Skip to content

Merge pull request #102 from kev1n77/codex/agent-auto-config-i18n #229

Merge pull request #102 from kev1n77/codex/agent-auto-config-i18n

Merge pull request #102 from kev1n77/codex/agent-auto-config-i18n #229

Workflow file for this run

name: CI
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
desktop-frontend:
name: Desktop frontend
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24"
cache: npm
- name: Install desktop dependencies
run: npm ci
- name: Install Chromium for desktop quality checks
run: npx playwright install --with-deps chromium
- name: Check desktop frontend
run: npm run desktop:check
- name: Build desktop frontend
run: npm run desktop:build
- name: Run desktop visual and performance checks
run: npm run desktop:e2e
- name: Upload desktop browser report
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: desktop-browser-report
path: |
apps/desktop/playwright-report
apps/desktop/test-results
if-no-files-found: ignore
retention-days: 14
desktop-native:
name: Desktop native (${{ matrix.os }})
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [windows-latest, macos-latest]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install Rust toolchain
run: rustup show
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2.9.1
with:
workspaces: apps/desktop/src-tauri -> apps/desktop/src-tauri/target
- name: Check desktop formatting
run: cargo fmt --manifest-path apps/desktop/src-tauri/Cargo.toml -- --check
- name: Test desktop native shell
run: cargo test --manifest-path apps/desktop/src-tauri/Cargo.toml
- name: Check desktop native shell
run: cargo check --manifest-path apps/desktop/src-tauri/Cargo.toml
rust:
name: Rust (${{ matrix.os }})
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install Rust toolchain
run: rustup show
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2.9.1
- name: Check formatting
if: runner.os == 'Linux'
run: cargo fmt --all -- --check
- name: Run tests
run: cargo test --workspace --all-targets
- name: Enforce Gateway latency budget
if: runner.os == 'Linux'
run: cargo test -p codeischeap-gateway --test performance -- --ignored --nocapture --test-threads=1
- name: Run real OS credential store experiment
if: runner.os == 'Windows' || runner.os == 'macOS'
run: cargo test -p codeischeap-storage --test os_key_store real_os_key_store_round_trip -- --ignored --exact --nocapture
- name: Run real WinINet recovery experiment
if: runner.os == 'Windows'
run: cargo test -p codeischeap-proxy-recovery --test windows_registry real_windows_proxy_is_restored_after_force_kill -- --ignored --exact --nocapture --test-threads=1
- name: Run Clippy
run: cargo clippy --workspace --all-targets -- -D warnings
- name: Run real macOS networksetup recovery experiment
if: runner.os == 'macOS'
run: |
cargo build -p codeischeap-proxy-recovery --bins
sudo target/debug/proxy-recovery-macos-experiment
sidecar:
name: Sidecar (${{ matrix.os }})
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
cache: pip
cache-dependency-path: |
sidecars/mitmproxy/requirements.txt
sidecars/mitmproxy/requirements-build.txt
- name: Install pinned sidecar toolchain
run: python -m pip install -r sidecars/mitmproxy/requirements-build.txt
- name: Run addon tests
run: python -m unittest discover -s sidecars/mitmproxy/tests -v
- name: Package and probe sidecar
run: python sidecars/mitmproxy/package_sidecar.py
- name: Validate sidecar bundle contract
run: python sidecars/mitmproxy/verify_sidecar_bundle.py sidecars/mitmproxy/dist
- name: Exercise atomic sidecar installation
run: python sidecars/mitmproxy/install_sidecar_bundle.py sidecars/mitmproxy/dist ${{ runner.temp }}/codeischeap-sidecar
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: sidecar-bundle-${{ runner.os }}-${{ runner.arch }}
path: sidecars/mitmproxy/dist/*
if-no-files-found: error
retention-days: 14
supply-chain:
name: Supply chain policy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Verify repository supply chain policy
run: python scripts/verify_supply_chain.py
- name: Validate release readiness contract
run: python scripts/verify_release_readiness.py --repository-root . --allow-pending
- name: Test release and supply-chain tooling
run: python -m unittest discover -s scripts/tests -v
- name: Reject newly introduced vulnerable dependencies
if: github.event_name == 'pull_request'
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
with:
fail-on-severity: high