Repository object · automation
Ci
Accepted automation in the public catalog.
- Source path
.github/workflows/ci.yml- Media type
application/yaml- Object ID
em:automation:sha256:8564fbb863aa61b4f2dd7b69d98b4b3b4574fb052ebdbaf099c48cff55a6edd7- Content digest
103035b71129f518e1cab8753e1788631e1c8cec1c9a5dde235167626dd57ff4
Source content
name: validate
on:
pull_request:
push:
branches: [main]
workflow_dispatch:
permissions: {}
concurrency:
group: validate-${{ github.ref }}
cancel-in-progress: true
jobs:
check:
permissions:
checks: read
contents: read
pull-requests: read
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
path: candidate
fetch-depth: 0
persist-credentials: false
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
ref: ${{ github.event.pull_request.base.sha || github.sha }}
path: validator
fetch-depth: 0
persist-credentials: false
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
with:
python-version: "3.12"
cache: pip
cache-dependency-path: candidate/pyproject.toml
- name: Classify docket contribution mode using accepted-base code
id: classify
shell: bash
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
run: |
set -euo pipefail
if [[ -f validator/ops/classify_docket_pr.py ]]; then
python validator/ops/classify_docket_pr.py \
--candidate candidate \
--base-sha "$BASE_SHA" \
--github-output "$GITHUB_OUTPUT"
else
# One-time bootstrap for the reviewed EM-0040 implementation. The accepted base
# predates the classifier, so no docket-sensitive diff may pass this transition.
mapfile -t bootstrap_paths < <(
git -C candidate diff --name-only "$BASE_SHA...HEAD"
)
for path in "${bootstrap_paths[@]}"; do
if [[ "$path" == research/open-dockets/* ]]; then
echo "accepted base lacks the docket classifier; rejecting sensitive diff" >&2
exit 1
fi
done
echo "mode=normal" >> "$GITHUB_OUTPUT"
fi
- name: Install
if: steps.classify.outputs.mode == 'normal'
working-directory: candidate
run: python -m pip install -e '.[dev]'
- name: Validate, build, test, audit, and verify deterministic state
if: steps.classify.outputs.mode == 'normal'
working-directory: candidate
run: make check
- name: Validate and block untrusted submission using accepted-base code
if: steps.classify.outputs.mode == 'submission'
env:
PYTHONPATH: validator/src
BASE_SHA: ${{ github.event.pull_request.base.sha }}
CURRENT_PR_NUMBER: ${{ github.event.pull_request.number }}
GITHUB_REPOSITORY: ${{ github.repository }}
GITHUB_TOKEN: ${{ github.token }}
run: python validator/ops/validate_submission_pr.py --candidate candidate --base-sha "$BASE_SHA"
- name: Validate promotion using accepted-base code
if: steps.classify.outputs.mode == 'promotion'
env:
PYTHONPATH: validator/src
BASE_SHA: ${{ github.event.pull_request.base.sha }}
CANDIDATE_SHA: ${{ github.event.pull_request.head.sha }}
CURRENT_PR_NUMBER: ${{ github.event.pull_request.number }}
GITHUB_REPOSITORY: ${{ github.repository }}
GITHUB_TOKEN: ${{ github.token }}
run: python validator/ops/validate_promotion_pr.py --candidate candidate --base-sha "$BASE_SHA"
Build receipt
Reproduce this projection
- Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d- Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf- Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9- Epistemic policy
commons-balanced-v0.1- Disclosure policy
public-noninterference-v0.1- Compiler
epistemedia/0.2.0