diff --git a/.github/actions/build-site/action.yml b/.github/actions/build-site/action.yml new file mode 100644 index 0000000..51c3b27 --- /dev/null +++ b/.github/actions/build-site/action.yml @@ -0,0 +1,61 @@ +name: Build and check the site +description: >- + Installs the pinned Hugo, builds the production site into public/, and tests + invariants. Shared by the deploy and the pull request workflows. + +runs: + using: composite + steps: + # Standard edition is sufficient: the site writes plain CSS, uses no Sass + # and no image processing. + - name: Install Hugo + shell: bash + env: + # The entire dependency manifest for this site is these two values. + # To bump: change the version, download the tarball, and replace the + # checksum with `sha256sum hugo__linux-amd64.tar.gz`. + HUGO_VERSION: 0.162.1 + HUGO_SHA256: 4bfcdb092d0306586f1b72e5687787ead053faab2d71f09951d3c5fecde66873 + run: | + set -euo pipefail + url="https://github.com/gohugoio/hugo/releases/download/v${HUGO_VERSION}/hugo_${HUGO_VERSION}_linux-amd64.tar.gz" + curl -sSLf -o hugo.tar.gz "$url" + echo "${HUGO_SHA256} hugo.tar.gz" | sha256sum --check --strict - + tar -xzf hugo.tar.gz hugo + rm hugo.tar.gz + ./hugo version + + # No -D, so drafts stay off the rendered site. + - name: Build + shell: bash + run: ./hugo --minify --printPathWarnings + env: + HUGO_ENVIRONMENT: production + + # baseURL is the only place the domain may appear. Templates must build + # URLs with .Permalink/.RelPermalink/relURL/absURL so that changing the + # domain stays a one-line edit. + - name: Assert no hardcoded host + shell: bash + run: | + if grep -rnE 'https?://(www\.)?lnfuzz\.(org|github\.io)' layouts/ content/ data/; then + echo "::error::A template or page hardcodes the site's own host. Use relURL/absURL instead." + exit 1 + fi + + # No JavaScript and no third-party requests. + - name: Assert no scripts or third-party requests + shell: bash + run: | + if grep -rniE '_linux-amd64.tar.gz`. - HUGO_VERSION: 0.162.1 - HUGO_SHA256: 4bfcdb092d0306586f1b72e5687787ead053faab2d71f09951d3c5fecde66873 - jobs: build: runs-on: ubuntu-latest @@ -30,50 +23,11 @@ jobs: - name: Checkout uses: actions/checkout@v4 - # Standard edition is sufficient: the site writes plain CSS, uses no Sass - # and no image processing. - - name: Install Hugo - run: | - set -euo pipefail - url="https://github.com/gohugoio/hugo/releases/download/v${HUGO_VERSION}/hugo_${HUGO_VERSION}_linux-amd64.tar.gz" - curl -sSLf -o hugo.tar.gz "$url" - echo "${HUGO_SHA256} hugo.tar.gz" | sha256sum --check --strict - - tar -xzf hugo.tar.gz hugo - ./hugo version - - name: Setup Pages uses: actions/configure-pages@v5 - # No -D, so drafts stay off the rendered site. - - name: Build - run: ./hugo --minify --printPathWarnings - env: - HUGO_ENVIRONMENT: production - - # baseURL is the only place the domain may appear. Templates must build - # URLs with .Permalink/.RelPermalink/relURL/absURL so that changing the - # domain stays a one-line edit. - - name: Assert no hardcoded host - run: | - if grep -rnE 'https?://(www\.)?lnfuzz\.(org|github\.io)' layouts/ content/ data/; then - echo "::error::A template or page hardcodes the site's own host. Use relURL/absURL instead." - exit 1 - fi - - # No JavaScript and no third-party requests. - - name: Assert no scripts or third-party requests - run: | - if grep -rniE '