name: CI # pull_request_target always runs this file from the base branch. A pull request # cannot replace these steps, which is what `pull_request` would allow after # someone clicks Approve on a fork. # # Forks still are not compiled until a maintainer adds the `ci` label. `cargo # check` executes build scripts, so review Cargo.toml, Cargo.lock, build.rs, # and .cargo/config.toml before adding it. New commits do not reuse that label; # remove it and add it again after reviewing them. on: pull_request_target: types: [opened, synchronize, reopened, labeled] jobs: check: if: | forgejo.event.pull_request.head.repo.full_name == forgejo.repository || (forgejo.event.action == 'label_updated' && forgejo.event.label.name == 'ci') runs-on: native steps: - name: Checkout pull request uses: https://data.forgejo.org/actions/checkout@v4 with: repository: ${{ forgejo.event.pull_request.head.repo.full_name }} ref: ${{ forgejo.event.pull_request.head.sha }} persist-credentials: false - name: Cargo check run: | docker run --rm \ --read-only \ --network bridge \ --cap-drop ALL \ --security-opt no-new-privileges \ --pids-limit 512 \ --memory 4g \ --tmpfs /tmp:rw,nosuid,nodev,size=2g \ --user "$(id -u):$(id -g)" \ -e CARGO_HOME=/tmp/cargo \ -e CARGO_TARGET_DIR=/tmp/target \ -e PATH=/usr/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin \ -v "$PWD:/src:ro" \ -w /src \ rust:1.98-bookworm \ cargo check --locked --manifest-path /src/Cargo.toml