Commit graph

8 commits

Author SHA1 Message Date
2dce5c6b76 fix(agent-team): post-build denied-path check writes scratch outside the checkout
Live smoke exposed a self-pollution bug (pre-existing from PR #17): the post-build
denied-path check wrote its own _build_diff_z.bin / _build_status_z.bin into the
working tree, then its own `git status --untracked-files=all` flagged them as
out-of-scope writes — failing any run with a narrow declared_scope (the smoke's
docs/**). Write them to $RUNNER_TEMP instead (read via $_DIFF_Z/$_STATUS_Z), so
the check no longer sees its own temp files. The agent-team pytest artifacts were
already correctly gitignored; only the check's own files tripped it. Test harness
updated to pass the env paths. 1044 tests, ruff clean.
2026-06-22 19:18:47 -04:00
Adam Moussa
5756178d62
feat(agent-team): wire apply/verify into .github/workflows (make it a live GitHub Actions workflow) (#37)
GitHub Actions only runs workflows under .github/workflows/, so the apply/verify
workflow at agent-team/ci/ was never registered (workflow_dispatch 404'd). Move it
to .github/workflows/agent-team-apply-verify.yml so it is a real, dispatchable
workflow. Its only trigger is workflow_dispatch + it is gated by the agent-apply
required-reviewer environment, so it never auto-runs and nothing privileged runs
unapproved. Updated the two workflow test files' path refs (parents[2]/.github/
workflows) and the ci/README pointer. Dispatcher push gains --no-verify: the apply
path is scanned CI-side (guard + the PR's checks), so it must not be blocked by the
operator's LOCAL human-commit pre-push dev hook (which flags pre-existing whole-repo
FPs like .env.example). 1044 tests, ruff clean.
2026-06-22 19:12:17 -04:00
3d066e04e4 ci: add workflow permissions from GHAS notes 2026-06-17 17:56:32 -04:00
d17427d3cc ci: remove temporary inline probe workflow 2026-06-17 17:46:42 -04:00
6adce96983 ci: temporary inline probe workflow 2026-06-17 17:41:55 -04:00
fa25af8971 Adopt org CI conventions: thin wrappers over reusable workflows + dependabot
Replace the inlined CI with thin callers of the Sea-Haven-Industries/.github
reusable workflows (org convention — CI logic lives centrally in .github):
- ci.yaml -> ci-python-app.yaml (ruff + conventions + root collect-only +
  the agent-team/ subproject suite; emits the required `ci / ci`)
- dependency-review.yml -> callable-dependency-review.yaml
- labeler.yml -> callable-labeler.yaml (all three permissions granted)
Add .github/dependabot.yml (pip + github-actions, weekly, grouped).
2026-06-17 17:28:55 -04:00
502828f75c Fix CI collection: isolate agent-team tests; add agent-team CI job
Repo-root 'pytest --collect-only' failed with ImportPathMismatchError because
agent-team/tests/ and the root tests/ are both the 'tests' package. Add a root
conftest.py that excludes agent-team from the root collection, and a dedicated
agent-team-tests CI job that runs the (API-key-free) agent-team suite in its own
working dir.
2026-06-17 15:19:51 -04:00
Adam Moussa
fb5dbb20ee Add CI workflow and ignore .DS_Store
Closes the no-CI gap surfaced in the post-merge retrospective. The org
reusable workflows live under Sea-Haven-Industries and assume SAM/CDK
projects — orchestrator is a personal CLI tool with neither, so this is
a standalone workflow on the same conventions (actions/checkout@v6,
Python 3.12, ruff).

- lint job: ruff check + ruff format --check.
- test-collect job: installs requirements + runs `pytest --collect-only`.
  Catches import errors and golden-set test discovery regressions without
  needing live ANTHROPIC/COMPOSIO secrets — full pytest stays a local
  pre-push responsibility.

Also adds .DS_Store to the local .gitignore (also covered by the user
global gitignore, but belt-and-suspenders).
2026-05-15 13:13:41 -04:00