李通洲
eff8514536
CI (macOS): builds Intel version with macport
2026-09-12 00:08:16 +08:00
Guiorgy
2e542bea64
CMake: bumps min version to 3.21 ( #2565 )
...
C_STANDARD C17 and C23 were only introduced in CMake 3.21
2026-09-05 13:43:05 +08:00
Carter Li
0b1bc5b527
CI: upgrades deps; reenables Haiku
2026-09-01 14:14:14 +08:00
dependabot[bot]
5b1ad1008d
CI: Bump the github-actions group with 3 updates
...
Bumps the github-actions group with 3 updates: [uraimo/run-on-arch-action](https://github.com/uraimo/run-on-arch-action ), [github/codeql-action/init](https://github.com/github/codeql-action ) and [github/codeql-action/analyze](https://github.com/github/codeql-action ).
Updates `uraimo/run-on-arch-action` from 3.1.0 to 3.2.0
- [Release notes](https://github.com/uraimo/run-on-arch-action/releases )
- [Commits](https://github.com/uraimo/run-on-arch-action/compare/f9b26e3a1a408d5fd530d20c17b9f3f4428ff8d9...460cb8e6d9f726a588fc9b5e681c8a6cab09ae41 )
Updates `github/codeql-action/init` from 4.37.7 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd...db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 )
Updates `github/codeql-action/analyze` from 4.37.7 to 4.37.8
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd...db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 )
---
updated-dependencies:
- dependency-name: uraimo/run-on-arch-action
dependency-version: 3.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: github/codeql-action/init
dependency-version: 4.37.8
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.8
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-31 08:41:25 +08:00
Carter Li
d7de7c41ca
CI: disables fail on alert
2026-08-27 15:28:18 +08:00
Carter Li
dcce4ccdb0
CI: moves benchmark-index to /.github as required by the script
2026-08-27 14:57:22 +08:00
Carter Li
5936c1cef4
CI: adds benchmark job
2026-08-27 14:23:16 +08:00
Carter Li
04f26a29eb
CI: enables bluetooth module on platforms other than macOS
2026-08-27 09:45:58 +08:00
dependabot[bot]
a979d8ae81
CI: Bump the github-actions group with 4 updates
...
Bumps the github-actions group with 4 updates: [cross-platform-actions/action](https://github.com/cross-platform-actions/action ), [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/analyze](https://github.com/github/codeql-action ) and [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request ).
Updates `cross-platform-actions/action` from 1.3.0 to 1.4.0
- [Release notes](https://github.com/cross-platform-actions/action/releases )
- [Changelog](https://github.com/cross-platform-actions/action/blob/master/changelog.md )
- [Commits](https://github.com/cross-platform-actions/action/compare/5ea7e8e4677bd726033a10b094ba1c5762b15dee...24ef01df165c76df1ed2b9f9e9212e78dc2fc963 )
Updates `github/codeql-action/init` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd )
Updates `github/codeql-action/analyze` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd )
Updates `signpath/github-action-submit-signing-request` from 2.2 to 2.3
- [Release notes](https://github.com/signpath/github-action-submit-signing-request/releases )
- [Commits](https://github.com/signpath/github-action-submit-signing-request/compare/b9d91eadd323de506c0c81cf0c7fe7438f3360fd...c92b958760219087e01f8d67a1669ed57afe2627 )
---
updated-dependencies:
- dependency-name: cross-platform-actions/action
dependency-version: 1.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: github/codeql-action/init
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: signpath/github-action-submit-signing-request
dependency-version: '2.3'
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-24 11:31:38 -05:00
dependabot[bot]
6d6302e327
CI: Bump the github-actions group with 2 updates
...
Bumps the github-actions group with 2 updates: [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) and [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request ).
