CI: Pin some actions to the commit hash

This commit is contained in:
Davide Pesavento committed 2025-06-08 12:45:52 -04:00
1 parent 0ee6448403
commit d635ac82b8
5 files changed
+34 -36

No files matched your search

+17 -19
View File
@@ -25,9 +25,8 @@ env:
SDL_AUDIODRIVER: "dummy" #"disk"
#SDL_VIDEODRIVER: "dummy"
#BUILD_CONFIGURATION: Release #RelWithDebInfo
jobs:
jobs:
build:
name: Building AppImage
strategy:
@@ -38,10 +37,10 @@ jobs:
id: x86_64
- os: ubuntu-24.04-arm
id: aarch64
runs-on: '${{ matrix.os }}'
container: ghcr.io/pkgforge-dev/archlinux:latest
steps:
- uses: actions/checkout@v1 # v2+ seems to have submodules issue with the archlinux container
with:
@@ -57,14 +56,14 @@ jobs:
# Fix dubious ownership issue when running git describe inside a container
git config --global --add safe.directory "$PWD" # Alternatively, chown -R $(id -u):$(id -g) $PWD
echo "count=$(git tag -l 'v[0-9]*' | wc -l | tr -d ' ')" >> $GITHUB_OUTPUT
- name: Fetch upstream tags # required for git describe to return a valid version and to preevnt androidGitVersion from crashing on a new fork
if: ${{ steps.valid-tags.outputs.count == '0' }}
run: |
# TODO: should try to fetch tags from whereever this repo was forked from before fetching from official repo
git remote add upstream https://github.com/hrydgard/ppsspp.git # fetching from official repo as a fallback
git fetch --deepen=15000 --no-recurse-submodules --tags upstream || exit 0
#- name: Setup ccache # Doesn't support archlinux container?
# uses: hendrikmuhs/[email protected]
# with:
@@ -94,11 +93,11 @@ jobs:
else
PKG_TYPE='aarch64.pkg.tar.xz'
fi
LLVM_URL="https://github.com/pkgforge-dev/llvm-libs-debloated/releases/download/continuous/llvm-libs-nano-$PKG_TYPE"
LIBXML_URL="https://github.com/pkgforge-dev/llvm-libs-debloated/releases/download/continuous/libxml2-iculess-$PKG_TYPE"
OPUS_URL="https://github.com/pkgforge-dev/llvm-libs-debloated/releases/download/continuous/opus-nano-$PKG_TYPE"
echo "Installing build dependencies..."
echo "---------------------------------------------------------------"
pacman -Syu --noconfirm \
@@ -136,19 +135,19 @@ jobs:
if [[ "$ARCH" == "x86_64" ]]; then
pacman -Syu --noconfirm vulkan-intel
fi
echo "Installing debloated pckages..."
echo "---------------------------------------------------------------"
wget --retry-connrefused --tries=30 "$LLVM_URL" -O ./llvm-libs.pkg.tar.zst
wget --retry-connrefused --tries=30 "$LIBXML_URL" -O ./libxml2.pkg.tar.zst
wget --retry-connrefused --tries=30 "$OPUS_URL" -O ./opus-nano.pkg.tar.zst
pacman -U --noconfirm ./*.pkg.tar.zst
rm -f ./*.pkg.tar.zst
echo "All done!"
echo "---------------------------------------------------------------"
- name: Build Release
id: version
env:
@@ -171,10 +170,10 @@ jobs:
gcc --version
g++ --version
#clang --version
#clang++ --version
# Build ppsspp
#./b.sh --release --no-sdl2 --no-png
mkdir -p build
@@ -192,7 +191,7 @@ jobs:
# Test for missing modules
ldd ./build/PPSSPPSDL
# Create AppImage package
echo "Creating AppImage..."
chmod +x ./build/PPSSPPSDL
@@ -217,19 +216,18 @@ jobs:
if [ -e ./PPSSPP*.zsync ]; then
cp ./PPSSPP*.zsync artifacts/
fi
- name: Upload artifacts
uses: actions/upload-artifact@v4
with:
name: linux-${{ steps.version.outputs.tag }}-${{ matrix.id }} AppImage
path: artifacts/
- name: Upload release
uses: softprops/action-gh-release@v2
uses: softprops/action-gh-release@da05d552573ad5aba039eaac05058a918a7bf631 # v2.2.2
