Pinned 2026 toolchains (Go 1.26, Rust 1.98/edition 2024, Python 3.14 + uv, Node 24, Zig 0.16, NixOS 26.05), postgres 18 / mongo 8, lockfiles built from, non-root runtimes, .dockerignore, per-project LICENSE, READMEs with the git.devai.io clone line, checkout@v7 CI. Security fixes in the legacy Rust APIs (any-password login, self-assigned admin, hard-coded JWT secret), JWT alg/exp/sub enforcement across the blog series, safe markdown links in the frontends, and many smaller bugs — every project was built, run and exercised end to end. Adds scripts/publish.sh + a CI publish job that splits every folder into its own repo at git.devai.io/templates/<folder>. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01128fhuZbgivaSJvtMf4s1G
21 lines
617 B
YAML
21 lines
617 B
YAML
name: ci
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
jobs:
|
|
check:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
# Evaluate the whole system (nothing is built) with the official Nix image.
|
|
- run: |
|
|
docker run --rm -v "$PWD:/src" -w /src \
|
|
-e NIX_CONFIG="experimental-features = nix-command flakes" \
|
|
nixos/nix:2.35.2 sh -ec '
|
|
git config --global --add safe.directory /src
|
|
nix flake check --no-build
|
|
nix eval --raw .#nixosConfigurations.desktop.config.system.build.toplevel.drvPath
|
|
'
|