Updates `docker/setup-qemu-action` from 4.1.0 to 4.2.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/06116385d9baf250c9f4dcb4858b16962ea869c3...96fe6ef7f33517b61c61be40b68a1882f3264fb8 )
Updates `signpath/github-action-submit-signing-request` from 1.3 to 2.2
- [Release notes](https://github.com/signpath/github-action-submit-signing-request/releases )
- [Commits](https://github.com/signpath/github-action-submit-signing-request/compare/ced31329c0317e779dad2eec2a7c3bb46ea1343e...b9d91eadd323de506c0c81cf0c7fe7438f3360fd )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: signpath/github-action-submit-signing-request
dependency-version: '2.2'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-05 21:28:37 -05:00
Carter Li
20277b9ee9
CI: adds dependabot.yml
2026-08-06 10:17:14 +08:00
Thibaud-Vdb
b6d95a0ce5
CI: declares least-privilege token permissions
...
Jobs without a permissions block get the repository's default token
scope, and reusable workflow calls pass the caller's grants straight
through. Scopes are now derived from what each workflow actually does
with the token:
- every build workflow declares contents: read; none of them writes
through the GITHUB_TOKEN.
- build-linux-hosts.yml keeps security-events: write for the CodeQL
upload; the other callers had that grant too but never upload
scanning results, so they drop it.
- build-windows-hosts.yml gets actions: read, which the SignPath
action documents needing to read job details and download the
unsigned artifact.
- build-release.yml declares contents: write, matching the grant its
caller already makes for creating the release.
Runs that execute pull request code now hold a token that can do
nothing but read the repository.
2026-08-05 20:59:02 -05:00
Thibaud-Vdb
daf5421be7
CI: passes only the secret each reusable workflow needs
...
Every reusable workflow call used 'secrets: inherit', which hands the
caller's whole secret set to the called workflow, but the only secret
any of them reads is SIGNPATH_API_TOKEN in build-windows-hosts.yml.
Passing that one secret explicitly and dropping inherit everywhere else
means a compromised step in, say, a BSD build VM has no signing token
to steal, and the workflow files now show exactly which secret flows
where.
The secret is declared optional in the reusable workflow so runs
without it (pull requests, forks) behave as before; the signing step
is already guarded to upstream push events.
2026-08-05 20:59:02 -05:00
Thibaud-Vdb
b739dfee0b
CI: pins actions to commit SHAs
...
A version tag like @v1 or a branch like @master is a movable pointer:
whoever controls the action repository can re-point it, and the next
run executes whatever it points at. Several of these actions run in
jobs whose outputs ship to users: build-release.yml creates the GitHub
release with the downloadable binaries, and build-windows-hosts.yml
holds the SignPath signing token, so a re-pointed tag there could ship
a tampered or wrongly signed release. This is exactly how the
tj-actions/changed-files compromise propagated (CVE-2025-30066).
Pinning by full commit SHA makes the reviewed code the code that runs,
the same way docker/setup-qemu-action is already pinned in
build-linux-vms.yml. Refs that pointed at master (cross-platform-actions,
setup-alpine, get-latest-release) are pinned to their latest release
tag. Every pin keeps a version comment, and each SHA was resolved from
the upstream repository and cross-checked against its release tag.
2026-08-05 20:59:02 -05:00
Carter Li
a58fc4f77d
CI: disable Haiku
...
Ref: https://github.com/haikuports/haikuports/issues/14445
2026-07-28 15:21:28 +08:00
徐晓伟
dda39f0c67
CI (Linux): adds loong64 build workflow ( #2469 )
...
* CI: add loong64 build workflow
Add reusable workflow for building fastfetch on LoongArch 64-bit
architecture using QEMU user-mode emulation + Docker container
(lcr.loongnix.cn/debian:14). Integrate into CI pipeline and
release dependencies.
* CI (loong64): pin docker/setup-qemu-action to full commit SHA
Pin to 06116385d9baf250c9f4dcb4858b16962ea869c3 (v4.1.0) for
immutable action reference as required by Codacy.
2026-07-21 21:14:38 +08:00
李通洲
69f3d9ae33
CI (FreeBSD): fixes building
2026-07-20 16:06:22 +08:00
Carter Li
bc8ce39193
Doc: update logo_request template [ci skip]
...
Ref: #2460
2026-07-16 10:30:56 +08:00
李通洲
2ae9c3da33
CI (Linux): removes armv6li
...
