diff --git a/.github/scripts/check-dev-green.sh b/.github/scripts/check-dev-green.sh index fa96bf23..8719e5b0 100755 --- a/.github/scripts/check-dev-green.sh +++ b/.github/scripts/check-dev-green.sh @@ -4,7 +4,7 @@ # Reads check-runs on stdin — one # namestatusconclusiondetails_url # per line, fields separated by ASCII Unit Separator (0x1F) — so it is unit-testable -# WITHOUT GitHub. promote_dev_to_prod.yml pipes the live `gh api .../check-runs` +# WITHOUT GitHub. promote-dev-to-prod.yml pipes the live `gh api .../check-runs` # output in. 0x1F (not TAB) is used deliberately: TAB is IFS-whitespace, so an empty # conclusion (every in_progress check has a null conclusion) would collapse and shift # the columns — which would make the promote run fail to exclude itself. 0x1F is @@ -26,12 +26,12 @@ set -euo pipefail EXCLUDE_RUN_ID="${EXCLUDE_RUN_ID:-}" -# Mandatory checks (one per line). Defaults to the Agent CI suite, which runs on +# Mandatory checks (one per line). Defaults to the CI suite, which runs on # every push to dev (see ci.yml). Keep in sync with those job names; if a name # drifts the gate blocks (fails safe) until the list is updated. -REQUIRED_CHECKS="${REQUIRED_CHECKS:-Agent lint -Agent format check -Agent unit tests +REQUIRED_CHECKS="${REQUIRED_CHECKS:-Lint +Format check +Unit tests Playwright E2E}" declare -A GREEN diff --git a/.github/workflows/build-artifacts.yml b/.github/workflows/build-artifacts.yml index 76bd9cdc..6e295de0 100644 --- a/.github/workflows/build-artifacts.yml +++ b/.github/workflows/build-artifacts.yml @@ -62,7 +62,7 @@ jobs: BUCKET: open-swe-dev-assets DEPLOY_DOC: open-swe-dev-deploy steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: oven-sh/setup-bun@v2 with: bun-version: latest @@ -100,7 +100,7 @@ jobs: BUCKET: open-swe-prod-assets DEPLOY_DOC: open-swe-prod-deploy steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: oven-sh/setup-bun@v2 with: bun-version: latest diff --git a/.github/workflows/cd-infra.yml b/.github/workflows/cd-infra.yml index 510bbe18..8e6f4008 100644 --- a/.github/workflows/cd-infra.yml +++ b/.github/workflows/cd-infra.yml @@ -66,7 +66,7 @@ jobs: id-token: write contents: read steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: actions/setup-node@v4 with: node-version: "24" @@ -102,7 +102,7 @@ jobs: id-token: write contents: read steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: actions/setup-node@v4 with: node-version: "24" diff --git a/.github/workflows/ci-infra.yml b/.github/workflows/ci-infra.yml index 8e82152d..0a40c69d 100644 --- a/.github/workflows/ci-infra.yml +++ b/.github/workflows/ci-infra.yml @@ -1,6 +1,6 @@ name: Infra CI -# Path-filtered CI for the /infra CDK app (TypeScript). The existing "Agent CI" +# Path-filtered CI for the /infra CDK app (TypeScript). The existing "CI" # (ci.yml) covers the Python agent; this adds tsc + jest + cdk synth for /infra so # infra changes are gated on a PR the same way. Runs only when /infra changes. diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c79fd149..42cbe8d6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,11 +1,11 @@ -name: Agent CI +name: CI permissions: contents: read on: push: - # dev as well as main so every dev HEAD carries the full Agent CI signal that + # dev as well as main so every dev HEAD carries the full CI signal that # the dev->main promotion gate (check-dev-green.sh) reads. PR checks alone are # not enough: an admin-merge can land a red PR onto dev. branches: ["main", "dev"] @@ -18,10 +18,10 @@ concurrency: jobs: lint: - name: Agent lint + name: Lint runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 - name: Install dependencies run: uv sync --locked --extra dev @@ -29,10 +29,10 @@ jobs: run: make lint format: - name: Agent format check + name: Format check runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 - name: Install dependencies run: uv sync --locked --extra dev @@ -40,10 +40,10 @@ jobs: run: make format-check unit-tests: - name: Agent unit tests + name: Unit tests runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 - name: Install dependencies run: uv sync --locked --extra dev @@ -55,7 +55,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 30 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 - uses: actions/setup-node@v4 with: diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 00000000..ca9a8b01 --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,15 @@ +name: Dependency Review + +on: pull_request + +permissions: + contents: read + +jobs: + dependency-review: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7 + - uses: actions/dependency-review-action@v4 + with: + fail-on-severity: high diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml new file mode 100644 index 00000000..115932f3 --- /dev/null +++ b/.github/workflows/labeler.yml @@ -0,0 +1,13 @@ +name: Labeler + +on: + pull_request: + +permissions: + contents: read + pull-requests: write + issues: write + +jobs: + labeler: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main diff --git a/.github/workflows/promote_dev_to_prod.yml b/.github/workflows/promote-dev-to-prod.yml similarity index 97% rename from .github/workflows/promote_dev_to_prod.yml rename to .github/workflows/promote-dev-to-prod.yml index 8c38e699..c253e21d 100644 --- a/.github/workflows/promote_dev_to_prod.yml +++ b/.github/workflows/promote-dev-to-prod.yml @@ -19,7 +19,7 @@ jobs: contents: write checks: read steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: ref: dev fetch-depth: 0 diff --git a/.github/workflows/reviewer_eval.yml b/.github/workflows/reviewer-eval.yml similarity index 99% rename from .github/workflows/reviewer_eval.yml rename to .github/workflows/reviewer-eval.yml index 66f62356..24b04bfb 100644 --- a/.github/workflows/reviewer_eval.yml +++ b/.github/workflows/reviewer-eval.yml @@ -78,7 +78,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 360 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 - name: Install dependencies run: uv sync --locked diff --git a/.github/workflows/rollback.yml b/.github/workflows/rollback.yml index 1a51e49c..5a4f30ec 100644 --- a/.github/workflows/rollback.yml +++ b/.github/workflows/rollback.yml @@ -50,7 +50,7 @@ jobs: DEPLOY_DOC: open-swe-dev-deploy TARGET_SHA: ${{ inputs.sha }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: aws-actions/configure-aws-credentials@v6 with: role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_APP_DEV }} @@ -75,7 +75,7 @@ jobs: DEPLOY_DOC: open-swe-prod-deploy TARGET_SHA: ${{ inputs.sha }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: aws-actions/configure-aws-credentials@v6 with: role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_APP_PROD }} diff --git a/evals/reviewer/README.md b/evals/reviewer/README.md index 2e5767d1..afeab53c 100644 --- a/evals/reviewer/README.md +++ b/evals/reviewer/README.md @@ -57,8 +57,8 @@ uv run python -m evals.reviewer.run_eval --limit 3 ### From the GitHub Action (recommended for full runs) -Trigger the **Reviewer eval** workflow (`.github/workflows/reviewer_eval.yml`) -from the Actions UI or `gh workflow run reviewer_eval.yml --ref prod -f limit=3`. +Trigger the **Reviewer eval** workflow (`.github/workflows/reviewer-eval.yml`) +from the Actions UI or `gh workflow run reviewer-eval.yml --ref prod -f limit=3`. Run it on the **prod** branch so the harness/judge match the deployed reviewer it scores. Running it on a durable runner (instead of inside the serving deployment) means a deploy or container recycle can't kill a long run. diff --git a/infra/README.md b/infra/README.md index 256cb868..f3f964f4 100644 --- a/infra/README.md +++ b/infra/README.md @@ -245,7 +245,7 @@ npm test # jest — naming Aspect ## CI/CD (T18 — `.github/workflows/ci-infra.yml` + `cd-infra.yml`) Path-filtered, OIDC-only (no static keys). The Python agent keeps its own -`ci.yml` ("Agent CI"); these two add the `/infra` half. +`ci.yml` ("CI"); these two add the `/infra` half. | Workflow | Trigger | Does | |---|---|---|