chore(deps-dev): update hypothesis requirement from <7.0,>=6.165.4 to >=6.165.10,<7.0 in /agent-governance-python/agent-hypervisor #5964
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Policy Validation | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| jobs: | |
| changes: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| policies: ${{ steps.filter.outputs.policies }} | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 | |
| id: filter | |
| with: | |
| filters: | | |
| policies: | |
| - '**/*.yaml' | |
| - '**/*.yml' | |
| - 'agent-governance-python/agt-policies/**' | |
| - 'agent-governance-python/agent-compliance/src/agent_compliance/lint_policy.py' | |
| validate-policies: | |
| runs-on: ubuntu-latest | |
| needs: changes | |
| if: needs.changes.outputs.policies == 'true' | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.11" | |
| - name: Build native ACS SDK | |
| # agent-compliance's manifest linter calls the native | |
| # `agent_control_specification` Rust SDK (pyo3/maturin); build it from | |
| # the vendored policy-engine so parse/validate are available. | |
| run: | | |
| set -euo pipefail | |
| pip install --no-cache-dir maturin==1.8.7 # Scorecard: version-pinned | |
| pip install --no-cache-dir --no-build-isolation ./policy-engine/sdk/python | |
| - name: Install native manifest linter | |
| run: | | |
| pip install --no-cache-dir -e agent-governance-python/agent-compliance | |
| pip install --no-cache-dir --no-deps -e agent-governance-python/agt-policies | |
| - name: Find and validate native ACS manifests | |
| run: | | |
| python - <<'PY' | |
| from pathlib import Path | |
| from agent_compliance.lint_policy import lint_file | |
| # A manifest that omits agent_control_specification_version would skip | |
| # validation silently, which is the wrong direction for a policy gate. | |
| # intervention_points is the ACS-specific tell: policies and agents | |
| # are also used by unrelated config formats in this repo. | |
| def declares_hooks(text): | |
| return text.startswith("intervention_points:") or "\nintervention_points:" in text | |
| manifests = [] | |
| missing_version = [] | |
| for root in (Path("examples"), Path("agent-governance-python")): | |
| for pattern in ("*.yaml", "*.yml"): | |
| for path in root.rglob(pattern): | |
| text = path.read_text(encoding="utf-8", errors="ignore") | |
| if "agent_control_specification_version:" in text: | |
| manifests.append(path) | |
| elif declares_hooks(text): | |
| missing_version.append(path) | |
| failed = [ | |
| f"{path}: declares intervention_points but no " | |
| "agent_control_specification_version, so it skips validation" | |
| for path in sorted(missing_version) | |
| ] | |
| for path in sorted(manifests): | |
| result = lint_file(path) | |
| if not result.passed: | |
| failed.extend(result.errors) | |
| print(f"Validated {len(manifests)} native ACS manifests.") | |
| for finding in failed: | |
| print(finding) | |
| raise SystemExit(bool(failed)) | |
| PY | |
| test-policies: | |
| runs-on: ubuntu-latest | |
| needs: [changes, validate-policies] | |
| if: always() && needs.validate-policies.result != 'failure' | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| if: needs.changes.outputs.policies == 'true' | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| if: needs.changes.outputs.policies == 'true' | |
| with: | |
| python-version: "3.11" | |
| - name: Build native ACS SDK (test job) | |
| if: needs.changes.outputs.policies == 'true' | |
| run: | | |
| set -euo pipefail | |
| pip install --no-cache-dir maturin==1.8.7 # Scorecard: version-pinned | |
| pip install --no-cache-dir --no-build-isolation ./policy-engine/sdk/python | |
| - name: Install native manifest test dependencies | |
| if: needs.changes.outputs.policies == 'true' | |
| run: | | |
| pip install --no-cache-dir -e agent-governance-python/agent-compliance | |
| pip install --no-cache-dir --no-deps -e agent-governance-python/agt-policies | |
| pip install --no-cache-dir --require-hashes -r "$GITHUB_WORKSPACE/agent-governance-python/requirements/ci-policy-test.txt" | |
| - name: Run native manifest lint tests | |
| if: needs.changes.outputs.policies == 'true' | |
| working-directory: agent-governance-python/agent-compliance | |
| run: pytest tests/test_lint_policy.py tests/test_agt_cli.py -k lint -v --tb=short | |
| - name: Skip (no policy changes) | |
| if: needs.changes.outputs.policies != 'true' | |
| run: echo "No policy file changes detected, skipping." |