Skip to content

v0.3.0: OpenRouter recogniser, custom recognisers, and review-UI upgr… #9

v0.3.0: OpenRouter recogniser, custom recognisers, and review-UI upgr…

v0.3.0: OpenRouter recogniser, custom recognisers, and review-UI upgr… #9

Workflow file for this run

name: CI
on:
push:
pull_request:
jobs:
# Python core: the detection pack, pseudonymiser, Scrubber, and CLI + hook tests.
python:
name: Python core (pytest)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
# Editable install puts the `scrub` console script on PATH, which the
# pre-commit hook integration test exercises; [dev] adds pytest.
- name: Install (editable, with dev deps)
run: pip install -e ".[dev]"
- name: Run tests
working-directory: scrub
run: python -m pytest -q
# Review UI: type-check, production build, and a gated dependency audit.
ui:
name: UI (tsc, build, audit)
runs-on: ubuntu-latest
defaults:
run:
working-directory: ui
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: npm
cache-dependency-path: ui/package-lock.json
- name: Install
run: npm ci
- name: Type-check
run: npx tsc --noEmit
- name: Build
run: npm run build
# Gate at `high`: a NEW high/critical advisory must break CI, but known,
# triaged moderate advisories (see SECURITY.md) must not block unrelated work.
# Patchable advisories are fixed at the source (deps / npm overrides), not muted
# here, this gate is the backstop that stops a new critical merging silently.
- name: Audit (fail on high/critical)
run: npm audit --audit-level=high