Skip to content

Commit eb5e8ab

Browse files
authored
Merge pull request #188 from QuantStrategyLab/codex/minimize-review-secrets-20260710
fix(ci): minimize Codex review privileges
2 parents f791345 + 7214210 commit eb5e8ab

4 files changed

Lines changed: 44 additions & 20 deletions

File tree

.github/workflows/codex_pr_review.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,8 @@ jobs:
2323
allow_unconfigured_backend: false
2424
api_fallback_enabled: "false"
2525
direct_api_primary_enabled: "false"
26-
secrets: inherit
26+
secrets:
27+
CODEX_AUDIT_SERVICE_URL: ${{ secrets.CODEX_AUDIT_SERVICE_URL }}
2728
permissions:
2829
contents: read
2930
id-token: write

.github/workflows/codex_review_gate.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ permissions:
2323
pull-requests: read
2424

2525
concurrency:
26-
group: codex-review-gate-${{ github.event.pull_request.number }}
26+
group: codex-review-gate-${{ github.event.pull_request.number }}-${{ github.event_name }}
2727
cancel-in-progress: true
2828

2929
jobs:

internal_dependency_matrix.json

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313
"path": "pyproject.toml",
1414
"package": "quant-platform-kit",
1515
"source_repo": "QuantPlatformKit",
16-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
16+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
1717
},
1818
{
1919
"consumer_repo": "BinancePlatform",
@@ -27,14 +27,14 @@
2727
"path": "uv.lock",
2828
"package": "quant-platform-kit",
2929
"source_repo": "QuantPlatformKit",
30-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
30+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
3131
},
3232
{
3333
"consumer_repo": "CharlesSchwabPlatform",
3434
"path": "pyproject.toml",
3535
"package": "quant-platform-kit",
3636
"source_repo": "QuantPlatformKit",
37-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
37+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
3838
},
3939
{
4040
"consumer_repo": "CharlesSchwabPlatform",
@@ -48,7 +48,7 @@
4848
"path": "uv.lock",
4949
"package": "quant-platform-kit",
5050
"source_repo": "QuantPlatformKit",
51-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
51+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
5252
},
5353
{
5454
"consumer_repo": "CharlesSchwabPlatform",
@@ -76,14 +76,14 @@
7676
"path": "pyproject.toml",
7777
"package": "quant-platform-kit",
7878
"source_repo": "QuantPlatformKit",
79-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
79+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
8080
},
8181
{
8282
"consumer_repo": "CnEquityStrategies",
8383
"path": "uv.lock",
8484
"package": "quant-platform-kit",
8585
"source_repo": "QuantPlatformKit",
86-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
86+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
8787
},
8888
{
8989
"consumer_repo": "CryptoLivePoolPipelines",
@@ -118,21 +118,21 @@
118118
"path": "pyproject.toml",
119119
"package": "quant-platform-kit",
120120
"source_repo": "QuantPlatformKit",
121-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
121+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
122122
},
123123
{
124124
"consumer_repo": "CryptoStrategies",
125125
"path": "uv.lock",
126126
"package": "quant-platform-kit",
127127
"source_repo": "QuantPlatformKit",
128-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
128+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
129129
},
130130
{
131131
"consumer_repo": "FirstradePlatform",
132132
"path": "pyproject.toml",
133133
"package": "quant-platform-kit",
134134
"source_repo": "QuantPlatformKit",
135-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
135+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
136136
},
137137
{
138138
"consumer_repo": "FirstradePlatform",
@@ -146,7 +146,7 @@
146146
"path": "uv.lock",
147147
"package": "quant-platform-kit",
148148
"source_repo": "QuantPlatformKit",
149-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
149+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
150150
},
151151
{
152152
"consumer_repo": "FirstradePlatform",
@@ -174,14 +174,14 @@
174174
"path": "pyproject.toml",
175175
"package": "quant-platform-kit",
176176
"source_repo": "QuantPlatformKit",
177-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
177+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
178178
},
179179
{
180180
"consumer_repo": "HkEquityStrategies",
181181
"path": "uv.lock",
182182
"package": "quant-platform-kit",
183183
"source_repo": "QuantPlatformKit",
184-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
184+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
185185
},
186186
{
187187
"consumer_repo": "InteractiveBrokersPlatform",
@@ -195,7 +195,7 @@
195195
"path": "pyproject.toml",
196196
"package": "quant-platform-kit",
197197
"source_repo": "QuantPlatformKit",
198-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
198+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
199199
},
200200
{
201201
"consumer_repo": "InteractiveBrokersPlatform",
@@ -216,7 +216,7 @@
216216
"path": "uv.lock",
217217
"package": "quant-platform-kit",
218218
"source_repo": "QuantPlatformKit",
219-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
219+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
220220
},
221221
{
222222
"consumer_repo": "InteractiveBrokersPlatform",
@@ -237,7 +237,7 @@
237237
"path": "pyproject.toml",
238238
"package": "quant-platform-kit",
239239
"source_repo": "QuantPlatformKit",
240-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
240+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
241241
},
242242
{
243243
"consumer_repo": "LongBridgePlatform",
@@ -258,7 +258,7 @@
258258
"path": "uv.lock",
259259
"package": "quant-platform-kit",
260260
"source_repo": "QuantPlatformKit",
261-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
261+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
262262
},
263263
{
264264
"consumer_repo": "LongBridgePlatform",
@@ -342,14 +342,14 @@
342342
"path": "pyproject.toml",
343343
"package": "quant-platform-kit",
344344
"source_repo": "QuantPlatformKit",
345-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
345+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
346346
},
347347
{
348348
"consumer_repo": "UsEquityStrategies",
349349
"path": "uv.lock",
350350
"package": "quant-platform-kit",
351351
"source_repo": "QuantPlatformKit",
352-
"ref": "69a0256934d081b5ef309a885384b9eb9f62cf90"
352+
"ref": "2381aa4577e9fd6329053a73a1c888929170eaf3"
353353
}
354354
]
355355
}

python/tests/test_internal_dependency_matrix.py

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -99,6 +99,29 @@ def test_current_matrix_matches_local_workspace(self):
9999
self.assertEqual(report.missing_files, [])
100100
self.assertEqual(report.issues, [])
101101

102+
def test_qpk_rollout_consumers_use_canonical_pin(self):
103+
canonical_pin = "2381aa4577e9fd6329053a73a1c888929170eaf3"
104+
rollout_consumers = {
105+
"BinancePlatform",
106+
"CharlesSchwabPlatform",
107+
"CnEquityStrategies",
108+
"CryptoStrategies",
109+
"FirstradePlatform",
110+
"HkEquityStrategies",
111+
"InteractiveBrokersPlatform",
112+
"LongBridgePlatform",
113+
"UsEquityStrategies",
114+
}
115+
matrix_pins = check_internal_dependency_matrix.load_matrix(ROOT / "internal_dependency_matrix.json")
116+
refs = {
117+
(pin.consumer_repo, pin.path): pin.ref
118+
for pin in matrix_pins
119+
if pin.consumer_repo in rollout_consumers and pin.source_repo == "QuantPlatformKit"
120+
}
121+
122+
self.assertEqual(len(refs), len(rollout_consumers) * 2)
123+
self.assertEqual(set(refs.values()), {canonical_pin})
124+
102125
def test_require_consumer_files_treats_missing_paths_as_issues(self):
103126
projects_root = self._make_projects_root({})
104127
expected = [

0 commit comments

Comments
 (0)