Doesn't have gcc13+
2026-07-11 08:14:25 +08:00
Carter Li
c31779e99d
CI: ensures CMAKE_BUILD_TYPE is correctly set
2026-07-10 14:44:39 +08:00
Carter Li
35dbcb2588
CI: updates scripts
2026-07-04 18:49:00 +08:00
Carter Li
49a1e42efd
CI: updates spellcheck
2026-06-18 13:39:56 +08:00
Carter Li
2edc41dd9a
CI (OpenBSD): updates packages
2026-06-11 15:14:39 +08:00
Carter Li
4594734b66
CI (OpenBSD): updates OS version
2026-06-09 16:07:56 +08:00
李通洲
8ee08d0067
CI: don't run heavy tests if the light one failed
2026-06-07 16:40:40 +08:00
李通洲
23ca6d94ab
CI: run codec module
2026-06-02 00:15:42 +08:00
Carter Li
2751737ebe
CI: builds with quickjs-ng support
2026-05-22 10:24:25 +08:00
李通洲
52972ed833
CI (Windows): bundles dlls of lua & qjs
2026-05-18 11:06:30 +08:00
李通洲
724b816252
CI: builds with lua support
2026-05-17 23:21:49 +08:00
李通洲
79c67ec0d7
CI (Linux): installs libefl
2026-05-13 14:37:39 +08:00
Carter Li
92082eed54
Doc: update PR template [ci skip]
2026-05-11 08:56:31 +08:00
Carter Li
0747fc0887
CI (OmniOS): fixes build
2026-05-10 17:35:33 +08:00
李通洲
77c916f747
CI: splits different jobs into different yml files
2026-04-03 08:55:38 +08:00
李通洲
6d73ecb944
CI: updates deps
2026-03-27 20:53:57 +08:00
李通洲
5f84630276
CI (macOS): disables vulkan because it crashes on Intel build
2026-03-27 09:50:32 +08:00
Carter Li
05fa8b0994
CI (Linux): fixes a CI error
...
```
kde-output-device-v2-client-protocol.h:257:9: error: implicit declaration of function 'wl_proxy_marshal_flags'; did you mean 'wl_proxy_marshal_array'? [-Werror=implicit-function-declaration]
257 | wl_proxy_marshal_flags((struct wl_proxy *) kde_output_device_registry_v2,
| ^~~~~~~~~~~~~~~~~~~~~~
| wl_proxy_marshal_array
```
2026-03-12 10:06:00 +08:00
李通洲
f781f8d9ea
Global (Windows): drops WIN7_COMPAT support
2026-03-07 11:49:56 +08:00
李通洲
14dccce393
CI (Linux): builds fastfetch with chafa support
2026-03-06 15:27:55 +08:00
Carter Li
ca8f54d331
CI: forwards envs & upgrades deps
2026-02-27 15:44:09 +08:00
李通洲
e6de2d4fd9
Doc: update issue template [ci skip]
2026-02-19 00:50:43 +08:00
李通洲
ba27f4f2ef
CI: adds Solaris
2026-02-11 15:50:58 +08:00
李通洲
4a581039d5
CI: fixes building
2026-01-24 09:17:13 +08:00
李通洲
79849fb2b5
CI: updates dependencies
2026-01-23 10:26:04 +08:00
李通洲
fd3c87abe7
Github: adds pull_request_template.md [ci skip]
2026-01-12 11:04:04 +08:00
李通洲
af075b8ef8
Github: update logo_request.yml [ci skip]
2026-01-12 11:04:04 +08:00
李通洲
0a17da2da0
CI (Windows): build win7-compat artifacts
2026-01-08 09:40:11 +08:00
李通洲
234552fbf2
CI (OpenBSD): uses clang-21
2026-01-07 16:22:28 +08:00
李通洲
7ae007a1d0
CI (OpenBSD): upgrades OS version
2026-01-07 08:58:20 +08:00
李通洲
2b620cf487
CI (SunOS): fixes a CI error
2025-12-04 16:15:20 +08:00
李通洲
db623b9c86
CI (Linux): adds Debian i386 packaging and verify deb package in CI
...
Fixes #2019
2025-10-22 17:45:50 +08:00