unsloth/.github/workflows/studio-tauri-smoke.yml
Daniel Han fadf48f562 deps: combine open dependabot PRs into one batched update
Consolidates eight of the ten open dependabot PRs into a single
review surface. Two are intentionally left out because they bundle
breaking-change deps that need source migration outside the scope
of a combine PR; dependabot recreates them on the next weekly tick:

  - #5364 (cargo-tauri group, 13 updates) bumps hmac 0.12 -> 0.13
    which removes Hmac::new_from_slice from the inherent impl, so
    studio/src-tauri/src/native_backend_lease.rs:152 fails to
    compile (error E0599). Also bumps sha2 0.10 -> 0.11 and
    reqwest 0.12 -> 0.13 which have their own migration surfaces.
    Needs a focused PR after the source migration.

  - #5365 (bun-frontend group, 14 updates) bumps TypeScript
    5.9 -> 6.0 promoting the baseUrl deprecation to a hard tsc
    error, plus @assistant-ui/react 0.12 -> 0.14 renaming the
    unstable_* exports, react-day-picker 9 -> 10 dropping the
    table classname, and recharts 3.7 -> 3.8.1 tightening the
    Key prop type. Same shape: needs a focused frontend
    migration PR.

The remaining eight land cleanly:

  - #4916  oxc-parser 0.123.0 -> 0.129.0 in /studio/backend/core/
           data_recipe/oxc-validator (npm-oxc-validator group)
  - #5343  hono 4.12.17 -> 4.12.18 and ip-address 10.1.0 -> 10.2.0
           in /studio/frontend (security advisory: GHSA-p77w-8qqv-26rm,
           GHSA-qp7p-654g-cw7p, GHSA-hm8q-7f3q-5f36)
  - #5362  python group (3 updates) in pyproject.toml
  - #5363  actions group (3 updates) in release-desktop /
           security-audit / studio-tauri-smoke workflows
  - #5366  openssl 0.10.76 -> 0.10.79 (security)
  - #5367  rand 0.10.0 -> 0.10.1 (security)
  - #5368  tauri 2.10.3 -> 2.11.1 (security; transitive bumps for
           tray-icon and wry come along)
  - #5369  rustls-webpki 0.103.10 -> 0.103.13 (security)

studio/src-tauri/Cargo.toml stays at main's values (hmac 0.12,
sha2 0.10, reqwest 0.12, rand 0.10.0, windows-sys 0.59); Cargo.lock
is regenerated by running cargo update -p <pkg> --precise <ver> for
each of the four security advisories on top of main, so only the
four pinned packages move and the rest of the dep graph stays
identical to main. Validated locally: cargo check passes through
the Rust source; the only error is the build-time frontendDist
check unrelated to source.
2026-05-12 00:39:15 +00:00

113 lines
4 KiB
YAML

# SPDX-License-Identifier: AGPL-3.0-only
# Copyright 2026-present the Unsloth AI Inc. team. All rights reserved.
# PR-time smoke for the Tauri desktop wrapper. Builds the frontend and the
# Tauri Linux debug binary, with no codesigning. Catches:
# - tauri.conf.json drift
# - src-tauri Cargo.toml or rust source breakage
# - Tauri CLI version drift (we pin 2.10.1, matching release-desktop.yml)
# - frontend output not picked up by Tauri's distDir
#
# Linux-only on a free `ubuntu-latest` runner. Mac and Windows desktop builds
# stay in release-desktop.yml (manual `workflow_dispatch`) because they need
# code-signing secrets and ~30 min of runner time each.
name: Studio Tauri CI
on:
pull_request:
paths:
- 'studio/frontend/**'
- 'studio/src-tauri/**'
# CLI rename / signature change can break Tauri's spawned
# `unsloth studio` -- include unsloth_cli in the trigger set.
- 'unsloth_cli/**'
- '.github/workflows/studio-tauri-smoke.yml'
push:
branches: [main, pip]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
linux-debug-build:
name: Tauri Linux debug build (no codesign)
runs-on: ubuntu-22.04
timeout-minutes: 25
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Linux native deps for Tauri / WebKit2GTK
run: |
sudo apt-get update
sudo apt-get install -y \
libwebkit2gtk-4.1-dev libayatana-appindicator3-dev \
librsvg2-dev libxdo-dev libssl-dev patchelf
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '24'
cache: 'npm'
cache-dependency-path: studio/frontend/package-lock.json
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable @ 2026-03-27
- uses: swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2.9.1
with:
workspaces: studio/src-tauri -> target
- name: Install pinned Tauri CLI (matches release-desktop.yml)
run: npm install --save-dev --prefix studio @tauri-apps/cli@2.10.1
- name: Verify pinned Tauri CLI version
run: |
out="$(npx --prefix studio tauri --version)"
echo "$out"
[ "$out" = "tauri-cli 2.10.1" ] || { echo "::error::expected tauri-cli 2.10.1, got $out"; exit 1; }
- name: Frontend build (npm ci, vite)
working-directory: studio/frontend
run: |
npm ci --no-fund --no-audit
npm run build
test -f dist/index.html
- name: Tauri debug build (Linux, no bundle, no codesign)
# `--debug` + `--no-bundle` keeps this lean: compiles the Rust crate,
# confirms the frontend dist is wired into Tauri, but skips the AppImage
# / .deb production. Code signing is irrelevant because we never produce
# a distributable artifact.
env:
TAURI_SIGNING_PRIVATE_KEY: ''
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ''
run: npx --prefix studio tauri build --debug --no-bundle
- name: Inspect produced binary
run: |
BIN=$(find studio/src-tauri/target/debug -maxdepth 1 -type f -executable 2>/dev/null \
| grep -Ev '\.(d|so|dylib|dll)$' \
| grep -Ev '/(deps|build|examples)$' \
| head -1)
echo "binary: $BIN"
if [ -z "$BIN" ]; then
echo "::error::Tauri debug binary not produced"
ls -la studio/src-tauri/target/debug/ || true
exit 1
fi
file "$BIN"
du -h "$BIN"
- name: Upload Tauri debug build
# Always upload so a green run leaves the binary inspectable too.
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: tauri-debug-build
path: |
studio/src-tauri/target/debug
studio/frontend/dist
retention-days: 3