ci.yml runs on `push: ["**"]`, so a Renovate branch is already compiled,
linted with `clippy -D warnings` and unit-tested before anything reaches
main; a red branch makes Renovate open a pull request instead of merging.
That gate now covers the Dockerfile base too, via the build job added in
the previous commit.
Cargo, the Rust toolchain, prek and the workflows' own actions therefore
merge by branch push. The local development images under etc/services/**
do too, on a different justification recorded in the rule itself: CI does
not run them and they reach no shipped artifact, so the worst case is a
broken `just services-start`.
Majors keep their pull request - the rule is deliberately last, so it
overrides the others for every manager.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The prek job never builds an image, so a bump of the Dockerfile's base
image reached main unvalidated and only failed afterwards in Publish -
by which point ghcr.io/etkecc/baibot:latest had already been attempted.
Add a gate job that looks for Dockerfile changes against main, and a
build job that builds the image the way Publish does but with
`push: false`. The build is gated rather than unconditional because it
is a full Rust release build: running it on every push would turn a
~1 minute pipeline into a ~10 minute one for changes that cannot affect
the image. It is skipped on main, where Publish already builds.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Since mise 2026.6.4 (advisory GHSA-436v-8fw5-4mj8), trust-control settings
(`yes`, `ci`, `trusted_config_paths`, `paranoid`) in non-global configs are
ignored, and every mise invocation prints a warning about this one.
Removing it changes nothing on current mise - the setting was already dead.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The CONDUWUIT_ prefix still works in v26.6.1, but is a legacy
compatibility name from before the conduwuit -> continuwuity rebrand.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>