diff --git a/.github/actions/setup-rust/action.yml b/.github/actions/setup-rust/action.yml index 58fd5f8e6..4017d0897 100644 --- a/.github/actions/setup-rust/action.yml +++ b/.github/actions/setup-rust/action.yml @@ -20,8 +20,16 @@ inputs: runs: using: composite steps: - - name: Setup Rust nightly - uses: dtolnay/rust-toolchain@nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + working_directory: ${{ github.action_path }}/../../.. + cache: false - name: Setup Depot uses: depot/setup-action@v1 diff --git a/.github/workflows/ci-fast.yml b/.github/workflows/ci-fast.yml index f992e243f..32c778b63 100644 --- a/.github/workflows/ci-fast.yml +++ b/.github/workflows/ci-fast.yml @@ -61,6 +61,8 @@ jobs: rust: - 'Cargo.toml' - 'Cargo.lock' + - 'mise*.toml' + - 'rust-toolchain.toml' - '.cargo/**' - 'crates/**' - 'packages/**' @@ -84,6 +86,10 @@ jobs: - 'crates/alien-terraform/**' - '.github/workflows/ci-fast.yml' typescript: + - 'mise*.toml' + - 'rust-toolchain.toml' + - '.github/workflows/ci-fast.yml' + - '.github/workflows/ci-fork.yml' # `pnpm format-and-lint` runs Biome from the repository root. # Match its source formats repository-wide instead of trying to # enumerate every directory that may contain linted files. @@ -134,19 +140,35 @@ jobs: steps: - uses: actions/checkout@v7 - - uses: pnpm/action-setup@v6 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm bun + cache_key: "{{default}}-${{ hashFiles('package.json') }}" - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm cache-dependency-path: | pnpm-lock.yaml examples/pnpm-lock.yaml - - uses: dtolnay/rust-toolchain@nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust with: - components: rustfmt, clippy + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: mozilla-actions/sccache-action@v0.0.11 continue-on-error: true @@ -155,10 +177,6 @@ jobs: - uses: taiki-e/install-action@nextest - - uses: oven-sh/setup-bun@v2 - with: - bun-version: "1.4.2" - - name: Install protoc uses: arduino/setup-protoc@v3 with: @@ -336,6 +354,10 @@ jobs: with: filters: | examples: + - 'mise*.toml' + - 'rust-toolchain.toml' + - '.github/workflows/ci-fast.yml' + - '.github/workflows/ci-fork.yml' - 'examples/**' - 'packages/**' # Changes to the generated Platform client can break the ordinary @@ -349,29 +371,41 @@ jobs: - 'crates/alien-bindings/**' - 'crates/alien-build/**' - - uses: pnpm/action-setup@v6 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm bun + cache_key: "{{default}}-${{ hashFiles('package.json') }}" - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm cache-dependency-path: | pnpm-lock.yaml examples/pnpm-lock.yaml - - uses: dtolnay/rust-toolchain@nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust with: - components: rustfmt, clippy + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: mozilla-actions/sccache-action@v0.0.11 continue-on-error: true with: version: v0.16.0 - - uses: oven-sh/setup-bun@v2 - with: - bun-version: "1.4.2" - - name: Install protoc uses: arduino/setup-protoc@v3 with: @@ -454,9 +488,9 @@ jobs: - name: Install operation compiler generation tools run: | - rustup toolchain install 1.97.1 --profile minimal --target wasm32-unknown-unknown + MISE_DATA_DIR="$RUNNER_TEMP/mise-rust" mise -E release-prepare install rust VERSION=$(node -e 'const fs = require("node:fs"); console.log(fs.readFileSync("Cargo.lock", "utf8").match(/name = "wasm-bindgen"\nversion = "([^"]+)"/)[1])') - cargo +1.97.1 install --locked --version "$VERSION" wasm-bindgen-cli + MISE_DATA_DIR="$RUNNER_TEMP/mise-rust" mise -E release-prepare exec -- cargo install --locked --version "$VERSION" wasm-bindgen-cli - name: Regenerate local TypeScript APIs run: pnpm generate diff --git a/.github/workflows/ci-fork.yml b/.github/workflows/ci-fork.yml index 99a320663..f743fe2bc 100644 --- a/.github/workflows/ci-fork.yml +++ b/.github/workflows/ci-fork.yml @@ -37,17 +37,33 @@ jobs: - uses: actions/checkout@v7 - - uses: pnpm/action-setup@v6 