosuid,nodev,size=2g \ + --user "$(id -u):$(id -g)" \ + -e CARGO_HOME=/tmp/cargo \ + -e CARGO_TARGET_DIR=/tmp/target \ + -e PATH=/usr/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin \ + -v "$PWD:/src:ro" \ + -w /src \ + rust:1.98-bookworm \ + cargo check --locked --manifest-path /src/Cargo.toml