Slop csharp #32
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: AI Slop Gate Compliance Analysis | |
| on: | |
| pull_request: | |
| branches: [ main ] | |
| push: | |
| branches: [ main ] | |
| workflow_dispatch: | |
| permissions: | |
| pull-requests: write | |
| contents: read | |
| jobs: | |
| compliance-analysis: | |
| runs-on: ubuntu-22.04 | |
| timeout-minutes: 20 | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Cache ai-slop-gate cache directory | |
| uses: actions/cache@v4 | |
| with: | |
| path: ~/.cache/ai-slop-gate | |
| key: ai-slop-gate-cache-${{ runner.os }}-${{ hashFiles('**/*.py', '**/*.yml', '**/*.yaml') }} | |
| restore-keys: | | |
| ai-slop-gate-cache-${{ runner.os }}- | |
| # Run compliance analysis | |
| - name: Compliance Analysis (ai-slop-gate) | |
| id: compliance_gate | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| continue-on-error: true | |
| run: | | |
| mkdir -p ~/.cache/ai-slop-gate | |
| # Check if policy.yml exists, otherwise use default | |
| POLICY_FLAG="" | |
| if [ -f "${{ github.workspace }}/policy.yml" ]; then | |
| echo "📋 Using custom policy.yml" | |
| POLICY_FLAG="--policy /data/policy.yml" | |
| else | |
| echo "📋 Using default policy" | |
| fi | |
| # Run compliance check and capture output (don't fail on non-zero exit) | |
| set +e # Disable exit on error temporarily | |
| docker run --rm \ | |
| -v "${{ github.workspace }}:/data" \ | |
| -v ~/.cache/ai-slop-gate:/root/.cache/ai-slop-gate \ | |
| -e GITHUB_TOKEN \ | |
| ghcr.io/sergudo/ai-slop-gate:latest \ | |
| run --compliance $POLICY_FLAG --path /data > raw_report.txt 2>&1 | |
| EXIT_CODE=$? | |
| set -e # Re-enable exit on error | |
| # Always show report | |
| cat raw_report.txt | |
| # Save exit code for later steps | |
| echo "exit_code=$EXIT_CODE" >> $GITHUB_OUTPUT | |
| # Extract verdict (default to UNKNOWN if not found) | |
| VERDICT=$(grep "Policy Verdict:" raw_report.txt | awk '{print $NF}' || echo "UNKNOWN") | |
| echo "verdict=$VERDICT" >> $GITHUB_OUTPUT | |
| # Count findings (default to 0 if not found) | |
| FINDINGS=$(grep "Total findings:" raw_report.txt | awk '{print $NF}' || echo "0") | |
| echo "findings=$FINDINGS" >> $GITHUB_OUTPUT | |
| # Log extracted values | |
| echo "📊 Extracted values:" | |
| echo " Exit code: $EXIT_CODE" | |
| echo " Verdict: $VERDICT" | |
| echo " Findings: $FINDINGS" | |
| # Don't fail here - let continue-on-error handle it | |
| exit 0 | |
| # Post comment on PR (always, not just on failure) | |
| - name: Post Compliance Report to PR | |
| if: github.event_name == 'pull_request' && always() | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| # Extract clean report (fix sed pattern) | |
| sed -n '/=== AI SLOP GATE REPORT ===/,/=== END OF REPORT ===/p' raw_report.txt > clean_report.md | |
| # Check if report was extracted | |
| if [ ! -s clean_report.md ]; then | |
| echo "⚠️ Warning: Could not extract report from raw_report.txt" | |
| echo "=== NO REPORT GENERATED ===" > clean_report.md | |
| echo "The compliance check may have failed to run properly." >> clean_report.md | |
| fi | |
| # Get values with defaults | |
| VERDICT="${{ steps.compliance_gate.outputs.verdict }}" | |
| FINDINGS="${{ steps.compliance_gate.outputs.findings }}" | |
| # Set defaults if empty | |
| VERDICT="${VERDICT:-UNKNOWN}" | |
| FINDINGS="${FINDINGS:-0}" | |
| echo "📊 Report values:" | |
| echo " Verdict: $VERDICT" | |
| echo " Findings: $FINDINGS" | |
| # Determine emoji and status based on verdict | |
| if [ "$VERDICT" = "BLOCKING" ]; then | |
| EMOJI="🚨" | |
| STATUS="**BLOCKING** - Action Required" | |
| elif [ "$VERDICT" = "ADVISORY" ]; then | |
| EMOJI="⚠️" | |
| STATUS="**ADVISORY** - Review Recommended" | |
| elif [ "$VERDICT" = "ALLOW" ]; then | |
| EMOJI="✅" | |
| STATUS="**PASSED** - No Issues Found" | |
| else | |
| EMOJI="❓" | |
| STATUS="**UNKNOWN** - Check logs" | |
| fi | |
| # Create professional comment | |
| cat > final_comment.md << EOF | |
| ## $EMOJI AI Slop Gate Compliance Analysis | |
| **Status:** $STATUS | |
| **Findings:** $FINDINGS issue(s) detected | |
| --- | |
| EOF | |
| # Append the clean report | |
| cat clean_report.md >> final_comment.md | |
| # Add footer with fix guide ONLY if there are violations | |
| if [ "$FINDINGS" != "0" ] && [ "$VERDICT" != "ALLOW" ]; then | |
| cat >> final_comment.md << EOF | |
| --- | |
| <details> | |
| <summary>📚 How to fix violations</summary> | |
| ### License Violations (GPL/AGPL) | |
| 1. Remove the dependency or find an alternative with a permissive license | |
| 2. If the dependency is necessary, consult with legal team | |
| 3. Add to \`.trivyignore\` only if approved by compliance team | |
| ### Data Residency Violations | |
| 1. Ensure all endpoints use EU regions | |
| 2. Update configuration to use \`eu-west-1\`, \`eu-central-1\`, etc. | |
| 3. Remove references to US/AP regions | |
| </details> | |
| EOF | |
| fi | |
| # Always add footer | |
| cat >> final_comment.md << EOF | |
| <sub>🤖 Powered by [AI Slop Gate](https://github.com/SergUdo/ai-slop-gate) | Run: \`${{ github.run_id }}\`</sub> | |
| EOF | |
| # Post comment | |
| gh pr comment ${{ github.event.pull_request.number }} \ | |
| --body-file final_comment.md \ | |
| --repo ${{ github.repository }} | |
| # Set job status based on verdict | |
| - name: Check Compliance Result | |
| if: steps.compliance_gate.outputs.verdict == 'BLOCKING' | |
| run: | | |
| echo "❌ Compliance analysis found blocking violations" | |
| exit 1 | |