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('package.json') }}" - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm cache-dependency-path: pnpm-lock.yaml - - uses: dtolnay/rust-toolchain@nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust with: - components: rustfmt, clippy + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: Swatinem/rust-cache@v2 @@ -99,9 +115,9 @@ jobs: - name: Install operation compiler generation tools run: | - rustup toolchain install 1.97.1 --profile minimal --target wasm32-unknown-unknown + MISE_DATA_DIR="$RUNNER_TEMP/mise-rust" mise -E release-prepare install rust VERSION=$(node -e 'const fs = require("node:fs"); console.log(fs.readFileSync("Cargo.lock", "utf8").match(/name = "wasm-bindgen"\nversion = "([^"]+)"/)[1])') - cargo +1.97.1 install --locked --version "$VERSION" wasm-bindgen-cli + MISE_DATA_DIR="$RUNNER_TEMP/mise-rust" mise -E release-prepare exec -- cargo install --locked --version "$VERSION" wasm-bindgen-cli - name: Regenerate local TypeScript APIs run: pnpm generate diff --git a/.github/workflows/cloud-tests.yml b/.github/workflows/cloud-tests.yml index 3f315e2a6..eb8d1ccad 100644 --- a/.github/workflows/cloud-tests.yml +++ b/.github/workflows/cloud-tests.yml @@ -292,7 +292,15 @@ jobs: --gcp "${{ inputs.gcp_target || 'gcp-target-3' }}" \ --azure "${{ inputs.azure_target || 'azure-target-1' }}" - - uses: dtolnay/rust-toolchain@nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: depot/setup-action@v1 diff --git a/.github/workflows/e2e-cloud.yml b/.github/workflows/e2e-cloud.yml index 8d350dcd5..6691fff7e 100644 --- a/.github/workflows/e2e-cloud.yml +++ b/.github/workflows/e2e-cloud.yml @@ -506,22 +506,25 @@ jobs: targets: x86_64-unknown-linux-musl install-protoc: "true" - - uses: pnpm/action-setup@v6 - if: needs.compute-matrix.outputs.needs_bindings_x86_64 == 'true' + - if: needs.compute-matrix.outputs.needs_bindings_x86_64 == 'true' + name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust with: - version: 10.34.5 + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm bun + cache_key: "{{default}}-${{ hashFiles('package.json') }}" - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 if: needs.compute-matrix.outputs.needs_bindings_x86_64 == 'true' with: - node-version: 24 cache: pnpm - - uses: oven-sh/setup-bun@v2 - if: needs.compute-matrix.outputs.needs_bindings_x86_64 == 'true' - with: - bun-version: "1.4.2" - - name: Install JS dependencies if: needs.compute-matrix.outputs.needs_bindings_x86_64 == 'true' run: pnpm install --frozen-lockfile @@ -604,22 +607,25 @@ jobs: targets: aarch64-unknown-linux-musl install-protoc: "true" - - uses: pnpm/action-setup@v6 - if: needs.compute-matrix.outputs.needs_bindings_aarch64 == 'true' + - if: needs.compute-matrix.outputs.needs_bindings_aarch64 == 'true' + name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust with: - version: 10.34.5 + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm bun + cache_key: "{{default}}-${{ hashFiles('package.json') }}" - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 if: needs.compute-matrix.outputs.needs_bindings_aarch64 == 'true' with: - node-version: 24 cache: pnpm - - uses: oven-sh/setup-bun@v2 - if: needs.compute-matrix.outputs.needs_bindings_aarch64 == 'true' - with: - bun-version: "1.4.2" - - name: Install JS dependencies if: needs.compute-matrix.outputs.needs_bindings_aarch64 == 'true' run: pnpm install --frozen-lockfile @@ -1262,7 +1268,15 @@ jobs: ) & echo "OIDC_REFRESH_PID=$!" >> $GITHUB_ENV - - uses: dtolnay/rust-toolchain@nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: depot/setup-action@v1 @@ -1287,17 +1301,21 @@ jobs: with: version: 0.16.0 - - uses: oven-sh/setup-bun@v2 - with: - bun-version: "1.4.2" - - - uses: pnpm/action-setup@v6 + - name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust with: - version: 10.34.5 + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm bun + cache_key: "{{default}}-${{ hashFiles('package.json') }}" + id: mise - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm - name: Install JS dependencies and build packages @@ -1361,7 +1379,15 @@ jobs: with: name: env-test-e2e - - uses: dtolnay/rust-toolchain@nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: depot/setup-action@v1 @@ -1386,17 +1412,21 @@ jobs: with: version: 0.16.0 - - uses: oven-sh/setup-bun@v2 - with: - bun-version: "1.4.2" - - - uses: pnpm/action-setup@v6 + - name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust with: - version: 10.34.5 + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm bun + cache_key: "{{default}}-${{ hashFiles('package.json') }}" + id: mise - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm - uses: hashicorp/setup-terraform@v4 @@ -1510,7 +1540,15 @@ jobs: if: needs.compute-matrix.outputs.build_operator_image == 'true' run: docker pull ${{ needs.build-operator-image.outputs.operator_image }} - - uses: dtolnay/rust-toolchain@nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: depot/setup-action@v1 @@ -1535,17 +1573,21 @@ jobs: with: version: 0.16.0 - - uses: oven-sh/setup-bun@v2 - with: - bun-version: "1.4.2" - - - uses: pnpm/action-setup@v6 + - name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust with: - version: 10.34.5 + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm bun + cache_key: "{{default}}-${{ hashFiles('package.json') }}" + id: mise - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm - uses: hashicorp/setup-terraform@v4 @@ -1674,7 +1716,15 @@ jobs: with: name: env-test-e2e - - uses: dtolnay/rust-toolchain@nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false # depot cargo works on Linux/macOS; Windows uses sccache directly - uses: depot/setup-action@v1 @@ -1714,17 +1764,21 @@ jobs: with: version: 0.16.0 - - uses: oven-sh/setup-bun@v2 - with: - bun-version: "1.4.2" - - - uses: pnpm/action-setup@v6 + - name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust with: - version: 10.34.5 + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm bun + cache_key: "{{default}}-${{ hashFiles('package.json') }}" + id: mise - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm - name: Install JS dependencies and build packages diff --git a/.github/workflows/egress-deny-guard.yml b/.github/workflows/egress-deny-guard.yml index 7eb33f2a4..42763ea57 100644 --- a/.github/workflows/egress-deny-guard.yml +++ b/.github/workflows/egress-deny-guard.yml @@ -41,10 +41,22 @@ jobs: - name: Configure git credentials run: git config --global url."https://x-access-token:${{ secrets.REPO_ACCESS_TOKEN }}@github.com/".insteadOf "https://github.com/" - - uses: dtolnay/rust-toolchain@7c8d7d138f5c09cef361f8214cf96882cd029cdb # nightly + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust with: - toolchain: nightly - targets: aarch64-unknown-linux-musl + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false + - name: Install Rust targets + shell: bash + env: + RUST_TARGETS: aarch64-unknown-linux-musl + run: | + read -r -a targets <<< "${RUST_TARGETS//$'\n'/ }" + rustup target add "${targets[@]}" - uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11 continue-on-error: true @@ -297,10 +309,16 @@ jobs: if: steps.survived.outputs.stack == 'present' run: git config --global url."https://x-access-token:${{ secrets.REPO_ACCESS_TOKEN }}@github.com/".insteadOf "https://github.com/" - - uses: dtolnay/rust-toolchain@7c8d7d138f5c09cef361f8214cf96882cd029cdb # nightly - if: steps.survived.outputs.stack == 'present' + - if: steps.survived.outputs.stack == 'present' + name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust with: - toolchain: nightly + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: taiki-e/install-action@43cb5d9d3c33252b8482ffa34f4e609859a530d8 # cargo-nextest if: steps.survived.outputs.stack == 'present' diff --git a/.github/workflows/publish-npm-dev.yml b/.github/workflows/publish-npm-dev.yml index 2d7b26ac5..72487e311 100644 --- a/.github/workflows/publish-npm-dev.yml +++ b/.github/workflows/publish-npm-dev.yml @@ -52,11 +52,22 @@ jobs: echo "git_sha=$git_sha" >> "$GITHUB_OUTPUT" echo "short_sha=${git_sha:0:12}" >> "$GITHUB_OUTPUT" - - uses: pnpm/action-setup@v4 - - - uses: actions/setup-node@v7 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .npm-dev-tools + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('.npm-dev-tools/package.json') }}" + + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm - name: Test version and dependency rewriting @@ -111,16 +122,31 @@ jobs: with: ref: ${{ needs.prepare.outputs.git_sha }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .npm-dev-tools + persist-credentials: false + - name: Setup Rust (linux) if: matrix.os == 'linux' - uses: ./.github/actions/setup-rust + uses: ./.npm-dev-tools/.github/actions/setup-rust with: depot-project-id: ${{ vars.DEPOT_PROJECT_ID }} repo-access-token: ${{ secrets.REPO_ACCESS_TOKEN }} install-protoc: "true" - - uses: dtolnay/rust-toolchain@nightly - if: matrix.os == 'macos' + - if: matrix.os == 'macos' + name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .npm-dev-tools + install_args: rust + cache: false - name: Configure git credentials for cargo (macos) if: matrix.os == 'macos' @@ -134,11 +160,22 @@ jobs: if: matrix.target == 'x86_64-apple-darwin' run: rustup target add x86_64-apple-darwin - - uses: pnpm/action-setup@v4 - - - uses: actions/setup-node@v7 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .npm-dev-tools + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('.npm-dev-tools/package.json') }}" + + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm - name: Install dependencies @@ -214,11 +251,22 @@ jobs: ref: ${{ github.ref }} path: .npm-dev-tools - - uses: pnpm/action-setup@v4 - - - uses: actions/setup-node@v7 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .npm-dev-tools + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('.npm-dev-tools/package.json') }}" + + - name: Cache pnpm dependencies and configure npm registry + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm registry-url: https://registry.npmjs.org diff --git a/.github/workflows/python-bindings.yml b/.github/workflows/python-bindings.yml index 0da6f3c66..d8597c0b5 100644 --- a/.github/workflows/python-bindings.yml +++ b/.github/workflows/python-bindings.yml @@ -5,6 +5,8 @@ on: paths: - "Cargo.lock" - "Cargo.toml" + - "mise*.toml" + - "rust-toolchain.toml" - "crates/alien-bindings/**" - "crates/alien-ai-gateway/**" - "crates/alien-core/src/bindings/**" @@ -16,6 +18,8 @@ on: paths: - "Cargo.lock" - "Cargo.toml" + - "mise*.toml" + - "rust-toolchain.toml" - "crates/alien-bindings/**" - "crates/alien-ai-gateway/**" - "crates/alien-core/src/bindings/**" @@ -36,7 +40,16 @@ jobs: runs-on: ${{ matrix.os }} steps: - uses: actions/checkout@v4 - - uses: dtolnay/rust-toolchain@stable + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + MISE_ENV: stable + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: actions/setup-python@v5 with: python-version: ${{ matrix.python }} @@ -72,10 +85,20 @@ jobs: runs-on: ${{ matrix.os }} steps: - uses: actions/checkout@v4 - - uses: dtolnay/rust-toolchain@stable + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + MISE_ENV: stable + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: rust + cache: false - uses: PyO3/maturin-action@v1 with: command: build + rust-toolchain: ${{ env.RUSTUP_TOOLCHAIN }} target: ${{ matrix.target }} manylinux: ${{ matrix.manylinux }} args: --manifest-path crates/alien-bindings-python/Cargo.toml --release --out dist --no-default-features --features all-platforms,platform-sdk diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4fa727dba..2dbd5e1c4 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -87,6 +87,12 @@ jobs: token: ${{ secrets.REPO_ACCESS_TOKEN }} fetch-depth: 0 + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - name: Verify qualification source commit if: ${{ inputs.stable_action == 'qualification' }} env: @@ -309,18 +315,32 @@ jobs: if: ${{ inputs.stable_action == 'prepare' || inputs.dry_run }} run: cargo metadata --format-version 1 >/dev/null - - name: Install permission compiler toolchain + - if: ${{ inputs.stable_action == 'prepare' || inputs.dry_run }} + name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + MISE_ENV: release-prepare + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: rust + cache: false + - name: Install Rust targets + shell: bash + env: + RUST_TARGETS: wasm32-unknown-unknown + run: | + read -r -a targets <<< "${RUST_TARGETS//$'\n'/ }" + rustup target add "${targets[@]}" if: ${{ inputs.stable_action == 'prepare' || inputs.dry_run }} - uses: dtolnay/rust-toolchain@stable - with: - toolchain: 1.97.1 - targets: wasm32-unknown-unknown - name: Regenerate versioned permission compiler if: ${{ inputs.stable_action == 'prepare' || inputs.dry_run }} run: | VERSION=$(node -e 'const fs = require("node:fs"); console.log(fs.readFileSync("Cargo.lock", "utf8").match(/name = "wasm-bindgen"\nversion = "([^"]+)"/)[1])') - cargo +1.97.1 install --locked --version "$VERSION" wasm-bindgen-cli + MISE_DATA_DIR="$RUNNER_TEMP/mise-rust" mise --cd .ci-tool-versions -E release-prepare exec -- cargo install --locked --version "$VERSION" wasm-bindgen-cli node packages/permissions/scripts/generate.mjs # Dry-run build jobs start from the untagged commit, so carry the exact @@ -495,7 +515,22 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} - - uses: dtolnay/rust-toolchain@nightly + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: rust + cache: false - name: Configure git credentials run: git config --global url."https://x-access-token:${{ secrets.REPO_ACCESS_TOKEN }}@github.com/".insteadOf "https://github.com/" @@ -691,18 +726,43 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} - - uses: pnpm/action-setup@v6 + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false - - uses: actions/setup-node@v7 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" + + - name: Cache pnpm dependencies and configure npm registry + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm registry-url: https://registry.npmjs.org - - uses: oven-sh/setup-bun@v2 - if: ${{ inputs.stable_action == 'qualification' }} + - if: ${{ inputs.stable_action == 'qualification' }} + name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust with: - bun-version: "1.4.2" + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: bun + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" - name: Validate npm auth if: ${{ inputs.stable_action == 'publish' }} @@ -783,9 +843,27 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} - - uses: actions/setup-node@v7 + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + + - name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: node + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" + id: mise + - name: Configure npm registry + uses: actions/setup-node@v7 with: - node-version: 24 registry-url: https://registry.npmjs.org package-manager-cache: false @@ -901,16 +979,33 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - uses: actions/setup-python@v5 with: python-version: "3.10" - - uses: dtolnay/rust-toolchain@stable + - name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + MISE_ENV: stable + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: rust + cache: false - name: Build Python wheel (${{ matrix.artifact }}) uses: PyO3/maturin-action@v1 with: command: build + rust-toolchain: ${{ env.RUSTUP_TOOLCHAIN }} target: ${{ matrix.target }} manylinux: ${{ matrix.manylinux }} args: --manifest-path crates/alien-bindings-python/Cargo.toml --release --out dist --no-default-features --features all-platforms,platform-sdk @@ -1017,6 +1112,12 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - name: Apply computed