Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Keeps the committed Cargo.lock current. CI builds with --locked, so without
# these PRs the lockfile would drift behind what users resolve.
version: 2
updates:
- package-ecosystem: cargo
directory: /
schedule:
interval: weekly
# Only the lockfile moves; Cargo.toml requirements are never rewritten, so
# declared floors stay the true minimums rather than tracking the latest
# release. (For cargo, Dependabot offers only this and `auto`, which raises
# requirements on every update.) A semver-incompatible upgrade is therefore
# a deliberate, hand-written Cargo.toml change.
versioning-strategy: lockfile-only
# One PR for the week's updates.
groups:
compatible:
update-types: [minor, patch]
open-pull-requests-limit: 5
40 changes: 18 additions & 22 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ jobs:
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: cargo check --workspace --all-features --all-targets
- run: cargo check --locked --workspace --all-features --all-targets

msrv-check:
name: MSRV
Expand All @@ -59,7 +59,7 @@ jobs:
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: cargo check --workspace --all-features --all-targets
- run: cargo check --locked --workspace --all-features --all-targets

test:
name: Test
Expand All @@ -73,7 +73,7 @@ jobs:
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: cargo test --workspace --all-features
- run: cargo test --locked --workspace --all-features

clippy:
name: Clippy
Expand All @@ -91,12 +91,12 @@ jobs:
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: cargo clippy --workspace --all-features --all-targets -- -D warnings
- run: cargo clippy --locked --workspace --all-features --all-targets -- -D warnings
# `serve_connection` and `ConnectionConfig` are public without TLS;
# lint that feature shape too, not just the union.
- run: cargo clippy -p connectrpc --no-default-features --features server --all-targets -- -D warnings
- run: cargo clippy --locked -p connectrpc --no-default-features --features server --all-targets -- -D warnings
# ...and the axum adapter without `server-tls`.
- run: cargo clippy -p connectrpc --no-default-features --features axum,server --all-targets -- -D warnings
- run: cargo clippy --locked -p connectrpc --no-default-features --features axum,server --all-targets -- -D warnings

fmt:
name: Format
Expand Down Expand Up @@ -150,12 +150,10 @@ jobs:
name: Check generated code
runs-on: ubuntu-latest
timeout-minutes: 15
# Note: the workspace has no committed Cargo.lock, so `cargo
# generate-lockfile` below resolves buffa and prettyplease (which formats
# the generated code) to the latest compatible releases at run time. A new
# release of either can therefore make this job fail on PRs that did not
# touch the protos or codegen — the fix is to run `task generate:all` on
# main and commit the resulting diff.
# The buffa plugins are built from the release tag matching the version in
# the committed Cargo.lock, so this job only changes behaviour when a PR
# bumps the lockfile — and such a PR must carry the regenerated code
# (`task generate:all`) with it.
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
Expand All @@ -172,8 +170,6 @@ jobs:
# regeneration when bumping.
version: 1.69.0
- uses: go-task/setup-task@01a4adf9db2d14c1de7a560f09170b6e0df736aa # v2 (sha-pinned)
- name: Generate lockfile
run: cargo generate-lockfile
- name: Resolve locked buffa version
id: buffa-version
shell: bash
Expand Down Expand Up @@ -230,7 +226,7 @@ jobs:
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: cargo doc --workspace --all-features --no-deps
- run: cargo doc --locked --workspace --all-features --no-deps

# Integration test: start server, run client, verify RPCs work end-to-end
examples:
Expand Down Expand Up @@ -269,7 +265,7 @@ jobs:
- name: Download conformance runner
run: ./conformance/scripts/download-conformance.sh
- name: Build conformance binary
run: cargo build --release -p connectrpc-conformance --bin ${{ matrix.bin }}
run: cargo build --locked --release -p connectrpc-conformance --bin ${{ matrix.bin }}
- name: Run conformance suite
run: |
./conformance/bin/connectconformance --mode ${{ matrix.mode }} \
Expand All @@ -291,8 +287,8 @@ jobs:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: curl https://rustwasm.github.io/wasm-pack/installer/init.sh -sSf | sh
- run: cargo check -p connectrpc --no-default-features --target wasm32-unknown-unknown
- run: cargo check -p connectrpc --no-default-features --features gzip --target wasm32-unknown-unknown
- run: cargo check --locked -p connectrpc --no-default-features --target wasm32-unknown-unknown
- run: cargo check --locked -p connectrpc --no-default-features --features gzip --target wasm32-unknown-unknown
- run: ./examples/wasm-client/test.sh

