Adopt org conventions: reusable-workflow CI, dependabot, labels #10

Merged
amoussa1229 merged 6 commits from feature/adopt-org-conventions into main 2026-06-17 22:00:33 +00:00
4 changed files with 60 additions and 67 deletions

20
.github/dependabot.yml vendored Normal file
View file

@ -0,0 +1,20 @@
version: 2
updates:
- package-ecosystem: "pip"
directory: "/"
schedule:
interval: "weekly"
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"

View file

@ -3,72 +3,17 @@ name: CI
on:
pull_request:
branches: [main]
push:
branches: [main]
permissions:
contents: read
jobs:
lint:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@v6
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install ruff
run: pip install ruff
- name: Ruff check
run: ruff check .
- name: Ruff format check
run: ruff format --check .
test-collect:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v6
- uses: actions/setup-python@v5
with:
python-version: "3.12"
cache: pip
cache-dependency-path: requirements.txt
- name: Install dependencies
run: |
pip install -r requirements.txt
pip install pytest python-dotenv
- name: Pytest collect-only
# Verifies all test modules + their imports resolve cleanly.
# Live test execution requires ANTHROPIC_API_KEY + COMPOSIO_API_KEY
# and runs locally before push, not in CI.
run: pytest --collect-only -q
agent-team-tests:
# The agent-team/ subproject is self-contained (no API keys needed), so its
# suite RUNS in CI rather than only collecting. Its tests/ package collides
# with the repo-root tests/ under one rootdir, so it runs in its own dir.
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v6
- uses: actions/setup-python@v5
with:
python-version: "3.12"
cache: pip
cache-dependency-path: requirements.txt
- name: Install dependencies
run: |
pip install -r requirements.txt
pip install pytest
- name: Run agent-team suite
working-directory: agent-team
run: python -m pytest -q
ci:
# Thin wrapper over the org reusable CI. The reusable runs ruff lint/format +
# conventions, a root `pytest --collect-only` (the root suite's live run needs
# ANTHROPIC_API_KEY/COMPOSIO_API_KEY, so CI only verifies imports resolve), and
# the self-contained agent-team/ suite in its own working dir. The aggregator
# job (keyed `ci`) emits the org-required `ci / ci` check.
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@main
with:
subproject-dir: agent-team

11
.github/workflows/dependency-review.yml vendored Normal file
View file

@ -0,0 +1,11 @@
name: Dependency Review
on:
pull_request:
permissions:
contents: read
jobs:
review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@main
github-advanced-security[bot] commented 2026-06-17 21:52:13 +00:00 (Migrated from github.com)
Review

CodeQL / Workflow does not contain permissions

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}}

Show more details

## CodeQL / Workflow does not contain permissions Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {{}} [Show more details](https://github.com/Sea-Haven-Industries/orchestrator/security/code-scanning/5)
amoussa1229 commented 2026-06-17 21:57:13 +00:00 (Migrated from github.com)
Review

Fixed: added permissions in 3d066e0

Fixed: added permissions in 3d066e0

17
.github/workflows/labeler.yml vendored Normal file
View file

@ -0,0 +1,17 @@
name: Labeler
on:
pull_request:
branches: [main]
# All three grants are required: reusable-workflow permissions can only be
# downgraded by the caller, so omitting one (e.g. issues: write, needed to create
# a label that does not exist yet) causes a silent startup_failure.
permissions:
contents: read
pull-requests: write
issues: write
jobs:
label:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@main