Last security-audit run revealed 4 step-level errors hidden by
continue-on-error (the job reported pass but each fix is real):
1. OSV-Scanner curl 404 -> tar exit 2. v2.x ships a raw binary
(`osv-scanner_linux_amd64`), not a tarball. Drop tar -xzf,
curl -o the binary directly + chmod +x.
2. cargo audit `parse error: TOML parse error at line 5 col 8`
on RUSTSEC-2026-0073.md. cargo-audit 0.21 doesn't parse the
CVSS 4.0 schema used in 2026 advisories. Bump pin to ^0.22.
3. TruffleHog `flag 'no-update' cannot be repeated`. The
trufflesecurity/trufflehog action passes --no-update
internally already; remove our duplicate from extra_args.
4. cyclonedx-py `unrecognized arguments: --schema-version 1.6
--outfile ...`. cyclonedx-bom 4.x renamed to `--sv` for spec
version and `-o` for the output file.
Plus pin every remaining mutable-ref action to a 40-char SHA. The
new GHA pinning verifier flagged 4 third-party + 40 first-party
mutable refs; this commit pins all 44 to the latest SHA *within
the existing major version* (no auto-upgrades). Mappings:
actions/checkout @v4 -> 34e114876b... (v4.3.1)
actions/setup-node @v4 -> 49933ea528... (v4.4.0)
actions/setup-python @v5 -> a26af69be9... (v5.6.0)
actions/stale @v10 -> b5d41d4e1d... (v10.2.0)
actions/upload-artifact @v4 -> ea165f8d65... (v4.6.2)
actions/cache @v4 -> 0057852bfa... (v4.3.0)
swatinem/rust-cache @v2 -> 23869a5bd6... (v2.9.1)
dtolnay/rust-toolchain @stable-> 29eef336d9... (stable @ 2026-05-07)
44 pins applied across 11 workflow files. The pin verifier now
reports zero unpinned `uses:`. Dependabot's github-actions
ecosystem (already configured in .github/dependabot.yml) will
auto-bump these SHAs in weekly batches.
This closes the same attack class that hit litellm 1.82.7: an
attacker who hijacks a tag (as in the aquasecurity/trivy-action
March 2026 incident) cannot redirect our workflows because we no
longer follow tag refs.
108 lines
3.8 KiB
YAML
108 lines
3.8 KiB
YAML
# SPDX-License-Identifier: AGPL-3.0-only
|
|
# Copyright 2026-present the Unsloth AI Inc. team. All rights reserved.
|
|
|
|
# PR-time smoke for the Tauri desktop wrapper. Builds the frontend and the
|
|
# Tauri Linux debug binary, with no codesigning. Catches:
|
|
# - tauri.conf.json drift
|
|
# - src-tauri Cargo.toml or rust source breakage
|
|
# - Tauri CLI version drift (we pin 2.10.1, matching release-desktop.yml)
|
|
# - frontend output not picked up by Tauri's distDir
|
|
#
|
|
# Linux-only on a free `ubuntu-latest` runner. Mac and Windows desktop builds
|
|
# stay in release-desktop.yml (manual `workflow_dispatch`) because they need
|
|
# code-signing secrets and ~30 min of runner time each.
|
|
|
|
name: Studio Tauri CI
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- 'studio/frontend/**'
|
|
- 'studio/src-tauri/**'
|
|
- '.github/workflows/studio-tauri-smoke.yml'
|
|
push:
|
|
branches: [main, pip]
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
linux-debug-build:
|
|
name: Tauri Linux debug build (no codesign)
|
|
runs-on: ubuntu-22.04
|
|
timeout-minutes: 25
|
|
steps:
|
|
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
|
|
|
|
- name: Linux native deps for Tauri / WebKit2GTK
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y \
|
|
libwebkit2gtk-4.1-dev libayatana-appindicator3-dev \
|
|
librsvg2-dev libxdo-dev libssl-dev patchelf
|
|
|
|
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
|
|
with:
|
|
node-version: '24'
|
|
cache: 'npm'
|
|
cache-dependency-path: studio/frontend/package-lock.json
|
|
|
|
- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable @ 2026-05-07
|
|
|
|
- uses: swatinem/rust-cache@23869a5bd66c73db3c0ac40331f3206eb23791dc # v2.9.1
|
|
with:
|
|
workspaces: studio/src-tauri -> target
|
|
|
|
- name: Install pinned Tauri CLI (matches release-desktop.yml)
|
|
run: npm install --save-dev --prefix studio @tauri-apps/cli@2.10.1
|
|
|
|
- name: Verify pinned Tauri CLI version
|
|
run: |
|
|
out="$(npx --prefix studio tauri --version)"
|
|
echo "$out"
|
|
[ "$out" = "tauri-cli 2.10.1" ] || { echo "::error::expected tauri-cli 2.10.1, got $out"; exit 1; }
|
|
|
|
- name: Frontend build (npm ci, vite)
|
|
working-directory: studio/frontend
|
|
run: |
|
|
npm ci --no-fund --no-audit
|
|
npm run build
|
|
test -f dist/index.html
|
|
|
|
- name: Tauri debug build (Linux, no bundle, no codesign)
|
|
# `--debug` + `--no-bundle` keeps this lean: compiles the Rust crate,
|
|
# confirms the frontend dist is wired into Tauri, but skips the AppImage
|
|
# / .deb production. Code signing is irrelevant because we never produce
|
|
# a distributable artifact.
|
|
env:
|
|
TAURI_SIGNING_PRIVATE_KEY: ''
|
|
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ''
|
|
run: npx --prefix studio tauri build --debug --no-bundle
|
|
|
|
- name: Inspect produced binary
|
|
run: |
|
|
BIN=$(find studio/src-tauri/target/debug -maxdepth 1 -type f -executable 2>/dev/null \
|
|
| grep -Ev '\.(d|so|dylib|dll)$' \
|
|
| grep -Ev '/(deps|build|examples)$' \
|
|
| head -1)
|
|
echo "binary: $BIN"
|
|
if [ -z "$BIN" ]; then
|
|
echo "::error::Tauri debug binary not produced"
|
|
ls -la studio/src-tauri/target/debug/ || true
|
|
exit 1
|
|
fi
|
|
file "$BIN"
|
|
du -h "$BIN"
|
|
|
|
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
if: failure()
|
|
with:
|
|
name: tauri-debug-build
|
|
path: |
|
|
studio/src-tauri/target/debug
|
|
studio/frontend/dist
|
|
retention-days: 3
|