You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Add a shared OTP/Elixir toolchain preparation job - #49
Validate environment variable keys before serialization
.github/workflows/elixir-deps.yaml:55
The env contract accepts arbitrary JSON object keys, but the KEY=VALUE environment-file format cannot represent them safely. For example, {"A=B":"x"} is parsed as variable A with value B=x, while an empty key makes the runner reject the file. Validate keys as environment-variable names before serializing them so invalid input fails explicitly instead of exporting the wrong environment.
The reason will be displayed to describe this comment to others. Learn more.
Awesome work! Thank you for including the documentation and the tests as well.
suggestion (non-blocking): The drawback of having a workflow layer is as documented that it requires a 2-releases process. Since elixir-deps and elixir-toolchain seem to always be invoked together, I was wondering if it's possible to release one (big) action only containing all the steps.
The reason will be displayed to describe this comment to others. Learn more.
Thank you for addressing the release remark and also for implementing the one action flavor, I needed to see it to figure out it wouldn't work as well.
The cache key ignores dependency declarations in mix.exs. Changes such as adding a path dependency can leave mix.lock unchanged, so this remains an exact hit and the build-deps steps are skipped, leaving the restored dependency tree incomplete. Hash the project manifests (including umbrella children) as well as lockfiles.
Test job lacks read-only permissions and credential persistence safeguards
docs/elixir-toolchain.md:82
The test example drops both safeguards used for the dependency-build job. A typical following mix test executes dependency code while checkout's credential remains available in the local Git configuration; with writable default token permissions, that code can use the token. Add read-only permissions and disable credential persistence here as well.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adding shared composite actions that web and wanda can use to:
actions/elixir-toolchain)actions/setup-elixir)actions/setup-elixirwithbuild-deps: "true")Callers define their own toolchain and deps jobs.
See usages in: