Triggers on push, pull_request, and workflow_dispatch. Two independent
jobs run on GitHub-hosted ubuntu-24.04 runners, so a failure in one never
hides the other's results.
| Step | Make target | What it checks |
|---|---|---|
| Go toolchain | make toolchain-check |
Go 1.26.6 or newer |
| Version contract | make version-check |
VERSION, runtime, capability, documentation, and release metadata agree; removed SDK tree stays absent |
| Source manifest | make manifest-check |
Every tracked source file matches its generated size and SHA-256 entry |
| Format, vet, tests | make check |
gofmt -l, go vet, go test ./... (24 packages, 21 with tests) |
| Race detector | make race |
go test -race ./... — data race detection |
| Fuzz campaigns | make fuzz |
FuzzDecode, FuzzSafeName, FuzzResultParser, FuzzTranscript, FuzzEnvelope (3s each) |
| Demo smoke | make demo |
12 end-to-end CLI scenarios (no model/network) |
| Extended scenarios | make demo-extended |
16 scenarios: PTY, TUI, workflow, MCP, remote, backup |
| Cross-compile | make cross-build |
linux/amd64 (cgo), darwin/amd64 + darwin/arm64 (cgo-free) |
| Vulnerability scan | make vulncheck |
Pinned govulncheck v1.8.0 — scans for known CVEs |
The Rust workspace under crates/ is a preview gated by
docs/design/RUST_PARITY_PLAN.md; it is not part of any release.
| Step | Command | What it checks |
|---|---|---|
| Toolchain | rustup toolchain install 1.88.0 --profile minimal --component clippy --component rustfmt |
Pinned MSRV from rust-toolchain.toml |
| Build cache | Swatinem/rust-cache (SHA-pinned) |
Restores ~/.cargo and target/rust-1.88.0, keyed on Cargo.lock, rust-toolchain.toml and .cargo/config.toml; only main saves |
| Locked fetch | cargo +1.88.0 fetch --locked |
Cargo.lock is complete; later steps run --offline |
| Format | make rust-fmt-check (via rust-check) |
cargo fmt --all -- --check |
| Lint | make rust-clippy (via rust-check) |
clippy --workspace --all-targets --locked --offline -- -D warnings with the workspace's clippy::pedantic and unsafe_code = "forbid" lints |
| Tests | make rust-test (via rust-check) |
cargo test --workspace --locked --offline |
| Dependency audit | make rust-deps-check (via rust-check) |
scripts/test_*.py unit tests, then scripts/rust_dependency_audit.py --check: every locked crate's SPDX expression and byte-exact bundled notice (SHA-256) in licenses/ |
| Rust SBOM | make rust-sbom |
CycloneDX 1.7 inventory of packages active on the supported targets, uploaded as the rover-rust-sbom run artifact (30-day retention) |
All Rust steps take CARGO='cargo +1.88.0'; the audit script honours the same
CARGO value. The Rust SBOM is not attached to releases because releases ship
only the Go binaries.
Measured duration: the first cold-cache run
(run 36279833786,
2026-09-26) took 1 min 22 s for the whole rust job: clippy build 27.6 s,
test build 31.4 s, 319 tests on Linux. The go job took 2 min 40 s in the same
run. Both are far below their timeouts.
| Target | CGO | SQLite | Notes |
|---|---|---|---|
| linux/amd64 | Enabled | System libsqlite3 | Host build, full functionality |
| darwin/amd64 | Disabled (CGO_ENABLED=0) | Stub (non-functional store) | Pure-Go, compiles and links |
| darwin/arm64 | Disabled (CGO_ENABLED=0) | Stub (non-functional store) | Pure-Go, compiles and links |
| windows/amd64 | — | — | Not supported — uses syscall.O_NOFOLLOW |
Opt-in via workflow_dispatch only. Does not trigger on push or PR.
Requires manual review of all build artifacts and vulnerability scan results
before publishing.
| Input | Description | Default |
|---|---|---|
version |
Version tag (e.g. v0.0.1) |
(required) |
draft |
Create as draft release? | true |
- Checkout source
- Setup Go 1.26.6
- Validate the Go toolchain, release tag,
make version-check, andmake manifest-check - Build host binary (
make build) - Verify the local source package (
rover doctor --verify) - Build the declared target matrix (
make cross-build) - Generate SBOM (
make sbom) - Run govulncheck (
make vulncheck) - Run all checks (
make check,make race) - Compute SHA-256 checksums (
bin/checksums.txt) - Attest build provenance for every checksummed asset with
actions/attest-build-provenance(keyless Sigstore signing through the run's OIDC token; needsid-token: writeandattestations: write) - Create GitHub release with artifacts
sha256sum -c checksums.txt --ignore-missing
gh attestation verify rover-linux-amd64 --repo GrayCodeAI/roverThe attestation proves which workflow run, commit and repository built the
file. It does not prove the code is correct or secure. The existing v0.0.1
release is a source-only tag with no binary assets, so it has no attestations.
No automatic publication, merge, release, deployment, or credential upload
occurs. The release workflow requires explicit workflow_dispatch trigger.