Skip to content

chore(deps-dev): update hypothesis requirement from <7.0,>=6.165.4 to >=6.165.10,<7.0 in /agent-governance-python/agent-hypervisor #5964

chore(deps-dev): update hypothesis requirement from <7.0,>=6.165.4 to >=6.165.10,<7.0 in /agent-governance-python/agent-hypervisor

chore(deps-dev): update hypothesis requirement from <7.0,>=6.165.4 to >=6.165.10,<7.0 in /agent-governance-python/agent-hypervisor #5964

name: Policy Validation
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
jobs:
changes:
runs-on: ubuntu-latest
outputs:
policies: ${{ steps.filter.outputs.policies }}
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3
id: filter
with:
filters: |
policies:
- '**/*.yaml'
- '**/*.yml'
- 'agent-governance-python/agt-policies/**'
- 'agent-governance-python/agent-compliance/src/agent_compliance/lint_policy.py'
validate-policies:
runs-on: ubuntu-latest
needs: changes
if: needs.changes.outputs.policies == 'true'
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.11"
- name: Build native ACS SDK
# agent-compliance's manifest linter calls the native
# `agent_control_specification` Rust SDK (pyo3/maturin); build it from
# the vendored policy-engine so parse/validate are available.
run: |
set -euo pipefail
pip install --no-cache-dir maturin==1.8.7 # Scorecard: version-pinned
pip install --no-cache-dir --no-build-isolation ./policy-engine/sdk/python
- name: Install native manifest linter
run: |
pip install --no-cache-dir -e agent-governance-python/agent-compliance
pip install --no-cache-dir --no-deps -e agent-governance-python/agt-policies
- name: Find and validate native ACS manifests
run: |
python - <<'PY'
from pathlib import Path
from agent_compliance.lint_policy import lint_file
# A manifest that omits agent_control_specification_version would skip
# validation silently, which is the wrong direction for a policy gate.
# intervention_points is the ACS-specific tell: policies and agents
# are also used by unrelated config formats in this repo.
def declares_hooks(text):
return text.startswith("intervention_points:") or "\nintervention_points:" in text
manifests = []
missing_version = []
for root in (Path("examples"), Path("agent-governance-python")):
for pattern in ("*.yaml", "*.yml"):
for path in root.rglob(pattern):
text = path.read_text(encoding="utf-8", errors="ignore")
if "agent_control_specification_version:" in text:
manifests.append(path)
elif declares_hooks(text):
missing_version.append(path)
failed = [
f"{path}: declares intervention_points but no "
"agent_control_specification_version, so it skips validation"
for path in sorted(missing_version)
]
for path in sorted(manifests):
result = lint_file(path)
if not result.passed:
failed.extend(result.errors)
print(f"Validated {len(manifests)} native ACS manifests.")
for finding in failed:
print(finding)
raise SystemExit(bool(failed))
PY
test-policies:
runs-on: ubuntu-latest
needs: [changes, validate-policies]
if: always() && needs.validate-policies.result != 'failure'
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
if: needs.changes.outputs.policies == 'true'
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
if: needs.changes.outputs.policies == 'true'
with:
python-version: "3.11"
- name: Build native ACS SDK (test job)
if: needs.changes.outputs.policies == 'true'
run: |
set -euo pipefail
pip install --no-cache-dir maturin==1.8.7 # Scorecard: version-pinned
pip install --no-cache-dir --no-build-isolation ./policy-engine/sdk/python
- name: Install native manifest test dependencies
if: needs.changes.outputs.policies == 'true'
run: |
pip install --no-cache-dir -e agent-governance-python/agent-compliance
pip install --no-cache-dir --no-deps -e agent-governance-python/agt-policies
pip install --no-cache-dir --require-hashes -r "$GITHUB_WORKSPACE/agent-governance-python/requirements/ci-policy-test.txt"
- name: Run native manifest lint tests
if: needs.changes.outputs.policies == 'true'
working-directory: agent-governance-python/agent-compliance
run: pytest tests/test_lint_policy.py tests/test_agt_cli.py -k lint -v --tb=short
- name: Skip (no policy changes)
if: needs.changes.outputs.policies != 'true'
run: echo "No policy file changes detected, skipping."