# Test with minimal feature set
Expand All @@ -304,7 +300,7 @@ jobs:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 (sha-pinned)
- run: cargo check -p connectrpc --no-default-features
- run: cargo test -p connectrpc --no-default-features
- run: cargo check -p connectrpc --no-default-features --features server
- run: cargo check -p connectrpc --no-default-features --features axum,server
- run: cargo check --locked -p connectrpc --no-default-features
- run: cargo test --locked -p connectrpc --no-default-features
- run: cargo check --locked -p connectrpc --no-default-features --features server
- run: cargo check --locked -p connectrpc --no-default-features --features axum,server
36 changes: 36 additions & 0 deletions .github/workflows/latest-deps.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
name: Latest dependencies

# CI builds against the committed Cargo.lock, so a new upstream release that
# breaks the build or the tests does not show up on ordinary PRs. This job is
# where it shows up: once a week (and on demand) it resolves every
# dependency to the newest compatible version and runs the test suite, which is
# what a downstream crate depending on connectrpc gets.
on:
schedule:
- cron: "23 6 * * 1"
workflow_dispatch:

permissions:
contents: read

env:
CARGO_TERM_COLOR: always
RUSTFLAGS: -Dwarnings
PROTOC_VERSION: "33.5"

jobs:
latest:
name: Test against latest compatible dependencies
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
- uses: arduino/setup-protoc@c65c819552d16ad3c9b72d9dfd5ba5237b9c906b # v3.0.0 (sha-pinned)
with:
version: ${{ env.PROTOC_VERSION }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
- name: Resolve newest compatible versions
run: cargo update --verbose
- run: cargo test --workspace --all-features
- run: cargo test -p connectrpc --no-default-features
1 change: 0 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
/target
Cargo.lock
/conformance/bin/

# User-local Claude Code settings (project-level agents/commands ARE committed)
Expand Down
32 changes: 30 additions & 2 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -164,6 +164,31 @@ task buffa:unlink # removes the override; reverts to crates.io / [patch]

The override is gitignored and never reaches CI or `cargo publish`.

## Cargo.lock

The workspace `Cargo.lock` is committed and CI builds with `--locked` (the
example scripts and `task generate:all` add it when `CI` is set), so a new
release of a dependency never changes what CI builds
until a PR bumps the lockfile. Dependabot opens that PR weekly for
semver-compatible updates (lockfile only; a semver-incompatible upgrade is a
hand-written `Cargo.toml` change), and the scheduled *Latest dependencies* workflow
runs the test suite against a fresh `cargo update`, which is what a crate
depending on `connectrpc` resolves, so a release that breaks downstream users
is noticed there. The lockfile only governs this
repository's own builds; crates that depend on `connectrpc` resolve against
the version requirements in `Cargo.toml` as usual, so keep those floors
truthful.

To bump one dependency: `cargo update -p <crate>` and commit the lockfile
change. A buffa bump is `cargo update -p buffa -p buffa-types -p
buffa-codegen -p buffa-descriptor` followed by `task generate:all`, in the
same PR, because the generated-code check builds the buffa plugins from the
tag matching the locked version; the locked version is the regen baseline,
and the `buffa` requirements in `Cargo.toml` only move when the new code
needs something the old floor lacks. `task buffa:link` rewrites the lockfile
to path dependencies; run `task buffa:unlink` and `git restore Cargo.lock`
before committing.

## Continuous Integration

GitHub Actions CI (`.github/workflows/ci.yml`) runs on every push to
Expand All @@ -180,8 +205,9 @@ GitHub Actions CI (`.github/workflows/ci.yml`) runs on every push to
across releases. Use the same dated nightly locally
(`rustup toolchain install nightly-2026-02-27 -c rustfmt`); bump it
together with the `fmt` job in `.github/workflows/ci.yml`
- **Check generated code** — runs `task generate:all` and verifies the
checked-in generated directories have no diff
- **Check generated code** — builds the buffa plugins at the version in
`Cargo.lock`, runs `task generate:all`, and verifies the checked-in
generated directories have no diff
- **Documentation** — `cargo doc` with broken-intra-doc-links denied
- **MSRV** — `cargo check` on the minimum toolchain, read from `rust-version`
in the workspace `Cargo.toml` so the declaration and the check cannot drift
Expand All @@ -192,4 +218,6 @@ GitHub Actions CI (`.github/workflows/ci.yml`) runs on every push to
`#[cfg(feature = "...")]`-gated or it fails here while passing the
default-feature suite
- **Wasm** — `wasm32-unknown-unknown` build of the client example
- **Latest dependencies** (weekly, separate workflow) — `cargo update` to
the newest compatible versions, then the test suite
- **Conformance (server)** / **Conformance (client)** — full suites
Loading
Loading