From a0d029fb850720ca4a5e6680e8204ed3d2df0c5a Mon Sep 17 00:00:00 2001 From: Ricardo Costa Date: Sun, 4 Oct 2026 15:16:13 +0100 Subject: [PATCH] Track playground LiquidJava upgrades with Dependabot Co-authored-by: Codex --- .github/dependabot.yml | 9 +++++++++ .github/workflows/pages.yml | 18 +++++++++++------- README.md | 4 +++- scripts/playground/build.py | 28 +++++++++++++++++++--------- scripts/playground/pom.xml | 35 +++++++++++++++++++++++++++++++++++ 5 files changed, 77 insertions(+), 17 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 scripts/playground/pom.xml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..80bced3 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,9 @@ +version: 2 +updates: + - package-ecosystem: maven + directory: /scripts/playground + schedule: + interval: daily + allow: + - dependency-name: io.github.liquid-java:liquidjava-verifier + - dependency-name: io.github.liquid-java:liquidjava-api diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index c72862e..85d1964 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,18 +1,17 @@ -name: Deploy Jekyll site to Pages +name: Build and deploy Jekyll site on: push: branches: - main + pull_request: workflow_dispatch: permissions: contents: read - pages: write - id-token: write concurrency: - group: "pages" + group: pages-${{ github.event.pull_request.number || 'deploy' }} cancel-in-progress: true jobs: @@ -46,24 +45,29 @@ jobs: npm run build:playground npm run test:playground - - name: Setup Pages - uses: actions/configure-pages@v5 - - name: Build site run: bundle exec jekyll build - name: Upload artifact + if: github.event_name != 'pull_request' uses: actions/upload-pages-artifact@v3 with: path: ./_site deploy: + if: github.event_name != 'pull_request' + permissions: + pages: write + id-token: write environment: name: github-pages url: ${{ steps.deployment.outputs.page_url }} runs-on: ubuntu-latest needs: build steps: + - name: Setup Pages + uses: actions/configure-pages@v5 + - name: Deploy to GitHub Pages id: deployment uses: actions/deploy-pages@v4 diff --git a/README.md b/README.md index 68cdb70..d9b3f1d 100644 --- a/README.md +++ b/README.md @@ -46,7 +46,9 @@ npm run test:playground bundle exec jekyll build ``` -The build requires JDK 17, Python 3, Node.js, and access to Maven Central. It recompiles the published verifier 0.0.35 and annotation API 0.0.7 sources for Java 17 without changing them, packages their dependencies, and adds the docs-owned runner and Z3 loader. The standard-library classpath comes from the build JDK's `java.base.jmod`. Generated runtime files are ignored by Git and included in the Pages artifact. The normal Pages workflow builds everything automatically. +The build requires JDK 17, Python 3, Node.js, and access to Maven Central. It recompiles the published verifier and annotation API sources for Java 17 without changing them, packages their dependencies, and adds the docs-owned runner and Z3 loader. `scripts/playground/pom.xml` is the single source of truth for the Maven artifact versions; the Python build reads it directly, without requiring Maven. The verifier binary and sources always use the same version. The standard-library classpath comes from the build JDK's `java.base.jmod`. Generated runtime files are ignored by Git and included in the Pages artifact. + +After the configuration is merged into `main`, Dependabot checks the manifest daily and opens update PRs for the LiquidJava verifier and annotation API. Every pull request builds the playground, runs its tests, and builds Jekyll. Review upgrades with browser verification before merging, including successful and failing refinements and typestate transitions. Pages deployment runs only after a push to `main` or a manual workflow run. The browser package also adapts Spoon 10.4.2's query initialization: when CheerpJ supplies an empty cast-exception stack trace, it selects Spoon's existing exotic-JVM query mode. The pinned source is downloaded and the adaptation checked during the build. This change is limited to the docs' generated dependency; the verifier repository and published sources remain unchanged. diff --git a/scripts/playground/build.py b/scripts/playground/build.py index d4ea394..c0fcf64 100644 --- a/scripts/playground/build.py +++ b/scripts/playground/build.py @@ -4,16 +4,25 @@ import subprocess import shutil import urllib.request +import xml.etree.ElementTree as ET import zipfile from pathlib import Path ROOT = Path(__file__).resolve().parents[2] WORK = ROOT / '.playground-build' OUTPUT = ROOT / 'playground/runtime' -VERIFIER = '0.0.35' -API = '0.0.7' -Z3 = '4.8.17' -SPOON = '10.4.2' + + +def dependency_artifacts(): + namespace = {'m': 'http://maven.apache.org/POM/4.0.0'} + pom = ET.parse(ROOT / 'scripts/playground/pom.xml') + return { + dependency.findtext('m:artifactId', namespaces=namespace): tuple( + dependency.findtext(f'm:{field}', namespaces=namespace) + for field in ['groupId', 'artifactId', 'version'] + ) + for dependency in pom.findall('m:dependencies/m:dependency', namespace) + } def artifact(group, name, version, classifier=''): @@ -33,11 +42,12 @@ def main(): raise RuntimeError('Build the playground with JDK 17 (set JAVA_HOME and PATH)') WORK.mkdir(exist_ok=True) OUTPUT.mkdir(parents=True, exist_ok=True) - verifier = artifact('io.github.liquid-java', 'liquidjava-verifier', VERIFIER) - sources = artifact('io.github.liquid-java', 'liquidjava-verifier', VERIFIER, '-sources') - annotations = artifact('io.github.liquid-java', 'liquidjava-api', API, '-sources') - z3_sources = artifact('tools.aqua', 'z3-turnkey', Z3, '-sources') - spoon_sources = artifact('fr.inria.gforge.spoon', 'spoon-core', SPOON, '-sources') + dependencies = dependency_artifacts() + verifier = artifact(*dependencies['liquidjava-verifier']) + sources = artifact(*dependencies['liquidjava-verifier'], '-sources') + annotations = artifact(*dependencies['liquidjava-api'], '-sources') + z3_sources = artifact(*dependencies['z3-turnkey'], '-sources') + spoon_sources = artifact(*dependencies['spoon-core'], '-sources') source_dir = WORK / 'sources' if source_dir.exists(): shutil.rmtree(source_dir) diff --git a/scripts/playground/pom.xml b/scripts/playground/pom.xml new file mode 100644 index 0000000..12a1844 --- /dev/null +++ b/scripts/playground/pom.xml @@ -0,0 +1,35 @@ + + + 4.0.0 + io.github.liquid-java + liquidjava-browser-playground + 1.0.0 + pom + + + io.github.liquid-java + liquidjava-verifier + 0.0.35 + + + io.github.liquid-java + liquidjava-api + 0.0.7 + sources + + + tools.aqua + z3-turnkey + 4.8.17 + sources + + + fr.inria.gforge.spoon + spoon-core + 10.4.2 + sources + + +