if: startsWith(github.ref, 'refs/tags/')
with:
token: ${{ secrets.GITHUB_TOKEN }}
files: |
artifacts/*.AppImage
artifacts/*.AppImage.zsync
+9 -8
View File
@@ -39,7 +39,7 @@ jobs:
submodules: recursive
- name: Add MSBuild to PATH
uses: microsoft/setup-msbuild@v2
uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2.0.0
- name: Build Windows
working-directory: ${{ env.GITHUB_WORKSPACE }}
@@ -76,7 +76,7 @@ jobs:
submodules: recursive
- name: Add MSBuild to PATH
uses: microsoft/setup-msbuild@v2
uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2.0.0
- name: Build UWP
working-directory: ${{ env.GITHUB_WORKSPACE }}
@@ -203,13 +203,14 @@ jobs:
git fetch --deepen=15000 --no-recurse-submodules --tags || exit 0
- name: Install Qt
uses: jurplel/install-qt-action@v4
uses: jurplel/install-qt-action@d325aaf2a8baeeda41ad0b5d39f84a6af9bcf005 # v4.3.0
if: matrix.extra == 'qt'
with:
cache: true
version: 5.15.2
- uses: nttld/setup-ndk@v1
- name: Setup Android NDK
uses: nttld/setup-ndk@afb4c9964b521afb97c864b7d40b11e6911bd410 # v1.5.0
if: matrix.extra == 'android'
id: setup-ndk
with:
@@ -229,7 +230,7 @@ jobs:
echo "#define PPSSPP_GIT_VERSION_NO_UPDATE 1" >> git-version.cpp
- name: Setup ccache
uses: hendrikmuhs/ccache-action@v1.2
uses: hendrikmuhs/ccache-action@63069e3931dedbf3b63792097479563182fe70d1 # v1.2.18
# Disable ccache on macos for now, it's become buggy for some reason.
if: matrix.id != 'macos'
with:
@@ -299,7 +300,7 @@ jobs:
mv PPSSPPSDL.zip PPSSPPSDL-macOS-${GITHUB_REF##*/}.zip || exit 1
- name: Upload macOS release
uses: softprops/action-gh-release@v2
uses: softprops/action-gh-release@da05d552573ad5aba039eaac05058a918a7bf631 # v2.2.2
if: startsWith(github.ref, 'refs/tags/') && runner.os == 'macOS' && matrix.extra == 'test'
with:
files: ppsspp/*.zip
@@ -383,8 +384,8 @@ jobs:
chown -R $(id -u):$(id -g) $PWD
- name: Setup ccache
uses: hendrikmuhs/ccache-action@v1.2
uses: hendrikmuhs/ccache-action@63069e3931dedbf3b63792097479563182fe70d1 # v1.2.18
- name: Compile ffmpeg
run: |
cd ffmpeg && ./linux_x86-64.sh
+1 -1
View File
@@ -57,7 +57,7 @@ jobs:
find . -name "Version.txt"
- name: Setup ccache
uses: hendrikmuhs/ccache-action@main
uses: hendrikmuhs/ccache-action@63069e3931dedbf3b63792097479563182fe70d1 # v1.2.18
with:
key: ios
create-symlink: true
+3 -3
View File
@@ -53,10 +53,10 @@ jobs:
# TODO: should try to fetch tags from whereever this repo was forked from before fetching from official repo
git remote add upstream https://github.com/hrydgard/ppsspp.git # fetching from official repo as a fallback
git fetch --deepen=15000 --no-recurse-submodules --tags upstream || exit 0
- name: Add MSBuild to PATH
uses: microsoft/setup-msbuild@v2
uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2.0.0
#- name: Setup cache # We probably need something like MSBuildCache for MSBuild to be able to use cache properly
# id: cache-uwp
# uses: actions/cache@v3
+4 -5
View File
@@ -14,12 +14,11 @@ jobs:
name: build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v4
with:
submodules: recursive
- name: archive
- name: Archive
id: archive
run: |
VERSION=${GITHUB_REF##*/}
@@ -42,8 +41,8 @@ jobs:
tar cJf $TARBALL $PKGNAME
echo "tarball=$TARBALL" >> $GITHUB_OUTPUT
- name: upload tarball
uses: softprops/action-gh-release@v1
- name: Upload tarball
uses: softprops/action-gh-release@da05d552573ad5aba039eaac05058a918a7bf631 # v2.2.2
with:
files: ${{ steps.archive.outputs.tarball }}
token: ${{ secrets.GITHUB_TOKEN }}