From fa25af8971036997ee7e6e569ab7a5e223fa8f93 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 17 Jun 2026 17:28:55 -0400 Subject: [PATCH 1/6] Adopt org CI conventions: thin wrappers over reusable workflows + dependabot MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Replace the inlined CI with thin callers of the Sea-Haven-Industries/.github reusable workflows (org convention — CI logic lives centrally in .github): - ci.yaml -> ci-python-app.yaml (ruff + conventions + root collect-only + the agent-team/ subproject suite; emits the required `ci / ci`) - dependency-review.yml -> callable-dependency-review.yaml - labeler.yml -> callable-labeler.yaml (all three permissions granted) Add .github/dependabot.yml (pip + github-actions, weekly, grouped). --- .github/dependabot.yml | 20 +++++++ .github/workflows/ci.yaml | 76 +++---------------------- .github/workflows/dependency-review.yml | 8 +++ .github/workflows/labeler.yml | 17 ++++++ 4 files changed, 54 insertions(+), 67 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/dependency-review.yml create mode 100644 .github/workflows/labeler.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..b6b02e7 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,20 @@ +version: 2 +updates: + - package-ecosystem: "pip" + directory: "/" + schedule: + interval: "weekly" + groups: + minor-and-patch: + update-types: + - "minor" + - "patch" + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + groups: + minor-and-patch: + update-types: + - "minor" + - "patch" diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 72c7336..0238d3a 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -3,72 +3,14 @@ name: CI on: pull_request: branches: [main] - push: - branches: [main] jobs: - lint: - runs-on: ubuntu-latest - timeout-minutes: 5 - steps: - - uses: actions/checkout@v6 - - - uses: actions/setup-python@v5 - with: - python-version: "3.12" - - - name: Install ruff - run: pip install ruff - - - name: Ruff check - run: ruff check . - - - name: Ruff format check - run: ruff format --check . - - test-collect: - runs-on: ubuntu-latest - timeout-minutes: 10 - steps: - - uses: actions/checkout@v6 - - - uses: actions/setup-python@v5 - with: - python-version: "3.12" - cache: pip - cache-dependency-path: requirements.txt - - - name: Install dependencies - run: | - pip install -r requirements.txt - pip install pytest python-dotenv - - - name: Pytest collect-only - # Verifies all test modules + their imports resolve cleanly. - # Live test execution requires ANTHROPIC_API_KEY + COMPOSIO_API_KEY - # and runs locally before push, not in CI. - run: pytest --collect-only -q - - agent-team-tests: - # The agent-team/ subproject is self-contained (no API keys needed), so its - # suite RUNS in CI rather than only collecting. Its tests/ package collides - # with the repo-root tests/ under one rootdir, so it runs in its own dir. - runs-on: ubuntu-latest - timeout-minutes: 10 - steps: - - uses: actions/checkout@v6 - - - uses: actions/setup-python@v5 - with: - python-version: "3.12" - cache: pip - cache-dependency-path: requirements.txt - - - name: Install dependencies - run: | - pip install -r requirements.txt - pip install pytest - - - name: Run agent-team suite - working-directory: agent-team - run: python -m pytest -q + ci: + # Thin wrapper over the org reusable CI. The reusable runs ruff lint/format + + # conventions, a root `pytest --collect-only` (the root suite's live run needs + # ANTHROPIC_API_KEY/COMPOSIO_API_KEY, so CI only verifies imports resolve), and + # the self-contained agent-team/ suite in its own working dir. The aggregator + # job (keyed `ci`) emits the org-required `ci / ci` check. + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@main + with: + subproject-dir: agent-team diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml new file mode 100644 index 0000000..3cb9057 --- /dev/null +++ b/.github/workflows/dependency-review.yml @@ -0,0 +1,8 @@ +name: Dependency Review + +on: + pull_request: + +jobs: + review: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml new file mode 100644 index 0000000..93098d7 --- /dev/null +++ b/.github/workflows/labeler.yml @@ -0,0 +1,17 @@ +name: Labeler + +on: + pull_request: + branches: [main] + +# All three grants are required: reusable-workflow permissions can only be +# downgraded by the caller, so omitting one (e.g. issues: write, needed to create +# a label that does not exist yet) causes a silent startup_failure. +permissions: + contents: read + pull-requests: write + issues: write + +jobs: + label: + uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main -- 2.50.1 From 87cf44948502dfc53386167981501664a6769d0e Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 17 Jun 2026 17:39:39 -0400 Subject: [PATCH 2/6] ci: retrigger workflows -- 2.50.1 From 6adce969839b40e1a119eb14ffe1e4f2fc2ee32c Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 17 Jun 2026 17:41:55 -0400 Subject: [PATCH 3/6] ci: temporary inline probe workflow --- .github/workflows/_probe.yml | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 .github/workflows/_probe.yml diff --git a/.github/workflows/_probe.yml b/.github/workflows/_probe.yml new file mode 100644 index 0000000..1dc6267 --- /dev/null +++ b/.github/workflows/_probe.yml @@ -0,0 +1,9 @@ +name: probe +on: + pull_request: + branches: [main] +jobs: + probe: + runs-on: ubuntu-latest + steps: + - run: echo ok -- 2.50.1 From d17427d3cc6feed43fd99d0d37b58cef0f33bfa4 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 17 Jun 2026 17:46:42 -0400 Subject: [PATCH 4/6] ci: remove temporary inline probe workflow --- .github/workflows/_probe.yml | 9 --------- 1 file changed, 9 deletions(-) delete mode 100644 .github/workflows/_probe.yml diff --git a/.github/workflows/_probe.yml b/.github/workflows/_probe.yml deleted file mode 100644 index 1dc6267..0000000 --- a/.github/workflows/_probe.yml +++ /dev/null @@ -1,9 +0,0 @@ -name: probe -on: - pull_request: - branches: [main] -jobs: - probe: - runs-on: ubuntu-latest - steps: - - run: echo ok -- 2.50.1 From 13f3d89c9965de1e26b7fad5ffa9f4e01d5a1e1e Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 17 Jun 2026 17:51:11 -0400 Subject: [PATCH 5/6] ci: retrigger workflows -- 2.50.1 From 3d066e04e478663d8a086cf66e289988a24c4d2f Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 17 Jun 2026 17:56:32 -0400 Subject: [PATCH 6/6] ci: add workflow permissions from GHAS notes --- .github/workflows/ci.yaml | 3 +++ .github/workflows/dependency-review.yml | 3 +++ 2 files changed, 6 insertions(+) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 0238d3a..a9ff229 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -4,6 +4,9 @@ on: pull_request: branches: [main] +permissions: + contents: read + jobs: ci: # Thin wrapper over the org reusable CI. The reusable runs ruff lint/format + diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 3cb9057..3a0e131 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -3,6 +3,9 @@ name: Dependency Review on: pull_request: +permissions: + contents: read + jobs: review: uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main -- 2.50.1