Skip to content

chore(deps-dev): bump @tailwindcss/postcss from 4.2.4 to 4.3.3 in /frontend #839

chore(deps-dev): bump @tailwindcss/postcss from 4.2.4 to 4.3.3 in /frontend

chore(deps-dev): bump @tailwindcss/postcss from 4.2.4 to 4.3.3 in /frontend #839

Workflow file for this run

name: Rust CI
on:
push:
branches: ["main"]
pull_request:
branches: ["main"]
env:
CARGO_TERM_COLOR: always
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
jobs:
cargo-deny:
name: Cargo Deny Check
runs-on: ubuntu-latest
# Supply-chain policy check: informative, must not block core CI.
continue-on-error: true
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Run cargo-deny
continue-on-error: true
uses: EmbarkStudios/cargo-deny-action@v2
with:
command: check
build-and-test:
name: Build & Test
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Install stable Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy
- name: Install Z3
run: |
sudo apt-get update
sudo apt-get install -y libz3-dev libdbus-1-dev libudev-dev pkg-config
- name: Cache cargo registry & build artifacts
uses: actions/cache@v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-${{ hashFiles('**/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-
- name: Check formatting
run: cargo fmt --check
- name: Run Clippy
run: cargo clippy -p sanctifier-cli -p sanctifier-core --all-targets -- -D warnings
- name: Install cargo-nextest
uses: taiki-e/install-action@nextest
- name: Run tests (JUnit XML)
run: cargo nextest run -p sanctifier-cli -p sanctifier-core --profile ci
- name: Upload test results
if: always()
uses: actions/upload-artifact@v6
with:
name: junit-test-results
path: target/nextest/ci/junit.xml
retention-days: 7
- name: Build release binary
run: cargo build --release -p sanctifier-cli
coverage:
name: Coverage Gate (≥ 80% per crate)
runs-on: ubuntu-latest
# Coverage reporting is informative; do not block core CI on it.
continue-on-error: true
# Only enforce on push/PR to main to avoid gating dependabot bumps
if: github.event_name == 'push' || github.event_name == 'pull_request'
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Install stable Rust toolchain
uses: dtolnay/rust-toolchain@stable
- name: Install Z3
run: |
sudo apt-get update
sudo apt-get install -y libz3-dev libdbus-1-dev libudev-dev pkg-config
- name: Cache cargo registry & build artifacts
uses: actions/cache@v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-cov-${{ hashFiles('**/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-cov-
- name: Install cargo-llvm-cov
uses: taiki-e/install-action@cargo-llvm-cov
- name: Collect coverage — sanctifier-core
continue-on-error: true
run: |
cargo llvm-cov --lcov --output-path lcov-core.info \
-p sanctifier-core \
--ignore-filename-regex '(_tests\.rs|/tests/|/benches/)'
- name: Collect coverage — sanctifier-cli
continue-on-error: true
run: |
cargo llvm-cov --lcov --output-path lcov-cli.info \
-p sanctifier-cli \
--ignore-filename-regex '(_tests\.rs|/tests/|/benches/)'
- name: Upload coverage to Codecov (sanctifier-core)
uses: codecov/codecov-action@v5
with:
files: lcov-core.info
flags: sanctifier-core
fail_ci_if_error: false
- name: Upload coverage to Codecov (sanctifier-cli)
uses: codecov/codecov-action@v5
with:
files: lcov-cli.info
flags: sanctifier-cli
fail_ci_if_error: false
sarif-snapshots:
name: SARIF Snapshot Tests
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Install stable Rust toolchain
uses: dtolnay/rust-toolchain@stable
- name: Install Z3
run: |
sudo apt-get update
sudo apt-get install -y libz3-dev libdbus-1-dev libudev-dev pkg-config
- name: Cache cargo registry & build artifacts
uses: actions/cache@v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-snapshots-${{ hashFiles('**/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-snapshots-
- name: Install cargo-insta
run: cargo install cargo-insta --locked
- name: Generate missing snapshots
env:
INSTA_UPDATE: new
run: |
if [ -f tooling/sanctifier-core/tests/sarif_snapshots.rs ]; then
cargo test --test sarif_snapshots -p sanctifier-core --no-default-features
else
echo "::notice::sarif_snapshots test not present yet at this point in history, skipping."
fi
- name: Verify no pending snapshots
if: hashFiles('tooling/sanctifier-core/tests/sarif_snapshots.rs') != ''
