Files
Peter Steinberger 234df15a6d chore: refresh dependencies after seven-day cooldown (#128414)
* build(deps): refresh dependencies after cooldown

Apply dependency, toolchain, action, image, and exact tool updates released by the inclusive 2026-08-16 seven-day cutoff. Adapt owner boundaries for the resulting CUA, logging, Teams, Markdown, native, and test-harness contract changes while retaining versions blocked by upstream compatibility constraints.

* fix(ui): align markdown renderer env typing

* fix(deps): align postcss and mistral peer contracts

* fix(deps): repair refreshed dependency contracts

* fix(deps): retain tslog startup budget

* fix(ci): verify Android tools with SHA-256

* fix(ci): fence Android SDK cache version
2026-08-24 03:01:54 -07:00

149 lines
5.0 KiB
YAML

name: Linux App
on:
pull_request:
paths:
- "apps/linux/**"
- ".github/workflows/linux-app.yml"
workflow_dispatch:
concurrency:
group: linux-app-${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }}
cancel-in-progress: true
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
permissions:
contents: read
jobs:
build:
name: Build Linux companion
# Match the release build base so PR artifacts have the same glibc floor.
runs-on: ubuntu-22.04
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
fetch-tags: false
persist-credentials: false
submodules: false
- name: Install Tauri system dependencies
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends \
build-essential \
curl \
file \
gstreamer1.0-libav \
gstreamer1.0-plugins-bad \
gstreamer1.0-plugins-good \
libayatana-appindicator3-dev \
librsvg2-dev \
libssl-dev \
libwebkit2gtk-4.1-dev \
libxdo-dev \
wget
- name: Install Rust
run: rustup toolchain install stable --profile minimal --component rustfmt
- name: Cache Cargo
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
~/.cargo/registry
~/.cargo/git
apps/linux/src-tauri/target
key: linux-app-${{ runner.os }}-${{ hashFiles('apps/linux/src-tauri/Cargo.lock') }}
restore-keys: |
linux-app-${{ runner.os }}-
- name: Setup Node environment
uses: ./.github/actions/setup-node-env
with:
cache-mode: restore
install-bun: "false"
- name: Check Rust formatting
working-directory: apps/linux/src-tauri
run: cargo +stable fmt --check
- name: Run Rust tests
working-directory: apps/linux/src-tauri
run: cargo +stable test --locked --all-targets
- name: Build Linux companion bundles
working-directory: apps/linux/src-tauri
env:
# appimagetool strips fail on CI runners; Tauri documents NO_STRIP for Actions.
NO_STRIP: "true"
# PR builds have no TAURI_SIGNING_PRIVATE_KEY, and the configured updater
# pubkey makes the bundler hard-require it. Skip updater artifacts here;
# linux-app-release.yml builds the signed updater bundles.
run: pnpm dlx @tauri-apps/cli@2.11.4 build --bundles deb,appimage --config '{"bundle":{"createUpdaterArtifacts":false}}'
- name: Upload bundles
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: openclaw-linux-companion
retention-days: 14
if-no-files-found: error
path: |
apps/linux/src-tauri/target/release/bundle/deb/*.deb
apps/linux/src-tauri/target/release/bundle/appimage/*.AppImage
test-macos:
name: Test macOS companion
# This app also ships macOS desktop-test bundles, but the only job that
# compiles them (linux-app-release.yml build_macos) runs behind a manual
# dispatch input. Without a per-PR check, a macOS-gated Tauri API can break
# the macOS target for weeks unnoticed - `WebviewWindowBuilder::transparent`
# did exactly that.
#
# macos-15, not macos-14: tauri-plugin-notifications' Swift sources use
# typed throws (`throws(FFIResult)`), which needs Swift 6. The macos-14
# image still ships Swift 5.x and fails to parse them.
runs-on: macos-15
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
fetch-tags: false
persist-credentials: false
submodules: false
- name: Install Rust
run: rustup toolchain install stable --profile minimal
- name: Setup Node environment
uses: ./.github/actions/setup-node-env
with:
cache-mode: restore
install-bun: "false"
- name: Cache Cargo
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
~/.cargo/registry
~/.cargo/git
apps/linux/src-tauri/target
key: macos-app-${{ runner.os }}-${{ hashFiles('apps/linux/src-tauri/Cargo.lock') }}
restore-keys: |
macos-app-${{ runner.os }}-
- name: Test macOS companion
working-directory: apps/linux/src-tauri
# `test` rather than `check`: it additionally links and runs the
# binaries, which is the only way macOS link-time breakage (a missing
# Swift runtime rpath, say) shows up at all. `--all-targets` keeps the
# compile coverage `check --all-targets` used to give.
run: cargo +stable test --locked --all-targets