ci: add actionlint and a test-environment guard (#155) #290
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| workflow_dispatch: | |
| inputs: | |
| ref: | |
| description: "Branch or SHA to run CI on" | |
| required: false | |
| default: "" | |
| permissions: | |
| contents: read | |
| jobs: | |
| test: | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| matrix: | |
| python-version: ["3.11", "3.12", "3.13"] | |
| os: [ubuntu-latest, windows-latest] | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| - name: Install dependencies | |
| run: python -m pip install --upgrade pip setuptools && pip install -e ".[dev]" | |
| - name: Security scan | |
| run: pip install bandit pip-audit && bandit -r src/ -c pyproject.toml && pip-audit | |
| - name: Lint | |
| run: ruff check src/ tests/ | |
| # Checked, not applied. Without this gate 34 of 77 files drifted out of | |
| # format unnoticed, because `ruff check` does not cover formatting. | |
| - name: Format | |
| run: ruff format --check src/ tests/ | |
| - name: Type check | |
| run: mypy src/ca2a_runtime/ src/ca2a_verify/ | |
| - name: Test | |
| run: pytest tests/unit/ tests/conformance/ -v --tb=short --cov=src --cov-report=xml | |
| - name: Upload coverage report | |
| uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 | |
| with: | |
| fail_ci_if_error: false | |
| governance: | |
| runs-on: ubuntu-latest | |
| needs: test | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.12" | |
| - name: Install dependencies | |
| run: python -m pip install --upgrade pip setuptools && pip install -e ".[dev]" | |
| # AGT 4.1 currently constrains cryptography below 49, while the runtime | |
| # requires 50+ for published security fixes. Keep the scanner isolated | |
| # so its tooling constraints cannot downgrade the package under test, | |
| # then override that stale upper bound inside the ephemeral scanner too. | |
| - name: Install governance tooling in an isolated environment | |
| run: | | |
| python -m venv .agt-venv | |
| .agt-venv/bin/pip install "agent-governance-toolkit[full]>=4.1" | |
| .agt-venv/bin/pip install --upgrade --no-deps "cryptography>=50.0" | |
| - name: Generate evidence file | |
| run: python scripts/gen_agt_evidence.py | |
| # Blocking gate: the [full] toolkit provides the ASI coverage modules | |
| # (10/10) and the evidence declares cA2A's governed capabilities, so strict | |
| # verify is COMPLETE. A regression that drops coverage or governance fails CI. | |
| - name: AGT governance verify (strict) | |
| run: .agt-venv/bin/agt verify --evidence agt-evidence.json | |
| - name: Save attestation JSON | |
| run: .agt-venv/bin/agt --json verify --evidence agt-evidence.json > agt-attestation.json | |
| - name: Upload governance artifacts | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.0 | |
| with: | |
| name: agt-governance-${{ github.sha }} | |
| path: | | |
| agt-evidence.json | |
| agt-attestation.json | |
| if-no-files-found: warn | |
| benchmark: | |
| runs-on: ubuntu-latest | |
| needs: test | |
| if: github.ref == 'refs/heads/main' | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.12" | |
| - name: Install dependencies | |
| run: python -m pip install --upgrade pip setuptools && pip install -e ".[dev]" | |
| - name: Run benchmark (software-only, CI gate p99 < 5ms) | |
| run: python -m ca2a_runtime.benchmarks --provider software-only --hops 10000 --out benchmarks/ | |
| - name: Upload benchmark results | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.0 | |
| with: | |
| name: benchmark-results | |
| path: benchmarks/ | |
| if-no-files-found: warn |