Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
33 commits
Select commit Hold shift + click to select a range
8e58053
compass-ui: ViciScrollBar's thin rounded scrollbar for every scrollable
claude Sep 25, 2026
9226136
Markdown views: draw in the launcher's font, not iced's generic sans
claude Sep 25, 2026
b0b51ad
Publish the Flatpak to the TunaOS remote, with store screenshots
claude Sep 25, 2026
cfeafb5
Merge the pre-squash history of this branch (#231 is already on main)
claude Sep 25, 2026
dfb512a
Window material: an unsafe bridge to the launcher's surface, and blur…
claude Sep 25, 2026
c4a50bc
README: why Compass over Vicinae, backed by a head-to-head benchmark
claude Sep 25, 2026
409cb3a
Merge the pre-squash history of this branch (#232 is already on main)
claude Sep 25, 2026
ea33c33
Raycast extensions on Linux: a runtime shim, a consent-gated host-com…
claude Sep 25, 2026
7cfbfb7
README: extensions ask before running host programs; the macOS shim
claude Sep 25, 2026
b934423
compass-ui: clickable root rows and a transparent window around the card
claude Sep 25, 2026
248ed9b
engine: rename the vicinae crate and identifiers to Compass (Phase 7)
claude Sep 25, 2026
c80759f
Cargo.toml: the config file and file-walk policy by their new names
claude Sep 25, 2026
73cc270
packaging: rebrand to org.tunaos.compass (Phase 7 cutover)
claude Sep 25, 2026
2112e6f
Docs: rename to Compass, org.tunaos.compass and ~/.config/compass (AD…
claude Sep 25, 2026
8c13632
Onboarding: the Compass logo on the welcome step
claude Sep 25, 2026
bcf1907
compass-ui: the click test names compass_pages after the rename
claude Sep 25, 2026
360c642
Merge the pre-squash history of this branch (#233 is already on main)
claude Sep 25, 2026
7233b39
Suite 1: a command waiting on host-command consent is needs-consent
claude Sep 25, 2026
bff38cd
Remove the C++ engine; upstream Vicinae releases are the reference (A…
claude Sep 25, 2026
b8dd2ed
Clean up what the C++ engine's removal left stale
claude Sep 25, 2026
4a56f01
Merge the pre-squash history of this branch (#234 is already on main)
claude Sep 25, 2026
1121bc7
nix: install the extension runtime under share/compass
claude Sep 25, 2026
e5ffed5
Merge the pre-squash history of this branch (#235 is already on main)
claude Oct 1, 2026
e356488
Add cargo-deny for advisories, licences, bans and sources (#244)
claude Oct 1, 2026
71e600c
Pin third-party actions to commit SHAs (#245, #247)
claude Oct 1, 2026
d905fb6
Build and publish the Flatpak for aarch64 as well (#246)
claude Oct 1, 2026
0d1c094
Fit the card's shadow inside the window (#251)
claude Oct 1, 2026
4fa49ee
Give the Settings page Adwaita-style controls (#252)
claude Oct 1, 2026
5cd9a5e
Add a Compass getting-started guide and point user-facing links at it
claude Oct 1, 2026
a454ab7
Onboarding: Compass hotkey docs, an extensions step, button tests (#2…
claude Oct 1, 2026
b11954b
Open Config File opens compass.json, and every item is audited (#253,…
claude Oct 1, 2026
1c1a86f
Settings audit: a fresh simulator per grid line on the first pass
claude Oct 1, 2026
66510a4
bench: repin the head-to-head image to fedora:44's current digest
claude Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/actions/vm-host/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -84,7 +84,7 @@ runs:
# "stability is not yet established".
sudo df -h /var/lib/containers/storage | tail -1

- uses: actions/setup-go@v5
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: '1.26'

Expand Down
20 changes: 20 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# Keeps the SHA-pinned actions current. Every third-party `uses:` is pinned to a
# commit with its version in a trailing comment; Dependabot moves both together.
#
# Cargo is deliberately not here: every Cargo.lock change has to regenerate
# packaging/flatpak/cargo-sources.json (flatpak.yaml checks it), which
# Dependabot cannot do. tuna-os/.github stays on @main by design, and
# Dependabot leaves branch refs alone.
version: 2
updates:
- package-ecosystem: github-actions
directories:
- /
- /.github/actions/*
schedule:
interval: weekly
groups:
actions:
patterns: ["*"]
commit-message:
prefix: ci
4 changes: 2 additions & 2 deletions .github/workflows/api-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,12 +27,12 @@ jobs:
run:
working-directory: ./src/typescript/api
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
ref: ${{ inputs.tag }}

