Adopt org conventions: reusable-workflow CI, dependabot, labels #10
4 changed files with 60 additions and 67 deletions
20
.github/dependabot.yml
vendored
Normal file
20
.github/dependabot.yml
vendored
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: "pip"
|
||||
directory: "/"
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
groups:
|
||||
minor-and-patch:
|
||||
update-types:
|
||||
- "minor"
|
||||
- "patch"
|
||||
- package-ecosystem: "github-actions"
|
||||
directory: "/"
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
groups:
|
||||
minor-and-patch:
|
||||
update-types:
|
||||
- "minor"
|
||||
- "patch"
|
||||
79
.github/workflows/ci.yaml
vendored
79
.github/workflows/ci.yaml
vendored
|
|
@ -3,72 +3,17 @@ name: CI
|
|||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
push:
|
||||
branches: [main]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
lint:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: "3.12"
|
||||
|
||||
- name: Install ruff
|
||||
run: pip install ruff
|
||||
|
||||
- name: Ruff check
|
||||
run: ruff check .
|
||||
|
||||
- name: Ruff format check
|
||||
run: ruff format --check .
|
||||
|
||||
test-collect:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: "3.12"
|
||||
cache: pip
|
||||
cache-dependency-path: requirements.txt
|
||||
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
pip install -r requirements.txt
|
||||
pip install pytest python-dotenv
|
||||
|
||||
- name: Pytest collect-only
|
||||
# Verifies all test modules + their imports resolve cleanly.
|
||||
# Live test execution requires ANTHROPIC_API_KEY + COMPOSIO_API_KEY
|
||||
# and runs locally before push, not in CI.
|
||||
run: pytest --collect-only -q
|
||||
|
||||
agent-team-tests:
|
||||
# The agent-team/ subproject is self-contained (no API keys needed), so its
|
||||
# suite RUNS in CI rather than only collecting. Its tests/ package collides
|
||||
# with the repo-root tests/ under one rootdir, so it runs in its own dir.
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: "3.12"
|
||||
cache: pip
|
||||
cache-dependency-path: requirements.txt
|
||||
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
pip install -r requirements.txt
|
||||
pip install pytest
|
||||
|
||||
- name: Run agent-team suite
|
||||
working-directory: agent-team
|
||||
run: python -m pytest -q
|
||||
ci:
|
||||
# Thin wrapper over the org reusable CI. The reusable runs ruff lint/format +
|
||||
# conventions, a root `pytest --collect-only` (the root suite's live run needs
|
||||
# ANTHROPIC_API_KEY/COMPOSIO_API_KEY, so CI only verifies imports resolve), and
|
||||
# the self-contained agent-team/ suite in its own working dir. The aggregator
|
||||
# job (keyed `ci`) emits the org-required `ci / ci` check.
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@main
|
||||
with:
|
||||
subproject-dir: agent-team
|
||||
|
|
|
|||
11
.github/workflows/dependency-review.yml
vendored
Normal file
11
.github/workflows/dependency-review.yml
vendored
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
name: Dependency Review
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
review:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main
|
||||
|
Fixed: added permissions in Fixed: added permissions in 3d066e0
|
||||
17
.github/workflows/labeler.yml
vendored
Normal file
17
.github/workflows/labeler.yml
vendored
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
name: Labeler
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
# All three grants are required: reusable-workflow permissions can only be
|
||||
# downgraded by the caller, so omitting one (e.g. issues: write, needed to create
|
||||
# a label that does not exist yet) causes a silent startup_failure.
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: write
|
||||
issues: write
|
||||
|
||||
jobs:
|
||||
label:
|
||||
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main
|
||||
Reference in a new issue
CodeQL / Workflow does not contain permissions
Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}}
Show more details