Repository navigation
release: complete TripChord 2.0 functional form #71
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: ci | |
| on: | |
| push: | |
| pull_request: | |
| jobs: | |
| api: | |
| runs-on: ubuntu-latest | |
| services: | |
| postgres: | |
| image: postgres:17-alpine | |
| env: | |
| POSTGRES_DB: tripchord_ci | |
| POSTGRES_USER: tripchord | |
| POSTGRES_PASSWORD: tripchord | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U tripchord -d tripchord_ci" | |
| --health-interval 5s | |
| --health-timeout 3s | |
| --health-retries 20 | |
| env: | |
| TRIPCHORD_POSTGRES_TEST_URL: postgresql+asyncpg://tripchord:[email protected]:5432/tripchord_ci | |
| steps: | |
| - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 | |
| - uses: astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6 | |
| with: | |
| python-version: "3.12" | |
| enable-cache: true | |
| - run: uv sync --locked --all-groups | |
| - run: uv run ruff check . | |
| - run: uv run mypy apps/api/src | |
| - run: uv run pytest -m 'not integration' | |
| - run: uv run python -m training.train_sft --validate-only | |
| - run: uv run python -m training.train_dpo --validate-only | |
| - run: uv run python -m training.policy_reranker | |
| - run: git diff --exit-code -- training/artifacts/replan-policy.json benchmarks/results/phase-7-post-training.json | |
| - run: | | |
| uv export --frozen --no-dev --no-hashes --no-emit-project \ | |
| --output-file /tmp/tripchord-requirements.txt | |
| uvx pip-audit --strict -r /tmp/tripchord-requirements.txt | |
| - run: | | |
| migration_db=$(mktemp /tmp/tripchord-migration-XXXXXX.db) | |
| TRIPCHORD_DATABASE_URL="sqlite+aiosqlite:///$migration_db" uv run alembic upgrade head | |
| TRIPCHORD_DATABASE_URL="sqlite+aiosqlite:///$migration_db" uv run alembic check | |
| - name: PostgreSQL durable live-job integration | |
| run: | | |
| TRIPCHORD_DATABASE_URL="$TRIPCHORD_POSTGRES_TEST_URL" uv run alembic upgrade head | |
| TRIPCHORD_DATABASE_URL="$TRIPCHORD_POSTGRES_TEST_URL" uv run alembic check | |
| uv run pytest -m integration apps/api/tests/test_live_planning_jobs_postgres.py | |
| - run: uv run python benchmarks/evaluate.py | |
| - run: uv run python benchmarks/evaluate_planning.py | |
| - run: uv run python benchmarks/evaluate_repair.py | |
| - run: uv run python benchmarks/evaluate_events.py | |
| - run: uv run python benchmarks/evaluate_acceptance.py | |
| - run: uv run python benchmarks/evaluate_faults.py | |
| - name: sbom / build provenance drift check | |
| run: | | |
| uv run python scripts/generate_sbom.py generate --output-dir /tmp/tripchord-sbom | |
| uv run python scripts/generate_sbom.py check | |
| companion: | |
| # v0.9: the Browser Companion release gate now runs in remote CI, not only | |
| # locally. It validates build-meta, the release seal, host permissions and | |
| # the JS/Python contract suites in a key-free environment. | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 | |
| - uses: astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6 | |
| with: | |
| python-version: "3.12" | |
| enable-cache: true | |
| - uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 | |
| with: | |
| node-version: "22" | |
| cache: npm | |
| - run: npm ci | |
| - run: uv sync --locked --all-groups | |
| - run: uv run python scripts/browser_companion_release_gate.py --ci-verify-key-free | |
| env: | |
| ANTHROPIC_API_KEY: "" | |
| MODEL_API_KEY: "" | |
| TRIPCHORD_ANTHROPIC_API_KEY: "" | |
| TRIPCHORD_BROWSER_BRIDGE_CONTROL_TOKEN: "" | |
| TRIPCHORD_BROWSER_BRIDGE_TOKEN: "" | |
| TRIPCHORD_MODEL_API_KEY: "" | |
| security: | |
| # v0.9: secret scanning + Python SAST stay cheap and fail closed. The | |
| # gitleaks action scans the push/PR diff for committed secrets. | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 | |
| with: | |
| fetch-depth: 0 | |
| - name: secret scan (gitleaks) | |
| uses: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7 # v2 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| GITLEAKS_LICENSE: "" | |
| - uses: astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6 | |
| with: | |
| python-version: "3.12" | |
| enable-cache: true | |
| - run: uv sync --locked --all-groups | |
| - run: uv run ruff check . | |
| - name: dependency audit | |
| run: | | |
| uv export --frozen --no-dev --no-hashes --no-emit-project \ | |
| --output-file /tmp/tripchord-requirements.txt | |
| uvx pip-audit --strict -r /tmp/tripchord-requirements.txt | |
| web: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 | |
| - uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 | |
| with: | |
| node-version: "22" | |
| cache: npm | |
| - run: npm ci | |
| - run: npm run build | |
| - run: npm test | |
| - run: npm audit --omit=dev --audit-level=high | |
| containers: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 | |
| - run: docker compose config | |
| - run: docker compose build |