v2.0.0-20260715165359 #6
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release publish | |
| on: | |
| release: | |
| types: [published] | |
| workflow_dispatch: | |
| inputs: | |
| tag: | |
| description: "Release tag to verify and publish, e.g. v1.0.0-20260709224500" | |
| required: true | |
| # Least privilege: the job reads the repo and downloads the release asset. The HF | |
| # token is exposed only to the publish step. | |
| permissions: | |
| contents: read | |
| env: | |
| TAG: ${{ github.event.release.tag_name || inputs.tag }} | |
| jobs: | |
| # Runs automatically on the release: no token, no environment, fast feedback. | |
| verify: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0 | |
| with: | |
| bun-version: 1.3.14 | |
| - name: Download release asset | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| gh release download "$TAG" --repo "${{ github.repository }}" \ | |
| --pattern 'curtain-model-*.tar.gz' --pattern 'SHA256SUMS' --dir dl | |
| mkdir -p model && tar -xzf dl/curtain-model-*.tar.gz -C model | |
| - name: Verify model_q4.onnx SHA-256 against SHA256SUMS | |
| run: | | |
| EXPECTED=$(grep 'model_q4.onnx' dl/SHA256SUMS | awk '{print $1}') | |
| ACTUAL=$(sha256sum model/onnx/model_q4.onnx | awk '{print $1}') | |
| echo "expected=$EXPECTED actual=$ACTUAL" | |
| test "$EXPECTED" = "$ACTUAL" | |
| - run: bun install --frozen-lockfile | |
| # bench-30k is not run here: its held-out data is gitignored. real-157 and | |
| # fairness (the absolute over-redaction gates) run through onnxruntime-web | |
| # via eval:wasm: the WASM backend is one deterministic binary, identical to | |
| # what browser consumers run, whereas native onnxruntime over-redaction is | |
| # platform-specific (Linux differs from macOS). No browser is needed; ort-web | |
| # runs the model directly under bun. adversarial is a same-backend coverage | |
| # comparison, so it is platform-robust on native cpu. | |
| - name: Quality gates on the built artifact | |
| env: | |
| # Absolute path: transformers.js treats a bare name like "model" as a | |
| # Hugging Face hub id and tries to fetch it. A path makes it load locally. | |
| CURTAIN_MODEL: ${{ github.workspace }}/model | |
| run: | | |
| bun run eval:wasm | |
| bun run eval:adversarial | |
| # Gated by the hf-release environment: its required-reviewers rule pauses here | |
| # for manual approval, its v* tag rule restricts it to release tags, and the | |
| # HF_TOKEN environment secret is available only to this job. Runs only after | |
| # verify succeeds. | |
| publish: | |
| needs: verify | |
| runs-on: ubuntu-latest | |
| environment: hf-release | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 | |
| - name: Download the verified release asset | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| gh release download "$TAG" --repo "${{ github.repository }}" \ | |
| --pattern 'curtain-model-*.tar.gz' --pattern 'SHA256SUMS' --dir dl | |
| mkdir -p model && tar -xzf dl/curtain-model-*.tar.gz -C model | |
| - name: Re-verify model_q4.onnx SHA-256 | |
| run: | | |
| EXPECTED=$(grep 'model_q4.onnx' dl/SHA256SUMS | awk '{print $1}') | |
| ACTUAL=$(sha256sum model/onnx/model_q4.onnx | awk '{print $1}') | |
| echo "expected=$EXPECTED actual=$ACTUAL" | |
| test "$EXPECTED" = "$ACTUAL" | |
| - name: Publish to Hugging Face | |
| env: | |
| HF_TOKEN: ${{ secrets.HF_TOKEN }} | |
| run: | | |
| # The moving pointer is the version without the build timestamp | |
| # (v2.0.0-<ts> -> v2.0.0), so v2.0.0 tracks the latest curtain-small build | |
| # while v1.0.0 (curtain-tiny) stays pinned to its own weights. | |
| MOVING_REF=$(echo "$TAG" | sed -E 's/-[0-9]{14}$//') | |
| uv run --with huggingface_hub --no-project python train/publish_hf.py \ | |
| --model model --card train/hf_card.md \ | |
| --repo hackshare/curtain-privacy --revision-tag "$TAG" --moving-ref "$MOVING_REF" |