Skip to content

ci: add actionlint and a test-environment guard (#155) #290

ci: add actionlint and a test-environment guard (#155)

ci: add actionlint and a test-environment guard (#155) #290

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
inputs:
ref:
description: "Branch or SHA to run CI on"
required: false
default: ""
permissions:
contents: read
jobs:
test:
runs-on: ${{ matrix.os }}
strategy:
matrix:
python-version: ["3.11", "3.12", "3.13"]
os: [ubuntu-latest, windows-latest]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python-version }}
- name: Install dependencies
run: python -m pip install --upgrade pip setuptools && pip install -e ".[dev]"
- name: Security scan
run: pip install bandit pip-audit && bandit -r src/ -c pyproject.toml && pip-audit
- name: Lint
run: ruff check src/ tests/
# Checked, not applied. Without this gate 34 of 77 files drifted out of
# format unnoticed, because `ruff check` does not cover formatting.
- name: Format
run: ruff format --check src/ tests/
- name: Type check
run: mypy src/ca2a_runtime/ src/ca2a_verify/
- name: Test
run: pytest tests/unit/ tests/conformance/ -v --tb=short --cov=src --cov-report=xml
- name: Upload coverage report
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
fail_ci_if_error: false
governance:
runs-on: ubuntu-latest
needs: test
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Install dependencies
run: python -m pip install --upgrade pip setuptools && pip install -e ".[dev]"
# AGT 4.1 currently constrains cryptography below 49, while the runtime
# requires 50+ for published security fixes. Keep the scanner isolated
# so its tooling constraints cannot downgrade the package under test,
# then override that stale upper bound inside the ephemeral scanner too.
- name: Install governance tooling in an isolated environment
run: |
python -m venv .agt-venv
.agt-venv/bin/pip install "agent-governance-toolkit[full]>=4.1"
.agt-venv/bin/pip install --upgrade --no-deps "cryptography>=50.0"
- name: Generate evidence file
run: python scripts/gen_agt_evidence.py
# Blocking gate: the [full] toolkit provides the ASI coverage modules
# (10/10) and the evidence declares cA2A's governed capabilities, so strict
# verify is COMPLETE. A regression that drops coverage or governance fails CI.
- name: AGT governance verify (strict)
run: .agt-venv/bin/agt verify --evidence agt-evidence.json
- name: Save attestation JSON
run: .agt-venv/bin/agt --json verify --evidence agt-evidence.json > agt-attestation.json
- name: Upload governance artifacts
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.0
with:
name: agt-governance-${{ github.sha }}
path: |
agt-evidence.json
agt-attestation.json
if-no-files-found: warn
benchmark:
runs-on: ubuntu-latest
needs: test
if: github.ref == 'refs/heads/main'
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Install dependencies
run: python -m pip install --upgrade pip setuptools && pip install -e ".[dev]"
- name: Run benchmark (software-only, CI gate p99 < 5ms)
run: python -m ca2a_runtime.benchmarks --provider software-only --hops 10000 --out benchmarks/
- name: Upload benchmark results
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.0
with:
name: benchmark-results
path: benchmarks/
if-no-files-found: warn