version for dry run if: ${{ inputs.dry_run }} uses: actions/download-artifact@v8 @@ -1034,20 +1135,29 @@ jobs: VERSION: ${{ needs.prepare.outputs.version }} run: node packages/ai-gateway/scripts/validate-release-version.mjs "$VERSION" - # Rust toolchain: Linux via the shared composite; macOS uses dtolnay + + # Rust toolchain: Linux via the shared composite; macOS uses mise + # brew protoc directly (plain `napi build`, not `depot cargo`, so no # Depot/sccache setup here). The addon depends on alien-bindings, whose # build.rs needs protoc. - name: Setup Rust (linux) if: matrix.os == 'linux' - uses: ./.github/actions/setup-rust + uses: ./.ci-tool-versions/.github/actions/setup-rust with: depot-project-id: ${{ vars.DEPOT_PROJECT_ID }} repo-access-token: ${{ secrets.REPO_ACCESS_TOKEN }} install-protoc: "true" - - uses: dtolnay/rust-toolchain@nightly - if: matrix.os == 'macos' + - if: matrix.os == 'macos' + name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: rust + cache: false - name: Configure git credentials for cargo (macos) if: matrix.os == 'macos' @@ -1061,11 +1171,22 @@ jobs: if: matrix.target == 'x86_64-apple-darwin' run: rustup target add x86_64-apple-darwin - - uses: pnpm/action-setup@v6 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm - name: Install dependencies @@ -1149,6 +1270,12 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - name: Apply computed version for dry run if: ${{ inputs.dry_run }} uses: actions/download-artifact@v8 @@ -1166,17 +1293,36 @@ jobs: VERSION: ${{ needs.prepare.outputs.version }} run: node packages/ai-gateway/scripts/validate-release-version.mjs "$VERSION" - - uses: pnpm/action-setup@v6 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm - - uses: oven-sh/setup-bun@v2 - if: matrix.execute + - if: matrix.execute + name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust with: - bun-version: "1.4.2" + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: bun + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" - name: Install JavaScript dependencies run: pnpm install --frozen-lockfile @@ -1212,6 +1358,12 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - name: Apply computed version for dry run if: ${{ inputs.dry_run }} uses: actions/download-artifact@v8 @@ -1229,11 +1381,22 @@ jobs: VERSION: ${{ needs.prepare.outputs.version }} run: node packages/ai-gateway/scripts/validate-release-version.mjs "$VERSION" - - uses: pnpm/action-setup@v6 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies and configure npm registry + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm registry-url: https://registry.npmjs.org @@ -1291,9 +1454,25 @@ jobs: runs-on: depot-ubuntu-24.04-arm timeout-minutes: 15 steps: - - uses: actions/setup-node@v7 + - uses: actions/checkout@v7 + with: + path: .ci-tool-versions + persist-credentials: false + - name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: node + working_directory: .ci-tool-versions + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" + id: mise + - name: Configure npm registry + uses: actions/setup-node@v7 with: - node-version: 24 registry-url: https://registry.npmjs.org - name: Validate npm auth @@ -1352,6 +1531,12 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - name: Apply computed version for dry run if: ${{ inputs.dry_run }} uses: actions/download-artifact@v8 @@ -1364,11 +1549,22 @@ jobs: VERSION: ${{ needs.prepare.outputs.version }} run: node packages/ai-gateway/scripts/validate-release-version.mjs "$VERSION" - - uses: pnpm/action-setup@v6 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" - - uses: actions/setup-node@v7 + - name: Cache pnpm dependencies and configure npm registry + uses: actions/setup-node@v7 with: - node-version: 24 cache: pnpm registry-url: https://registry.npmjs.org @@ -1440,9 +1636,25 @@ jobs: runs-on: depot-ubuntu-24.04-arm timeout-minutes: 15 steps: - - uses: actions/setup-node@v7 + - uses: actions/checkout@v7 + with: + path: .ci-tool-versions + persist-credentials: false + - name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + install_args: node + working_directory: .ci-tool-versions + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" + id: mise + - name: Configure npm registry + uses: actions/setup-node@v7 with: - node-version: 24 registry-url: https://registry.npmjs.org - name: Validate npm auth @@ -1505,6 +1717,12 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - uses: actions/checkout@v7 with: repository: alienplatform/platform @@ -1528,9 +1746,9 @@ jobs: target/x86_64-unknown-linux-musl/release/alien-sandbox-agent platform/crates/alien-clix/target/x86_64-unknown-linux-musl/release/alien # Bump the -bN suffix whenever the set of cached binaries changes. - key: release-linux-x86_64-v${{ needs.prepare.outputs.version }}-${{ needs.prepare.outputs.source_ref }}-clix-${{ needs.prepare.outputs.platform_ref }}-b1 + key: release-linux-x86_64-v${{ needs.prepare.outputs.version }}-${{ needs.prepare.outputs.source_ref }}-clix-${{ needs.prepare.outputs.platform_ref }}-b1-${{ hashFiles('.ci-tool-versions/rust-toolchain.toml', '.ci-tool-versions/mise*.toml') }} - - uses: ./.github/actions/setup-rust + - uses: ./.ci-tool-versions/.github/actions/setup-rust if: steps.binary-cache.outputs.cache-hit != 'true' with: depot-project-id: ${{ vars.DEPOT_PROJECT_ID }} @@ -1578,6 +1796,12 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - uses: actions/checkout@v7 with: repository: alienplatform/platform @@ -1601,9 +1825,9 @@ jobs: target/aarch64-unknown-linux-musl/release/alien-sandbox-agent platform/crates/alien-clix/target/aarch64-unknown-linux-musl/release/alien # Bump the -bN suffix whenever the set of cached binaries changes. - key: release-linux-aarch64-v${{ needs.prepare.outputs.version }}-${{ needs.prepare.outputs.source_ref }}-clix-${{ needs.prepare.outputs.platform_ref }}-b1 + key: release-linux-aarch64-v${{ needs.prepare.outputs.version }}-${{ needs.prepare.outputs.source_ref }}-clix-${{ needs.prepare.outputs.platform_ref }}-b1-${{ hashFiles('.ci-tool-versions/rust-toolchain.toml', '.ci-tool-versions/mise*.toml') }} - - uses: ./.github/actions/setup-rust + - uses: ./.ci-tool-versions/.github/actions/setup-rust if: steps.binary-cache.outputs.cache-hit != 'true' with: depot-project-id: ${{ vars.DEPOT_PROJECT_ID }} @@ -1653,6 +1877,12 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - uses: actions/checkout@v7 with: repository: alienplatform/platform @@ -1672,10 +1902,19 @@ jobs: target/aarch64-apple-darwin/release/alien-deploy target/aarch64-apple-darwin/release/alien-operator platform/crates/alien-clix/target/aarch64-apple-darwin/release/alien - key: release-darwin-aarch64-v${{ needs.prepare.outputs.version }}-${{ needs.prepare.outputs.source_ref }}-clix-${{ needs.prepare.outputs.platform_ref }}-b1 + key: release-darwin-aarch64-v${{ needs.prepare.outputs.version }}-${{ needs.prepare.outputs.source_ref }}-clix-${{ needs.prepare.outputs.platform_ref }}-b1-${{ hashFiles('.ci-tool-versions/rust-toolchain.toml', '.ci-tool-versions/mise*.toml') }} - - uses: dtolnay/rust-toolchain@nightly - if: steps.binary-cache.outputs.cache-hit != 'true' + - if: steps.binary-cache.outputs.cache-hit != 'true' + name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: rust + cache: false - name: Configure git credentials for cargo if: steps.binary-cache.outputs.cache-hit != 'true' @@ -1739,6 +1978,12 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + - uses: actions/checkout@v7 with: repository: alienplatform/platform @@ -1758,10 +2003,19 @@ jobs: target/x86_64-pc-windows-msvc/release/alien-deploy.exe target/x86_64-pc-windows-msvc/release/alien-operator.exe platform/crates/alien-clix/target/x86_64-pc-windows-msvc/release/alien.exe - key: release-windows-x86_64-v${{ needs.prepare.outputs.version }}-${{ needs.prepare.outputs.source_ref }}-clix-${{ needs.prepare.outputs.platform_ref }}-b1 + key: release-windows-x86_64-v${{ needs.prepare.outputs.version }}-${{ needs.prepare.outputs.source_ref }}-clix-${{ needs.prepare.outputs.platform_ref }}-b1-${{ hashFiles('.ci-tool-versions/rust-toolchain.toml', '.ci-tool-versions/mise*.toml') }} - - uses: dtolnay/rust-toolchain@nightly - if: steps.binary-cache.outputs.cache-hit != 'true' + - if: steps.binary-cache.outputs.cache-hit != 'true' + name: Install Rust toolchain + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: rust + cache: false - name: Configure git credentials for cargo if: steps.binary-cache.outputs.cache-hit != 'true' @@ -2693,9 +2947,27 @@ jobs: with: ref: ${{ needs.prepare.outputs.source_ref }} - - uses: actions/setup-node@v7 + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + + - name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: node + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" + id: mise + - name: Configure npm registry + uses: actions/setup-node@v7 with: - node-version: 24 registry-url: https://registry.npmjs.org package-manager-cache: false @@ -2731,9 +3003,27 @@ jobs: with: ref: ${{ needs.prepare.outputs.release_commit }} - - uses: actions/setup-node@v7 + - uses: actions/checkout@v7 + with: + ref: ${{ github.ref }} + path: .ci-tool-versions + persist-credentials: false + + - name: Install development tools + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust + with: + version: 2026.10.1 + add_shims_to_path: false + working_directory: .ci-tool-versions + install_args: node + cache_key: "{{default}}-${{ hashFiles('.ci-tool-versions/package.json') }}" + id: mise + - name: Configure npm registry + uses: actions/setup-node@v7 with: - node-version: 24 registry-url: https://registry.npmjs.org package-manager-cache: false diff --git a/.github/workflows/repair-renovate-lockfiles.yml b/.github/workflows/repair-renovate-lockfiles.yml index cdcda8349..de39eb5bc 100644 --- a/.github/workflows/repair-renovate-lockfiles.yml +++ b/.github/workflows/repair-renovate-lockfiles.yml @@ -24,11 +24,17 @@ jobs: token: ${{ secrets.REPO_ACCESS_TOKEN }} persist-credentials: false - - uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6 - - - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 + - name: Install development tools + id: mise + uses: jdx/mise-action@v5 + env: + MISE_DATA_DIR: ${{ runner.temp }}/mise-tools + MISE_DISABLE_TOOLS: rust with: - node-version: 24 + version: 2026.10.1 + add_shims_to_path: false + install_args: node pnpm + cache_key: "{{default}}-${{ hashFiles('package.json') }}" - name: Regenerate pnpm lockfiles run: | diff --git a/mise.release-prepare.toml b/mise.release-prepare.toml new file mode 100644 index 000000000..b12a9b12c --- /dev/null +++ b/mise.release-prepare.toml @@ -0,0 +1,4 @@ +# Established compiler for release permission artifacts. +# Select locally with: mise -E release-prepare exec -- cargo +[tools] +rust = { version = "1.97.1", profile = "minimal", targets = ["wasm32-unknown-unknown"] } diff --git a/mise.stable.toml b/mise.stable.toml new file mode 100644 index 000000000..c676062b9 --- /dev/null +++ b/mise.stable.toml @@ -0,0 +1,4 @@ +# Stable compiler for Python wheel builds. +# Select locally with: mise -E stable exec -- cargo +[tools] +rust = { version = "1.99.0", profile = "minimal", components = "rustfmt,clippy" } diff --git a/mise.toml b/mise.toml new file mode 100644 index 000000000..6d529773f --- /dev/null +++ b/mise.toml @@ -0,0 +1,10 @@ +min_version = "2026.10.1" + +[settings] +# Versions are exact; do not generate local lockfiles from inherited settings. +lockfile = false +idiomatic_version_file_enable_tools = ["pnpm", "rust"] + +[tools] +node = "24.21.0" +bun = "1.4.2" diff --git a/rust-toolchain.toml b/rust-toolchain.toml new file mode 100644 index 000000000..148d39e62 --- /dev/null +++ b/rust-toolchain.toml @@ -0,0 +1,4 @@ +[toolchain] +channel = "nightly-2026-10-03" +profile = "minimal" +components = ["rustfmt", "clippy"]