- name: Setup Node.js
uses: actions/setup-node@v4
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: 24
registry-url: https://registry.npmjs.org
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/cachix.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -42,14 +42,14 @@ jobs:
matrix:
os: [ubuntu-24.04, ubuntu-24.04-arm]
steps:
- uses: actions/checkout@v4
- uses: cachix/install-nix-action@v31
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
- name: Cache Nix Evaluation
uses: actions/cache@v4
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.cache/nix
key: nix-eval-${{ hashFiles('flake.lock') }}
- uses: cachix/cachix-action@v14
- uses: cachix/cachix-action@18cf96c7c98e048e10a83abd92116114cd8504be # v14
with:
name: vicinae
authToken: ${{ github.ref == 'refs/heads/main' && secrets.CACHIX_AUTH_TOKEN || '' }}
Expand Down
49 changes: 49 additions & 0 deletions .github/workflows/cargo-deny.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
# cargo-deny against deny.toml: RustSec advisories, licences, duplicate
# versions and where crates may come from.
#
# Advisories are a separate leg because they change without any change here:
# a crate published years ago can gain an advisory tonight. On a pull request
# that leg reports without blocking, so an unrelated change is not held up by
# news about a dependency it did not touch; on main and on the daily schedule it
# fails, which is where somebody has to act on it. The other checks only change
# when Cargo.lock or deny.toml does, so they always gate.
name: cargo-deny

on:
push:
branches: [main]
paths: &paths
- Cargo.lock
- "**/Cargo.toml"
- deny.toml
- .github/workflows/cargo-deny.yaml
pull_request:
paths: *paths
schedule:
- cron: "17 6 * * *"
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
deny:
name: cargo-deny (${{ matrix.checks }})
runs-on: ubuntu-24.04
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
checks:
- advisories
- bans licenses sources
continue-on-error: ${{ matrix.checks == 'advisories' && github.event_name == 'pull_request' }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1
with:
command: check ${{ matrix.checks }}
4 changes: 2 additions & 2 deletions .github/workflows/corpus-harvest.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ jobs:
runs-on: ubuntu-24.04
timeout-minutes: 45
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

# Ordered cheap-first, deliberately. The unknown here is whether the
# repoquery below names packages at all; if the syntax is wrong this step
Expand Down Expand Up @@ -125,7 +125,7 @@ jobs:
echo "harvested $(find harvested -name "*.desktop" | wc -l) entries"

- name: Publish for review
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: desktop-corpus
path: harvested
Expand Down
56 changes: 44 additions & 12 deletions .github/workflows/flatpak.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,14 @@ on:
# The VM tier calls this workflow so that "how the Flatpak is built" has one
# definition. The bundle it uploads is what gets layered into the test image.
workflow_call:
inputs:
archs:
description: >-
JSON array of the architectures to build. The callers (VM tier,
Suite 1, tier 2) test on x86_64 runners only, so they need only that
bundle and do not wait for an aarch64 build.
type: string
default: '["x86_64"]'

# The literal prefix matters. `github.workflow` in a *called* workflow is the
# CALLER's name, so without it this group would be identical to the VM tier's
Expand Down Expand Up @@ -54,7 +62,7 @@ jobs:
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Regenerate and compare
run: |
Expand All @@ -66,13 +74,30 @@ jobs:
fi
echo "cargo-sources.json matches Cargo.lock"

