ci: adopt rainix nix-cachix-setup composite, drop deprecated DeterminateSystems nix installer - #5
Conversation
…ateSystems installer Replaces DeterminateSystems/nix-installer-action + magic-nix-cache-action with the shared rainlanguage/rainix nix-cachix-setup composite (pinned-SHA third-party actions, single source of truth). Closes #4. Co-Authored-By: Claude <noreply@anthropic.com>
WalkthroughThe test workflow replaces separate Nix installer and magic cache actions with the shared Rainix Nix/Cachix setup action, disabling its checkout behavior and passing the repository Cachix authentication token. ChangesCI Nix setup
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related issues
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/test.yaml:
- Line 16: Update the shared nix-cachix-setup action reference in the workflow
to use its current immutable commit SHA instead of the mutable `@main` ref. Keep
the action path and workflow behavior unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 168dae14-6a24-4e5e-b2f4-e5945849ef4d
📒 Files selected for processing (1)
.github/workflows/test.yaml
|
Reviewed 0579368: correct — swaps deprecated |
Closes #4
What
Replaces the deprecated
DeterminateSystems/nix-installer-action(+magic-nix-cache-action) in.github/workflows/test.yamlwith the org-standard shared compositerainlanguage/rainix/.github/actions/nix-cachix-setup@main, which bundles nix-quick-install + Cachix +cache-nix-actionand pins every third-party action to an exact SHA (single source of truth — "rainix owns shared CI"). The pre-existingactions/checkout@v4step is kept, so the composite is called withcheckout: 'false'.This is the same swap already applied and green on the pilot PRs rainlanguage/rain.chainlink#11 and rainlanguage/rain.tier.interface#8.
QA
CI-infrastructure-only change: it touches a single GitHub Actions workflow file and no source or test code, so there is no behavioral code surface to mutation-test — the discriminating oracle is the CI run itself.
Testjob must install Nix and runnix develop -c npm run testwith the composite in place of the removed installer. A mis-reference (wrong action path or input name) fails the setup step, so the swap is CI-green-discriminating, not a silent no-op.checkout,cachix-auth-token) was verified againstnix-cachix-setup/action.ymlonrainix@main.checkout: 'false'preserves the existingactions/checkout@v4(submodules recursive, fetch-depth 0). An emptyCACHIX_AUTH_TOKENdegrades to a read-only Cachix pull (the composite's documented default), so the job stays green whether or not the repo sets that secret.DeterminateSystems/nix-installer-actionwith org-standard nix-quick-install #4.Co-Authored-By: Claude noreply@anthropic.com
Summary by CodeRabbit