refactor(agentInfraCost): thread repo context, health port and enrich… #122
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| # Was a deliberately lenient Sprint 1 skeleton (continue-on-error | |
| # everywhere, so the pipeline stayed green while most modules were still | |
| # mocks). Hardened per T-5.6/T-5.7: lint/type-check/test/build failures now | |
| # fail the job for real. As of this change that means CI is red on this | |
| # branch until the ~912 pre-existing ruff findings (`ruff check src/ | |
| # --fix` resolves most of them) and any real test/type failures are | |
| # addressed -- known and expected, not a regression introduced here. | |
| on: | |
| push: | |
| branches: ["main", "master", "feature/**"] | |
| pull_request: | |
| branches: ["main", "master"] | |
| jobs: | |
| secrets-scan: | |
| name: Secrets scan (gitleaks) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 # gitleaks needs full history to scan past commits, not just the current tree | |
| - name: Run gitleaks | |
| uses: gitleaks/gitleaks-action@v2 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| # No continue-on-error here on purpose: unlike the lint/test jobs | |
| # below (Sprint 1, most modules still mocks), a real committed | |
| # secret is a real incident regardless of what sprint it is. | |
| backend-lint-and-test: | |
| name: Backend (Python) - lint & test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Set up Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.12" | |
| cache: "pip" | |
| - name: Install dependencies | |
| run: | | |
| pip install --upgrade pip | |
| pip install -r requirements.txt | |
| # requirements.txt already pins pytest/ruff/mypy/qdrant-client/ | |
| # google-generativeai -- this used to re-list them by hand as a | |
| # separate step; now redundant, dropped. | |
| - name: Lint (ruff) | |
| run: ruff check src/ | |
| - name: Type check (mypy) | |
| run: mypy src/ | |
| - name: Set JWT secret (fail-fast requires non-empty) | |
| run: echo "SECRET_KEY=$(openssl rand -hex 32)" >> "$GITHUB_ENV" | |
| - name: Run tests (pytest) | |
| run: pytest --continue-on-collection-errors --disable-warnings -q | |
| frontend-lint-and-build: | |
| name: Frontend (React) - lint & build | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| # BUGFIX v1.1: actions/setup-node's cache-dependency-path used to | |
| # point at src/frontend/package-lock.json unconditionally. Until | |
| # T-1.16 (Karim) creates src/frontend/, that file doesn't exist, | |
| # and setup-node's cache resolution step FAILS HARD at this point - | |
| # continue-on-error on the later steps (install/lint/build) never | |
| # even gets a chance to run, because Set up Node itself errors out. | |
| # Fix: check the folder exists first, and skip the rest of this | |
| # job's steps entirely (via `if:`) when it doesn't, instead of | |
| # relying on continue-on-error to catch a failure it can't reach. | |
| - name: Check if frontend exists | |
| id: check_frontend | |
| run: | | |
| if [ -f "src/frontend/package.json" ]; then | |
| echo "exists=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "exists=false" >> "$GITHUB_OUTPUT" | |
| echo "::warning::src/frontend/package.json not found yet (T-1.16 not done) - skipping frontend CI job" | |
| fi | |
| - name: Set up Node | |
| if: steps.check_frontend.outputs.exists == 'true' | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: "npm" | |
| cache-dependency-path: src/frontend/package-lock.json | |
| - name: Install dependencies | |
| if: steps.check_frontend.outputs.exists == 'true' | |
| working-directory: src/frontend | |
| run: npm ci | |
| - name: Lint (ESLint) | |
| if: steps.check_frontend.outputs.exists == 'true' | |
| working-directory: src/frontend | |
| run: npm run lint | |
| - name: Build | |
| if: steps.check_frontend.outputs.exists == 'true' | |
| working-directory: src/frontend | |
| run: npm run build |