# One leg per architecture, each on a native runner (#246). No QEMU: the
# build is a full release compile, and every step after it -- doctor, Suite
# 5, Spike B -- runs the binary, so each architecture is tested on its own
# hardware with the same steps. Pushes, pull requests and manual runs build
# both, so publish-flatpak.yaml always finds both bundles; a caller through
# workflow_call gets the `archs` it asks for, x86_64 by default.
#
# x86_64 keeps the artifact names it always had (flatpak-bundle and so on),
# which the VM tier, Suite 1 and tier 2 download by name; other
# architectures add `-<arch>`.
build:
runs-on: ubuntu-24.04
name: build (${{ matrix.arch }})
runs-on: ${{ matrix.arch == 'aarch64' && 'ubuntu-24.04-arm' || 'ubuntu-24.04' }}
# The freedesktop SDK plus the Rust extension is a large download and the build
# is a full release compile of the workspace. Generous, but bounded.
timeout-minutes: 90
strategy:
fail-fast: false
matrix:
arch: ${{ fromJSON(inputs.archs || '["x86_64", "aarch64"]') }}
env:
ARTIFACT_SUFFIX: ${{ matrix.arch != 'x86_64' && format('-{0}', matrix.arch) || '' }}
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Install flatpak and flatpak-builder
run: |
Expand All @@ -94,11 +119,11 @@ jobs:
# See --reinstall and the commit assertion below, which are what make the
# cache safe to keep.
- name: Cache the runtime
uses: actions/cache@v4
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.local/share/flatpak
key: flatpak-runtime-${{ runner.os }}-${{ hashFiles('packaging/flatpak/org.tunaos.compass.yaml') }}
restore-keys: flatpak-runtime-${{ runner.os }}-
key: flatpak-runtime-${{ runner.os }}-${{ matrix.arch }}-${{ hashFiles('packaging/flatpak/org.tunaos.compass.yaml') }}
restore-keys: flatpak-runtime-${{ runner.os }}-${{ matrix.arch }}-

- name: Install the runtime and SDK
run: |
Expand All @@ -125,6 +150,13 @@ jobs:
flatpak run --user --command=sh --devel org.freedesktop.Sdk//26.08 \
-c 'PATH=/usr/lib/sdk/rust-stable/bin:$PATH rustc --version' || echo "could not query"

# The bundle is JavaScript, the same on every architecture, but npm runs
# on the runner, and the arm64 image need not carry the Node the x86_64
# one does. 22 is the major the manifest ships (node22).
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: 22

# The manifest installs this from the source tree, because the offline
# build cannot run npm. Same script as the Rust workflow's
# extension-runtime job.
Expand Down Expand Up @@ -227,9 +259,9 @@ jobs:

- name: Upload the Spike B report
if: always()
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: spike-b-flatpak
name: spike-b-flatpak${{ env.ARTIFACT_SUFFIX }}
path: /tmp/spike-b.*
retention-days: 14
if-no-files-found: warn
Expand All @@ -246,18 +278,18 @@ jobs:

- name: Upload the bundle
if: always()
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: flatpak-bundle
name: flatpak-bundle${{ env.ARTIFACT_SUFFIX }}
path: /tmp/org.tunaos.compass.flatpak
retention-days: 14
if-no-files-found: error

- name: Upload the repo
if: always()
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: flatpak-repo
name: flatpak-repo${{ env.ARTIFACT_SUFFIX }}
path: /tmp/repo
retention-days: 7
if-no-files-found: warn
2 changes: 1 addition & 1 deletion .github/workflows/format.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Check TypeScript formatting
working-directory: src/typescript
Expand Down
8 changes: 5 additions & 3 deletions .github/workflows/head-to-head.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,10 @@ jobs:
runs-on: ubuntu-24.04
timeout-minutes: 60
steps:
- uses: actions/checkout@v4
- uses: taiki-e/install-action@just
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: taiki-e/install-action@83ac0ad63c0167e6f06796fab0fce28db1bf3db0 # v2.87.22
with:
tool: just
- name: Runner prerequisites
run: |
sudo apt-get update -qq
Expand All @@ -44,7 +46,7 @@ jobs:
find target/head-to-head -name summary.md -exec cat {} + >> "$GITHUB_STEP_SUMMARY"
- name: Preserve measurements and failure logs
if: always()
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: upstream-head-to-head-${{ github.sha }}
retention-days: 30
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/nix-format.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,10 +26,10 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0

- name: Install Nix
uses: cachix/install-nix-action@v25
uses: cachix/install-nix-action@6004951b182f8860210c8d6f0d808ec5b1a33d28 # v25
with:
nix_path: nixpkgs=channel:nixos-unstable
extra_nix_config: |
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/nix-support.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,11 +19,11 @@ jobs:
runs-on: ubuntu-24.04

steps:
- uses: actions/checkout@v5
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.1.0
with:
fetch-depth: 0
fetch-tags: true
- uses: cachix/install-nix-action@v31
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
- name: Check nix hashes
run: |
nix run --no-update-lock-file .#nix-update-script --extra-experimental-features nix-command flakes --accept-flake-config
Loading
Loading