Skip to content

Point adapter transforms at the agentsys install layout (#34) #33

Point adapter transforms at the agentsys install layout (#34)

Point adapter transforms at the agentsys install layout (#34) #33

Workflow file for this run

name: Sync to consumers
on:
push:
branches: [main]
paths: ['lib/**', 'templates/**', 'scripts/generate-agents-md.js']
workflow_dispatch:
permissions:
contents: read
jobs:
sync:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
repo: [agentsys, next-task, ship, enhance, deslop, learn, consult, debate, drift-detect, sync-docs, audit-project, perf, repo-intel]
steps:
- name: Checkout agent-core
uses: actions/checkout@v4
with:
path: source
- name: Checkout target
uses: actions/checkout@v4
with:
repository: agent-sh/${{ matrix.repo }}
token: ${{ secrets.SYNC_TOKEN }}
path: target
- name: Sync lib (explicit allowlist)
run: |
# Explicit allowlist policy. Previously this rsync copied
# everything under lib/ additively. The audit HIGH finding was:
# "any file a committer adds under lib/ replicates everywhere -
# allowlist needed".
#
# rsync --include / --exclude rules:
# 1. Allowlisted subdirs are synced recursively (/*** pattern).
# 2. Top-level files index.js, adapter-transforms.js sync.
# 3. A denylist of known-internal path patterns is rejected
# (belt-and-suspenders against adding them to the allowlist
# by mistake - e.g. lib/dev-only/, lib/scripts/, lib/.cache/).
# 4. Consumer-only lib/ files NOT in the allowlist are preserved
# (no --delete), same as the previous additive behavior.
#
# To add a new shared subdir: add it to the include list below
# AND document why it belongs in the shared core.
# To keep a subdir agent-core-internal: put it under lib/dev-only/
# or name it with a leading dot (.cache, .internal) - both are
# denylisted.
#
# Excludes *.test.js because agent-core's inline node:test suites
# break consumers that run Jest with a broad testMatch.
mkdir -p target/lib
# IMPORTANT: rsync filter rules are evaluated in order, first
# match wins. Test-file excludes MUST come before the subdir
# `***` includes — otherwise `--include='binary/***'` matches
# `binary/index.test.js` first and the later
# `--exclude='*.test.js'` never fires. Same logic for any
# other sub-path exclusion that should override a broad
# include.
rsync -a \
--exclude='*.test.js' \
--exclude='dev-only/***' \
--exclude='scripts/***' \
--exclude='.cache/***' \
--exclude='.internal/***' \
--include='index.js' \
--include='adapter-transforms.js' \
--include='binary/***' \
--include='collectors/***' \
--include='config/***' \
--include='cross-platform/***' \
--include='discovery/***' \
--include='drift-detect/***' \
--include='enhance/***' \
--include='patterns/***' \
--include='perf/***' \
--include='platform/***' \
--include='repo-intel/***' \
--include='repo-map/***' \
--include='schemas/***' \
--include='sources/***' \
--include='state/***' \
--include='types/***' \
--include='utils/***' \
--exclude='*' \
source/lib/ target/lib/
- name: Generate AGENTS.md
run: node source/scripts/generate-agents-md.js --target target --template source/templates/AGENTS.md.tmpl
- name: Check for changes
id: diff
working-directory: target
run: |
if [ -n "$(git status --porcelain)" ]; then
echo "changed=true" >> $GITHUB_OUTPUT
else
echo "changed=false" >> $GITHUB_OUTPUT
fi
- name: Create PR
if: steps.diff.outputs.changed == 'true'
working-directory: target
env:
GH_TOKEN: ${{ secrets.SYNC_TOKEN }}
TARGET_REPO: agent-sh/${{ matrix.repo }}
REPO_NAME: ${{ matrix.repo }}
run: |
BRANCH="chore/sync-core-${REPO_NAME}-$(date +%Y%m%d-%H%M%S)"
git config user.name "agent-core-bot"
git config user.email "[email protected]"
git checkout -b "$BRANCH"
git add lib/ AGENTS.md
git commit -m "chore: sync core lib and AGENTS.md from agent-core"
git push origin "$BRANCH"
gh pr create \
--repo "$TARGET_REPO" \
--base main \
--title "chore: sync core lib and AGENTS.md from agent-core" \
--body "Automated sync of lib/ and AGENTS.md from [agent-core](https://github.com/agent-sh/agent-core)." \
--head "$BRANCH"