Consolidates eight of the ten open dependabot PRs into a single review surface. Two are intentionally left out because they bundle breaking-change deps that need source migration outside the scope of a combine PR; dependabot recreates them on the next weekly tick: - #5364 (cargo-tauri group, 13 updates) bumps hmac 0.12 -> 0.13 which removes Hmac::new_from_slice from the inherent impl, so studio/src-tauri/src/native_backend_lease.rs:152 fails to compile (error E0599). Also bumps sha2 0.10 -> 0.11 and reqwest 0.12 -> 0.13 which have their own migration surfaces. Needs a focused PR after the source migration. - #5365 (bun-frontend group, 14 updates) bumps TypeScript 5.9 -> 6.0 promoting the baseUrl deprecation to a hard tsc error, plus @assistant-ui/react 0.12 -> 0.14 renaming the unstable_* exports, react-day-picker 9 -> 10 dropping the table classname, and recharts 3.7 -> 3.8.1 tightening the Key prop type. Same shape: needs a focused frontend migration PR. The remaining eight land cleanly: - #4916 oxc-parser 0.123.0 -> 0.129.0 in /studio/backend/core/ data_recipe/oxc-validator (npm-oxc-validator group) - #5343 hono 4.12.17 -> 4.12.18 and ip-address 10.1.0 -> 10.2.0 in /studio/frontend (security advisory: GHSA-p77w-8qqv-26rm, GHSA-qp7p-654g-cw7p, GHSA-hm8q-7f3q-5f36) - #5362 python group (3 updates) in pyproject.toml - #5363 actions group (3 updates) in release-desktop / security-audit / studio-tauri-smoke workflows - #5366 openssl 0.10.76 -> 0.10.79 (security) - #5367 rand 0.10.0 -> 0.10.1 (security) - #5368 tauri 2.10.3 -> 2.11.1 (security; transitive bumps for tray-icon and wry come along) - #5369 rustls-webpki 0.103.10 -> 0.103.13 (security) studio/src-tauri/Cargo.toml stays at main's values (hmac 0.12, sha2 0.10, reqwest 0.12, rand 0.10.0, windows-sys 0.59); Cargo.lock is regenerated by running cargo update -p <pkg> --precise <ver> for each of the four security advisories on top of main, so only the four pinned packages move and the rest of the dep graph stays identical to main. Validated locally: cargo check passes through the Rust source; the only error is the build-time frontendDist check unrelated to source.
113 lines
4 KiB
YAML
113 lines
4 KiB
YAML
# SPDX-License-Identifier: AGPL-3.0-only
|
|
# Copyright 2026-present the Unsloth AI Inc. team. All rights reserved.
|
|
|
|
# PR-time smoke for the Tauri desktop wrapper. Builds the frontend and the
|
|
# Tauri Linux debug binary, with no codesigning. Catches:
|
|
# - tauri.conf.json drift
|
|
# - src-tauri Cargo.toml or rust source breakage
|
|
# - Tauri CLI version drift (we pin 2.10.1, matching release-desktop.yml)
|
|
# - frontend output not picked up by Tauri's distDir
|
|
#
|
|
# Linux-only on a free `ubuntu-latest` runner. Mac and Windows desktop builds
|
|
# stay in release-desktop.yml (manual `workflow_dispatch`) because they need
|
|
# code-signing secrets and ~30 min of runner time each.
|
|
|
|
name: Studio Tauri CI
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- 'studio/frontend/**'
|
|
- 'studio/src-tauri/**'
|
|
# CLI rename / signature change can break Tauri's spawned
|
|
# `unsloth studio` -- include unsloth_cli in the trigger set.
|
|
- 'unsloth_cli/**'
|
|
- '.github/workflows/studio-tauri-smoke.yml'
|
|
push:
|
|
branches: [main, pip]
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
linux-debug-build:
|
|
name: Tauri Linux debug build (no codesign)
|
|
runs-on: ubuntu-22.04
|
|
timeout-minutes: 25
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Linux native deps for Tauri / WebKit2GTK
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y \
|
|
libwebkit2gtk-4.1-dev libayatana-appindicator3-dev \
|
|
librsvg2-dev libxdo-dev libssl-dev patchelf
|
|
|
|
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
|
with:
|
|
node-version: '24'
|
|
cache: 'npm'
|
|
cache-dependency-path: studio/frontend/package-lock.json
|
|
|
|
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable @ 2026-03-27
|
|
|
|
- uses: swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2.9.1
|
|
with:
|
|
workspaces: studio/src-tauri -> target
|
|
|
|
- name: Install pinned Tauri CLI (matches release-desktop.yml)
|
|
run: npm install --save-dev --prefix studio @tauri-apps/cli@2.10.1
|
|
|
|
- name: Verify pinned Tauri CLI version
|
|
run: |
|
|
out="$(npx --prefix studio tauri --version)"
|
|
echo "$out"
|
|
[ "$out" = "tauri-cli 2.10.1" ] || { echo "::error::expected tauri-cli 2.10.1, got $out"; exit 1; }
|
|
|
|
- name: Frontend build (npm ci, vite)
|
|
working-directory: studio/frontend
|
|
run: |
|
|
npm ci --no-fund --no-audit
|
|
npm run build
|
|
test -f dist/index.html
|
|
|
|
- name: Tauri debug build (Linux, no bundle, no codesign)
|
|
# `--debug` + `--no-bundle` keeps this lean: compiles the Rust crate,
|
|
# confirms the frontend dist is wired into Tauri, but skips the AppImage
|
|
# / .deb production. Code signing is irrelevant because we never produce
|
|
# a distributable artifact.
|
|
env:
|
|
TAURI_SIGNING_PRIVATE_KEY: ''
|
|
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ''
|
|
run: npx --prefix studio tauri build --debug --no-bundle
|
|
|
|
- name: Inspect produced binary
|
|
run: |
|
|
BIN=$(find studio/src-tauri/target/debug -maxdepth 1 -type f -executable 2>/dev/null \
|
|
| grep -Ev '\.(d|so|dylib|dll)$' \
|
|
| grep -Ev '/(deps|build|examples)$' \
|
|
| head -1)
|
|
echo "binary: $BIN"
|
|
if [ -z "$BIN" ]; then
|
|
echo "::error::Tauri debug binary not produced"
|
|
ls -la studio/src-tauri/target/debug/ || true
|
|
exit 1
|
|
fi
|
|
file "$BIN"
|
|
du -h "$BIN"
|
|
|
|
- name: Upload Tauri debug build
|
|
# Always upload so a green run leaves the binary inspectable too.
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: tauri-debug-build
|
|
path: |
|
|
studio/src-tauri/target/debug
|
|
studio/frontend/dist
|
|
retention-days: 3
|