From 0a838d0945b77ccb15515472637ab34bf969ad2c Mon Sep 17 00:00:00 2001 From: meh Date: Wed, 29 Jul 2026 01:52:10 +0700 Subject: [PATCH] Run CI on Ubicloud runners, and add a cargo audit job CI across ~/code runs on Ubicloud; `ubuntu-latest` here was billing GitHub Actions minutes instead. Switched to `ubicloud-standard-2`. Sized deliberately rather than copied: the heavier repos use `-8`, but this crate's whole check job finishes in about 40 seconds, and Ubicloud bills by vCPU-minute, so a larger runner would cost more for no wall-clock gain. WorkTable uses `-2` for the same reason. Added a `cargo audit` job, matching honey_id-types, the closest analogue as another published library. Worth having now that this crate is on crates.io: an advisory against tokio or serde reaches every consumer and nothing else in CI would notice. It runs on `-2` since it is a lookup, not a build. Recorded the runner rule in AGENTS.md so it survives the next person reaching for `ubuntu-latest` out of habit, including the part that bites on new repos: Ubicloud has to be enabled per repository or workflows queue forever. --- .github/workflows/ci.yml | 25 ++++++++++++++++++++++++- AGENTS.md | 11 +++++++++++ 2 files changed, 35 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f1cfde2..53e75f8 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -13,7 +13,13 @@ env: jobs: check: name: fmt, clippy, test - runs-on: ubuntu-latest + # Ubicloud, never a GitHub-hosted label: CI here runs on Ubicloud runners + # and `ubuntu-latest` would quietly bill GitHub Actions minutes instead. + # `-2` is deliberate rather than lazy: this job finishes in well under a + # minute, and Ubicloud bills by vCPU-minute, so a larger runner costs more + # for no wall-clock gain. Reach for `-4`/`-8` when a build is actually the + # bottleneck. + runs-on: ubicloud-standard-2 steps: - uses: actions/checkout@v4 @@ -45,3 +51,20 @@ jobs: run: cargo doc --no-deps env: RUSTDOCFLAGS: -D warnings + + audit: + name: cargo audit + runs-on: ubicloud-standard-2 + permissions: + contents: read + # `audit-check` reports advisories as check annotations. + checks: write + issues: write + steps: + - uses: actions/checkout@v4 + + # Worth having now that the crate is published: an advisory against tokio + # or serde reaches every consumer, and nothing else here would notice. + - uses: rustsec/audit-check@v2 + with: + token: ${{ secrets.GITHUB_TOKEN }} diff --git a/AGENTS.md b/AGENTS.md index 0ea67dc..455d1c7 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -38,6 +38,17 @@ Copilot CLIs headlessly behind one API. Consumed as a direct dependency by the `unsafe_code = "deny"` rather than `forbid` so that one audited call can be excepted. A second `unsafe` anywhere is a design question, not a local decision. +## CI runners + +**Never `runs-on: ubuntu-latest`**, or any other GitHub-hosted label. CI here runs on +Ubicloud: `ubicloud-standard-2` / `-4` / `-8`. A GitHub-hosted label is not a neutral +default, it silently bills GitHub Actions minutes instead. + +Size by what the job actually needs. This crate's checks finish in well under a minute, so +`-2` is correct; Ubicloud bills by vCPU-minute and a bigger runner costs more for no +wall-clock gain. Ubicloud must also be enabled for a repository before its runners will +pick up jobs, so a new repo needs that done first or workflows queue forever. + ## Build & run ```bash