run: |
cargo insta pending-snapshots
count=$(cargo insta pending-snapshots 2>&1 | grep -c '\.snap' || true)
if [ "$count" -gt 0 ]; then
echo "::error::Uncommitted snapshot changes detected. Run INSTA_UPDATE=new cargo test --test sarif_snapshots -p sanctifier-core --no-default-features then cargo insta accept --workspace and commit the .snap files."
exit 1
fi
# ---------------------------------------------------------------------------
# Rule engine orchestration — integration/e2e coverage
# Covers: RuleRegistry pipeline, determinism, custom rules, output stability.
# ---------------------------------------------------------------------------
rule-engine-e2e:
name: Rule Engine Orchestration (integration/e2e)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Install stable Rust toolchain
uses: dtolnay/rust-toolchain@stable
- name: Install Z3
run: |
sudo apt-get update
sudo apt-get install -y libz3-dev libdbus-1-dev libudev-dev pkg-config
- name: Cache cargo registry & build artifacts
uses: actions/cache@v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-rule-e2e-${{ hashFiles('**/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-rule-e2e-
- name: Run rule engine orchestration integration tests
run: |
if [ -f tooling/sanctifier-core/tests/rule_engine_orchestration_test.rs ]; then
cargo test --test rule_engine_orchestration_test -p sanctifier-core
else
echo "::notice::rule_engine_orchestration_test not present yet at this point in history, skipping."
fi
# ---------------------------------------------------------------------------
# Z3 backend module boundaries — integration coverage for S011
# Covers: smt::types, smt::invariants, smt::backend, smt::benchmark.
# ---------------------------------------------------------------------------
smt-module-boundaries:
name: Z3 Backend Module Boundaries (S011)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Install stable Rust toolchain
uses: dtolnay/rust-toolchain@stable
- name: Install Z3
run: |
sudo apt-get update
sudo apt-get install -y libz3-dev libdbus-1-dev libudev-dev pkg-config
- name: Cache cargo registry & build artifacts
uses: actions/cache@v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-smt-boundaries-${{ hashFiles('**/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-smt-boundaries-
- name: Run Z3 module boundary integration tests
run: |
if [ -f tooling/sanctifier-core/tests/smt_module_boundaries_test.rs ]; then
cargo test --test smt_module_boundaries_test -p sanctifier-core
else
echo "::notice::smt_module_boundaries_test not present yet at this point in history, skipping."
fi
# ---------------------------------------------------------------------------
# Property-based tests — the analysis engine must not panic on any input.
# Generates random Rust source (structured Soroban contracts, free-form
# snippets, and arbitrary text) and runs every rule against it, asserting the
# result is always Ok(findings) or Err(parse_error). Runs as a SEPARATE job
# with a hard 60-second budget on the proptest run itself (10,000 cases).
# ---------------------------------------------------------------------------
proptest:
name: Property-Based Tests (proptest)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: Install stable Rust toolchain
uses: dtolnay/rust-toolchain@stable
- name: Install Z3
run: |
sudo apt-get update
sudo apt-get install -y libz3-dev libdbus-1-dev libudev-dev pkg-config
- name: Cache cargo registry & build artifacts
uses: actions/cache@v5
with:
path: |
~/.cargo/registry
~/.cargo/git
target
key: ${{ runner.os }}-cargo-proptest-${{ hashFiles('**/Cargo.lock') }}
restore-keys: |
${{ runner.os }}-cargo-proptest-
# Compile separately so the 60-second budget below covers test execution
# only, not the build.
- name: Build property-test binary (release)
run: |
if [ -f tooling/sanctifier-core/tests/proptest_analysis.rs ]; then
cargo test -p sanctifier-core --test proptest_analysis --release --no-run
else
echo "::notice::proptest_analysis not present yet at this point in history, skipping."
fi
- name: Run property tests — 10,000 inputs, 60s budget
if: hashFiles('tooling/sanctifier-core/tests/proptest_analysis.rs') != ''
env:
PROPTEST_CASES: "10000"
run: timeout 60s cargo test -p sanctifier-core --test proptest_analysis --release