Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -35,3 +35,6 @@ docs/
.idea/
*.swp
.DS_Store

# Sibling repo checked out into the workspace by CI — must never reach the image.
/aurora-sensor-agent/
13 changes: 13 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -158,6 +158,14 @@ jobs:
- uses: actions/checkout@v7
with:
fetch-depth: 0 # need the base commit for the oasdiff comparison
# Cross-repo telemetry drift needs the device repo. Set the DEVICE_REPO variable (e.g.
# owner/aurora-sensor-agent) to enable it; without it the job runs the in-repo checksum
# guard only and stays green, so a fork with no variables set still passes.
- if: vars.DEVICE_REPO != ''
uses: actions/checkout@v7
with:
repository: ${{ vars.DEVICE_REPO }}
path: aurora-sensor-agent
- uses: ./.github/actions/setup-python-uv
# 1. Drift: the served schema must equal the committed contracts/openapi.json.
- name: OpenAPI drift check
Expand All @@ -166,6 +174,11 @@ jobs:
# checksums (and, when the device repo is checked out alongside, be byte-identical to its
# source). The OpenAPI gate in reverse — spec §8 rule 4.
- name: Telemetry contract drift check
env:
# Set: the sibling checkout above lands at <workspace>/aurora-sensor-agent.
# Unset (a fork): falls back to ../, which is absent in CI, so the script skips the
# cross-repo half and keeps the in-repo checksum guard. ../ is also the local-dev layout.
AURORA_DEVICE_REPO: ${{ vars.DEVICE_REPO != '' && 'aurora-sensor-agent' || '../aurora-sensor-agent' }}
run: uv run python scripts/check_telemetry_contract.py
- name: Publish OpenAPI as a build artifact
uses: actions/upload-artifact@v7
Expand Down
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -37,3 +37,6 @@ _*.log
.vscode/
*.swp
.DS_Store

# Sibling repo checked out into the workspace by CI (cross-repo contract drift gate).
/aurora-sensor-agent/
15 changes: 15 additions & 0 deletions .gitleaksignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Gitleaks findings reviewed and accepted, one fingerprint per line.
#
# Scope note: on a pull request the gitleaks action scans only the pushed commits, so these
# historical findings are invisible there. On workflow_dispatch — and for anyone who clones the
# repo and runs `gitleaks detect` — it scans the full history and surfaces them. This file exists
# so a full-history scan is clean too, rather than the repo merely appearing clean because of
# where the scan happened to look.
#
# Each entry must be a reviewed false positive, never a real credential that has been rotated:
# a committed secret stays in the history and must be revoked at the source, not ignored here.

# tests/integration/test_webhooks_api.py:27 — the webhook subscription fixture's signing secret,
# the literal "0123456789abcdef". A sequential hex string written to be readable in test output;
# it signs nothing outside the test process. Flagged by the generic-api-key rule on entropy alone.
7a2b78bba835061243e0d8b24acdffd09ffec1d0:tests/integration/test_webhooks_api.py:generic-api-key:27
4 changes: 3 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,9 @@ make stack-up # Postgres + Redis + the API on http://localhost:8000
make seed # demo users, clinic, clinician, service
```

Demo login: `admin@aurora-clinic.com` / `password123` (local demo only).
Demo login: `admin@aurora-clinic.com` / `password123` (local demo only). The browser demo uses
different addresses (`admin@aurora.test`) because it runs on the mock API; this one rejects the
reserved `.test` TLD.

| Tool | How | Notes |
|---|---|---|
Expand Down
5 changes: 5 additions & 0 deletions docs/KNOWN_GAPS.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,11 @@ CI/CD in milestone 11.

## CI/CD: what could not be executed in this environment (milestone 6)

**Every gate that can run without a cloud account runs on every pull request** — lint, typecheck,
unit, integration against real Postgres and Redis, contract, coverage, build, security scanning,
and CodeQL. The list below is only the deploy path, which needs infrastructure this environment
does not have.

The workflows are complete and statically valid (`actionlint` + `yamllint` pass locally, wired into
`make ci-local`). What could not be *run* here, and why:

Expand Down
4 changes: 2 additions & 2 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -32,8 +32,8 @@ dependencies = [

[project.optional-dependencies]
dev = [
"pytest>=8.3,<9",
"pytest-asyncio>=0.24,<0.25",
"pytest>=9.0.3,<10",
"pytest-asyncio>=1.0,<2",
"pytest-cov>=5.0,<8",
"pytest-mock>=3.14,<4",
"pytest-xdist>=3.6,<4",
Expand Down
17 changes: 9 additions & 8 deletions uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading