Merge pull request #102 from kev1n77/codex/agent-auto-config-i18n #229
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ci-${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| desktop-frontend: | |
| name: Desktop frontend | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: "24" | |
| cache: npm | |
| - name: Install desktop dependencies | |
| run: npm ci | |
| - name: Install Chromium for desktop quality checks | |
| run: npx playwright install --with-deps chromium | |
| - name: Check desktop frontend | |
| run: npm run desktop:check | |
| - name: Build desktop frontend | |
| run: npm run desktop:build | |
| - name: Run desktop visual and performance checks | |
| run: npm run desktop:e2e | |
| - name: Upload desktop browser report | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: desktop-browser-report | |
| path: | | |
| apps/desktop/playwright-report | |
| apps/desktop/test-results | |
| if-no-files-found: ignore | |
| retention-days: 14 | |
| desktop-native: | |
| name: Desktop native (${{ matrix.os }}) | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [windows-latest, macos-latest] | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Install Rust toolchain | |
| run: rustup show | |
| - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2.9.1 | |
| with: | |
| workspaces: apps/desktop/src-tauri -> apps/desktop/src-tauri/target | |
| - name: Check desktop formatting | |
| run: cargo fmt --manifest-path apps/desktop/src-tauri/Cargo.toml -- --check | |
| - name: Test desktop native shell | |
| run: cargo test --manifest-path apps/desktop/src-tauri/Cargo.toml | |
| - name: Check desktop native shell | |
| run: cargo check --manifest-path apps/desktop/src-tauri/Cargo.toml | |
| rust: | |
| name: Rust (${{ matrix.os }}) | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, windows-latest, macos-latest] | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Install Rust toolchain | |
| run: rustup show | |
| - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2.9.1 | |
| - name: Check formatting | |
| if: runner.os == 'Linux' | |
| run: cargo fmt --all -- --check | |
| - name: Run tests | |
| run: cargo test --workspace --all-targets | |
| - name: Enforce Gateway latency budget | |
| if: runner.os == 'Linux' | |
| run: cargo test -p codeischeap-gateway --test performance -- --ignored --nocapture --test-threads=1 | |
| - name: Run real OS credential store experiment | |
| if: runner.os == 'Windows' || runner.os == 'macOS' | |
| run: cargo test -p codeischeap-storage --test os_key_store real_os_key_store_round_trip -- --ignored --exact --nocapture | |
| - name: Run real WinINet recovery experiment | |
| if: runner.os == 'Windows' | |
| run: cargo test -p codeischeap-proxy-recovery --test windows_registry real_windows_proxy_is_restored_after_force_kill -- --ignored --exact --nocapture --test-threads=1 | |
| - name: Run Clippy | |
| run: cargo clippy --workspace --all-targets -- -D warnings | |
| - name: Run real macOS networksetup recovery experiment | |
| if: runner.os == 'macOS' | |
| run: | | |
| cargo build -p codeischeap-proxy-recovery --bins | |
| sudo target/debug/proxy-recovery-macos-experiment | |
| sidecar: | |
| name: Sidecar (${{ matrix.os }}) | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, windows-latest, macos-latest] | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.12" | |
| cache: pip | |
| cache-dependency-path: | | |
| sidecars/mitmproxy/requirements.txt | |
| sidecars/mitmproxy/requirements-build.txt | |
| - name: Install pinned sidecar toolchain | |
| run: python -m pip install -r sidecars/mitmproxy/requirements-build.txt | |
| - name: Run addon tests | |
| run: python -m unittest discover -s sidecars/mitmproxy/tests -v | |
| - name: Package and probe sidecar | |
| run: python sidecars/mitmproxy/package_sidecar.py | |
| - name: Validate sidecar bundle contract | |
| run: python sidecars/mitmproxy/verify_sidecar_bundle.py sidecars/mitmproxy/dist | |
| - name: Exercise atomic sidecar installation | |
| run: python sidecars/mitmproxy/install_sidecar_bundle.py sidecars/mitmproxy/dist ${{ runner.temp }}/codeischeap-sidecar | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: sidecar-bundle-${{ runner.os }}-${{ runner.arch }} | |
| path: sidecars/mitmproxy/dist/* | |
| if-no-files-found: error | |
| retention-days: 14 | |
| supply-chain: | |
| name: Supply chain policy | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.12" | |
| - name: Verify repository supply chain policy | |
| run: python scripts/verify_supply_chain.py | |
| - name: Validate release readiness contract | |
| run: python scripts/verify_release_readiness.py --repository-root . --allow-pending | |
| - name: Test release and supply-chain tooling | |
| run: python -m unittest discover -s scripts/tests -v | |
| - name: Reject newly introduced vulnerable dependencies | |
| if: github.event_name == 'pull_request' | |
| uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0 | |
| with: | |
| fail-on-severity: high |