ci: adopt rainix nix-cachix-setup composite, drop deprecated DeterminateSystems nix installer - #13
Conversation
…ateSystems nix installer Closes #12 Co-Authored-By: Claude <noreply@anthropic.com>
WalkthroughThe build workflow replaces ChangesCI setup modernization
Estimated code review effort: 2 (Simple) | ~5 minutes Possibly related issues
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/build.yaml:
- Around line 16-19: Update the shared action reference in the workflow step
using rainlanguage/rainix/.github/actions/nix-cachix-setup so it is pinned to a
specific immutable commit SHA instead of the mutable `@main` ref, while preserving
the existing checkout and cachix-auth-token inputs.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: a33d1298-ba61-4afc-ba3b-0e5cffc43971
📒 Files selected for processing (1)
.github/workflows/build.yaml
|
🤖 ai:vetter |
Closes #12
What
Replaces the deprecated
DeterminateSystems/nix-installer-action@v4in.github/workflows/build.yamlwith the org-standard shared compositerainlanguage/rainix/.github/actions/nix-cachix-setup@main, which bundles nix-quick-install + Cachix +cache-nix-actionand pins every third-party action to an exact SHA (single source of truth — "rainix owns shared CI"). The pre-existingactions/checkout@v3step is kept, so the composite is called withcheckout: 'false'.build.yamlis the only workflow flagged by roh-scan'sold-nix-installersignal here;test.yamlinstalls no Nix (cargo testruns on the runner toolchain), so it is untouched.This is the same swap already applied and green on the pilot PRs rainlanguage/rain.chainlink#11, rainlanguage/rain.tier.interface#8, and rainlanguage/assemblyscript-cbor#5.
QA
CI-infrastructure-only change: it touches a single GitHub Actions workflow file and no source or test code, so there is no behavioral code surface to mutation-test — the discriminating oracle is the CI run itself.
build.yamlruns onpull_request, so this PR's own CI exercises the swap on theubuntu-latest/macos-latestmatrix: theBuildjob must install Nix via the composite and runnix build . --print-build-logs. A mis-reference (wrong action path or input name) fails the setup step, so the swap is CI-green-discriminating, not a silent no-op.checkout,cachix-auth-token) matchesnix-cachix-setup/action.ymlonrainix@main.checkout: 'false'preserves the existingactions/checkout@v3. An emptyCACHIX_AUTH_TOKENdegrades to a read-only Cachix pull (the composite's documented default), so the job stays green whether or not the repo sets that secret.DeterminateSystems/nix-installer-actionwith org-standard nix-quick-install #12.Co-Authored-By: Claude noreply@anthropic.com
Summary by CodeRabbit