Skip to content

refactor(agentInfraCost): thread repo context, health port and enrich… #122

refactor(agentInfraCost): thread repo context, health port and enrich…

refactor(agentInfraCost): thread repo context, health port and enrich… #122

Workflow file for this run

name: CI
# Was a deliberately lenient Sprint 1 skeleton (continue-on-error
# everywhere, so the pipeline stayed green while most modules were still
# mocks). Hardened per T-5.6/T-5.7: lint/type-check/test/build failures now
# fail the job for real. As of this change that means CI is red on this
# branch until the ~912 pre-existing ruff findings (`ruff check src/
# --fix` resolves most of them) and any real test/type failures are
# addressed -- known and expected, not a regression introduced here.
on:
push:
branches: ["main", "master", "feature/**"]
pull_request:
branches: ["main", "master"]
jobs:
secrets-scan:
name: Secrets scan (gitleaks)
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0 # gitleaks needs full history to scan past commits, not just the current tree
- name: Run gitleaks
uses: gitleaks/gitleaks-action@v2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# No continue-on-error here on purpose: unlike the lint/test jobs
# below (Sprint 1, most modules still mocks), a real committed
# secret is a real incident regardless of what sprint it is.
backend-lint-and-test:
name: Backend (Python) - lint & test
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
cache: "pip"
- name: Install dependencies
run: |
pip install --upgrade pip
pip install -r requirements.txt
# requirements.txt already pins pytest/ruff/mypy/qdrant-client/
# google-generativeai -- this used to re-list them by hand as a
# separate step; now redundant, dropped.
- name: Lint (ruff)
run: ruff check src/
- name: Type check (mypy)
run: mypy src/
- name: Set JWT secret (fail-fast requires non-empty)
run: echo "SECRET_KEY=$(openssl rand -hex 32)" >> "$GITHUB_ENV"
- name: Run tests (pytest)
run: pytest --continue-on-collection-errors --disable-warnings -q
frontend-lint-and-build:
name: Frontend (React) - lint & build
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
# BUGFIX v1.1: actions/setup-node's cache-dependency-path used to
# point at src/frontend/package-lock.json unconditionally. Until
# T-1.16 (Karim) creates src/frontend/, that file doesn't exist,
# and setup-node's cache resolution step FAILS HARD at this point -
# continue-on-error on the later steps (install/lint/build) never
# even gets a chance to run, because Set up Node itself errors out.
# Fix: check the folder exists first, and skip the rest of this
# job's steps entirely (via `if:`) when it doesn't, instead of
# relying on continue-on-error to catch a failure it can't reach.
- name: Check if frontend exists
id: check_frontend
run: |
if [ -f "src/frontend/package.json" ]; then
echo "exists=true" >> "$GITHUB_OUTPUT"
else
echo "exists=false" >> "$GITHUB_OUTPUT"
echo "::warning::src/frontend/package.json not found yet (T-1.16 not done) - skipping frontend CI job"
fi
- name: Set up Node
if: steps.check_frontend.outputs.exists == 'true'
uses: actions/setup-node@v4
with:
node-version: "20"
cache: "npm"
cache-dependency-path: src/frontend/package-lock.json
- name: Install dependencies
if: steps.check_frontend.outputs.exists == 'true'
working-directory: src/frontend
run: npm ci
- name: Lint (ESLint)
if: steps.check_frontend.outputs.exists == 'true'
working-directory: src/frontend
run: npm run lint
- name: Build
if: steps.check_frontend.outputs.exists == 'true'
working-directory: src/frontend
run: npm run build