Skip to content

ci: adopt rainix nix-cachix-setup composite, drop deprecated DeterminateSystems nix installer - #8

Merged
thedavidmeister merged 1 commit into
mainfrom
2026-07-11-issue-7-nix-installer
Jul 12, 2026
Merged

thedavidmeister merged 1 commit into
mainfrom
2026-07-11-issue-7-nix-installer

Conversation

@thedavidmeister

Copy link
Copy Markdown
Contributor

Closes #7

What

Replace the two deprecated DeterminateSystems CI steps in .github/workflows/rainix.yaml with the org-standard shared composite:

  • DeterminateSystems/nix-installer-action@main → gone (also removes a floating @main pin — the supply-chain/reproducibility risk the issue flags)
  • DeterminateSystems/magic-nix-cache-action@main → gone
  • both replaced by rainlanguage/rainix/.github/actions/nix-cachix-setup@main (nix-quick-install + Cachix substituter + cache-nix-action store restore/save, every third-party action SHA-pinned in one place).

checkout: 'false' is passed because this job needs the existing actions/checkout@v4 with submodules: recursive + fetch-depth: 0 (the sol prelude and tests need submodules), which the composite's bundled default checkout would not replicate. The composite runs after the repo's own checkout.

This is the Preferred fix the issue calls for and retires a second deprecated DeterminateSystems action (magic-nix-cache) in the same change.

QA evidence (QA-GUIDE §8)

  • Category: CI-config change (a GitHub Actions workflow YAML). No executable code logic in the diff — no unit under test, nothing to mutation-test; the adversarial-mutation lens is N/A for this category (docs/CI fixes are verified end-to-end).
  • Oracle / discriminating check: the workflow is the test. rainix.yaml runs on: [push], so pushing this branch triggers the sol matrix — rainix-sol-test, rainix-sol-static — each run via nix develop -c …. If the installer/cache swap failed to provide nix, every nix develop step fails; a green matrix is direct end-to-end proof the swap works. Fails closed.
  • Fail-on-base confidence: main is green on both matrix tasks with the old DeterminateSystems steps; this PR re-runs the identical task set with only the nix-setup steps changed.
  • Interface correctness: composite used per its documented action.yml inputs (checkout, cachix-auth-token); checkout: 'false' matches the composite's inputs.checkout == 'true' gate. YAML validated (yq parse).
  • Scope: one file, +4/−2, no source or test changes; deterministic and reversible.

…ateSystems nix installer

Replaces the deprecated `DeterminateSystems/nix-installer-action@main` and
`DeterminateSystems/magic-nix-cache-action@main` steps with the org-standard
shared composite `rainlanguage/rainix/.github/actions/nix-cachix-setup@main`
(nix-quick-install + Cachix + cache-nix-action, third-party actions SHA-pinned
in one place; also drops the floating `@main` installer pin). `checkout: 'false'`
keeps the existing submodules-recursive/fetch-depth:0 checkout the sol prelude
and tests need.

Closes #7

Co-Authored-By: Claude <noreply@anthropic.com>
@thedavidmeister thedavidmeister self-assigned this Jul 11, 2026
@coderabbitai

coderabbitai Bot commented Jul 11, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@thedavidmeister, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 57 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 861e99df-c33b-4fe3-acb1-758f0cc043b9

📥 Commits

Reviewing files that changed from the base of the PR and between 6ea7c52 and 71a6996.

📒 Files selected for processing (1)
  • .github/workflows/rainix.yaml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 2026-07-11-issue-7-nix-installer

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thedavidmeister thedavidmeister added the ai:ready AI vetter: passes review, ready for human decision label Jul 11, 2026
@thedavidmeister

Copy link
Copy Markdown
Contributor Author

🤖 ai:vetter
Reviewed 71a6996: ready — closes #7 — adopts org-standard nix-cachix-setup composite, retires floating @main DeterminateSystems pins; checkout:'false' preserves submodules-recursive checkout (verified vs composite action.yml gate); rainix.yaml is the only workflow, coverage complete
cost 152 — CI installer swap, single workflow, gate verified

@thedavidmeister

Copy link
Copy Markdown
Contributor Author

Reviewed 71a6996: correct — swaps deprecated DeterminateSystems/nix-installer-action + magic-nix-cache-action for the org-standard rainlanguage/rainix/.github/actions/nix-cachix-setup@main composite. checkout: 'false' preserves the workflow's own submodules: recursive checkout (composite gates its internal checkout on that input, verified). Kills both old-nix-installer and dead-magic-nix-cache. All CI green; @main pin is org convention (rain.flare#123/#52). Ready.

@thedavidmeister
thedavidmeister merged commit d0b47f8 into main Jul 12, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai:ready AI vetter: passes review, ready for human decision

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: replace deprecated DeterminateSystems/nix-installer-action with org-standard nix-quick-install

1 participant