Skip to content

v2.0.0-20260715165359 #6

v2.0.0-20260715165359

v2.0.0-20260715165359 #6

Workflow file for this run

name: Release publish
on:
release:
types: [published]
workflow_dispatch:
inputs:
tag:
description: "Release tag to verify and publish, e.g. v1.0.0-20260709224500"
required: true
# Least privilege: the job reads the repo and downloads the release asset. The HF
# token is exposed only to the publish step.
permissions:
contents: read
env:
TAG: ${{ github.event.release.tag_name || inputs.tag }}
jobs:
# Runs automatically on the release: no token, no environment, fast feedback.
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: 1.3.14
- name: Download release asset
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release download "$TAG" --repo "${{ github.repository }}" \
--pattern 'curtain-model-*.tar.gz' --pattern 'SHA256SUMS' --dir dl
mkdir -p model && tar -xzf dl/curtain-model-*.tar.gz -C model
- name: Verify model_q4.onnx SHA-256 against SHA256SUMS
run: |
EXPECTED=$(grep 'model_q4.onnx' dl/SHA256SUMS | awk '{print $1}')
ACTUAL=$(sha256sum model/onnx/model_q4.onnx | awk '{print $1}')
echo "expected=$EXPECTED actual=$ACTUAL"
test "$EXPECTED" = "$ACTUAL"
- run: bun install --frozen-lockfile
# bench-30k is not run here: its held-out data is gitignored. real-157 and
# fairness (the absolute over-redaction gates) run through onnxruntime-web
# via eval:wasm: the WASM backend is one deterministic binary, identical to
# what browser consumers run, whereas native onnxruntime over-redaction is
# platform-specific (Linux differs from macOS). No browser is needed; ort-web
# runs the model directly under bun. adversarial is a same-backend coverage
# comparison, so it is platform-robust on native cpu.
- name: Quality gates on the built artifact
env:
# Absolute path: transformers.js treats a bare name like "model" as a
# Hugging Face hub id and tries to fetch it. A path makes it load locally.
CURTAIN_MODEL: ${{ github.workspace }}/model
run: |
bun run eval:wasm
bun run eval:adversarial
# Gated by the hf-release environment: its required-reviewers rule pauses here
# for manual approval, its v* tag rule restricts it to release tags, and the
# HF_TOKEN environment secret is available only to this job. Runs only after
# verify succeeds.
publish:
needs: verify
runs-on: ubuntu-latest
environment: hf-release
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
- name: Download the verified release asset
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release download "$TAG" --repo "${{ github.repository }}" \
--pattern 'curtain-model-*.tar.gz' --pattern 'SHA256SUMS' --dir dl
mkdir -p model && tar -xzf dl/curtain-model-*.tar.gz -C model
- name: Re-verify model_q4.onnx SHA-256
run: |
EXPECTED=$(grep 'model_q4.onnx' dl/SHA256SUMS | awk '{print $1}')
ACTUAL=$(sha256sum model/onnx/model_q4.onnx | awk '{print $1}')
echo "expected=$EXPECTED actual=$ACTUAL"
test "$EXPECTED" = "$ACTUAL"
- name: Publish to Hugging Face
env:
HF_TOKEN: ${{ secrets.HF_TOKEN }}
run: |
# The moving pointer is the version without the build timestamp
# (v2.0.0-<ts> -> v2.0.0), so v2.0.0 tracks the latest curtain-small build
# while v1.0.0 (curtain-tiny) stays pinned to its own weights.
MOVING_REF=$(echo "$TAG" | sed -E 's/-[0-9]{14}$//')
uv run --with huggingface_hub --no-project python train/publish_hf.py \
--model model --card train/hf_card.md \
--repo hackshare/curtain-privacy --revision-tag "$TAG" --moving-ref "$MOVING_REF"