mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-10 06:58:59 +02:00
Merge remote-tracking branch 'origin/main' into garrytan/gbrain-code-smell-audit
# Conflicts: # CHANGELOG.md # browse/test/dual-listener.test.ts # browse/test/fixtures/security-bench-haiku-responses.json # browse/test/sidebar-tabs.test.ts # browse/test/sidebar-ux.test.ts # browse/test/terminal-agent.test.ts # claude/SKILL.md.tmpl # scripts/gen-skill-docs.ts # scripts/proactive-suggestions.json # spec/SKILL.md # test/gen-skill-docs.test.ts # test/host-config.test.ts
This commit is contained in:
@@ -1,5 +1,13 @@
|
||||
name: Workflow Lint
|
||||
on: [push, pull_request]
|
||||
|
||||
# Cancel superseded runs for the same branch (matches evals.yml,
|
||||
# windows-free-tests.yml, etc.). head_ref is set on pull_request; ref_name is
|
||||
# the fallback for push so a rapid push series doesn't pile up stale lint runs.
|
||||
concurrency:
|
||||
group: actionlint-${{ github.head_ref || github.ref_name }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
actionlint:
|
||||
runs-on: ubicloud-standard-8
|
||||
|
||||
@@ -45,19 +45,30 @@ jobs:
|
||||
- if: steps.check.outputs.exists == 'false'
|
||||
run: cp package.json bun.lock .github/docker/
|
||||
|
||||
# A fork PR's GITHUB_TOKEN only has `packages: read`, so pushing fails.
|
||||
# Still BUILD (validates Dockerfile.ci changes), just don't publish. This
|
||||
# job intentionally keeps no `if:` so fork PRs still get one real, honest
|
||||
# green check here instead of a run where every job is grey.
|
||||
- if: steps.check.outputs.exists == 'false'
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: .github/docker
|
||||
file: .github/docker/Dockerfile.ci
|
||||
push: true
|
||||
push: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
|
||||
tags: |
|
||||
${{ steps.meta.outputs.tag }}
|
||||
${{ env.IMAGE }}:latest
|
||||
|
||||
# Fork PRs never receive repository secrets (ANTHROPIC_API_KEY et al), so every
|
||||
# API-calling eval fails at SDK auth before a model runs. Skip deterministically
|
||||
# rather than leaving the outcome to Docker-cache luck: a warm cache let these
|
||||
# run and fail, a cold one made build-image fail its push and the shards skip.
|
||||
# Same-repo PRs, pushes, and workflow_dispatch keep full coverage. Fork work
|
||||
# gets real coverage via a trusted base-repo branch.
|
||||
evals:
|
||||
runs-on: ${{ matrix.suite.runner || 'ubicloud-standard-8' }}
|
||||
needs: build-image
|
||||
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
|
||||
container:
|
||||
image: ${{ needs.build-image.outputs.image-tag }}
|
||||
credentials:
|
||||
@@ -276,7 +287,7 @@ jobs:
|
||||
report:
|
||||
runs-on: ubicloud-standard-8
|
||||
needs: evals
|
||||
if: always() && github.event_name == 'pull_request'
|
||||
if: always() && github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository
|
||||
timeout-minutes: 5
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
@@ -1,5 +1,13 @@
|
||||
name: Skill Docs Freshness
|
||||
on: [push, pull_request]
|
||||
|
||||
# Cancel superseded runs for the same branch (matches evals.yml,
|
||||
# windows-free-tests.yml, etc.). head_ref is set on pull_request; ref_name is
|
||||
# the fallback for push so a rapid push series doesn't pile up stale runs.
|
||||
concurrency:
|
||||
group: skill-docs-${{ github.head_ref || github.ref_name }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
check-freshness:
|
||||
runs-on: ubicloud-standard-8
|
||||
|
||||
Reference in New Issue
Block a user