Skip to content

chore(deps-dev): Bump @types/node from 26.2.0 to 26.4.0 in /sdk/typescript in the node group across 1 directory #295

chore(deps-dev): Bump @types/node from 26.2.0 to 26.4.0 in /sdk/typescript in the node group across 1 directory

chore(deps-dev): Bump @types/node from 26.2.0 to 26.4.0 in /sdk/typescript in the node group across 1 directory #295

Workflow file for this run

name: ci
on:
push:
branches: [main]
pull_request:
# Supply chain: least privilege — jobs only read the repo.
permissions:
contents: read
jobs:
schema-lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with: { node-version: "22" }
- run: npm install -g ajv-cli@5.0.0 ajv-formats@3.0.1
- name: Validate schemas are well-formed
run: |
set -e
schemas=(spec/schema/*.json spec/schema/agent-context/*.json conformance/vectors.schema.json)
for f in "${schemas[@]}"; do
# -r must not include the file under -s (ajv rejects duplicate $id)
refs=()
for r in "${schemas[@]}"; do
[ "$r" = "$f" ] || refs+=(-r "$r")
done
ajv compile --spec=draft2020 -c ajv-formats -s "$f" "${refs[@]}"
done
- name: Validate vectors against vectors.schema.json
run: |
ajv validate --spec=draft2020 -c ajv-formats \
-s conformance/vectors.schema.json \
-r 'spec/schema/*.json' \
-r 'spec/schema/agent-context/*.json' \
-d 'conformance/vectors/*.json'
python:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with: { python-version: "3.12" }
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with: { toolchain: stable }
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
- name: Install locked dependencies, then the package itself
# requirements-dev.lock pins every transitive dep including the
# maturin build backend (uv pip compile); --no-build-isolation
# makes the editable install use that pinned maturin instead of
# fetching a floating one, and [tool.maturin] locked=true pins
# the Rust side via Cargo.lock.
run: |
uv pip install --system -r sdk/python/requirements-dev.lock
uv pip install --system --no-deps --no-build-isolation -e ./sdk/python
- run: ruff format --check sdk/python scripts && ruff check sdk/python scripts
- run: pytest sdk/python/tests -p no:agent_hooks_ctk -v
typescript:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with: { toolchain: stable }
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with: { node-version: "22" }
- run: npm ci
working-directory: sdk/typescript
- run: cargo fetch --locked
# napi-cli does not forward --locked; fetching first pins the
# graph, and the build below resolves offline-consistent.
working-directory: sdk/typescript
- run: npm run build:native:debug
working-directory: sdk/typescript
- name: Generated-binding drift (mirrors schema-drift)
run: git diff --exit-code -- binding.js binding.d.ts
working-directory: sdk/typescript
- run: npx tsc
working-directory: sdk/typescript
# All test files, never an allowlist: the emitter suite shipped
# ~100 tests before first running in CI because this line named
# two files.
- run: node --test test/*.mjs
working-directory: sdk/typescript
rust:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with: { toolchain: stable, components: "clippy, rustfmt" }
- run: cargo fmt --all --check
working-directory: sdk/rust
- run: cargo clippy --locked --workspace --all-features -- -D warnings
working-directory: sdk/rust
- run: cargo test --locked --workspace --all-features
working-directory: sdk/rust
dotnet:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with: { toolchain: stable }
- name: Build ffi cdylib
run: cargo build --locked -p agent-hooks-ffi --release
working-directory: sdk/rust
- uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with: { dotnet-version: "8.0.x" }
- run: dotnet restore --locked-mode
working-directory: sdk/dotnet
- run: dotnet format --no-restore --verify-no-changes
working-directory: sdk/dotnet
- run: dotnet build --no-restore -warnaserror
working-directory: sdk/dotnet
- name: Test (golden identity)
run: dotnet test test/AgentHooks.Tests/ --nologo
working-directory: sdk/dotnet
env:
LD_LIBRARY_PATH: ${{ github.workspace }}/sdk/rust/target/release
go:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with: { toolchain: stable }
- name: Build ffi cdylib
run: cargo build --locked -p agent-hooks-ffi --release
working-directory: sdk/rust
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with: { go-version: "1.22" }
- name: Build and test
run: |
test -z "$(gofmt -l .)" || { gofmt -l .; echo "::error::gofmt violations"; exit 1; }
go build ./...
go vet ./...
go test ./... -v
working-directory: sdk/go
env:
CGO_LDFLAGS: -L${{ github.workspace }}/sdk/rust/target/release -lagent_hooks_ffi
LD_LIBRARY_PATH: ${{ github.workspace }}/sdk/rust/target/release
# Cross-platform build+test of the core and one FFI consumer
# Advisory: not in the required-check set yet — required
# names must be stable and always-reporting (see CONTRIBUTING.md).
rust-xplat:
strategy:
fail-fast: false
matrix:
os: [macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with: { toolchain: stable }
- run: cargo test --locked --workspace --all-features
working-directory: sdk/rust
dotnet-xplat:
strategy:
fail-fast: false
matrix:
os: [macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with: { toolchain: stable }
- name: Build ffi cdylib
run: cargo build --locked -p agent-hooks-ffi --release
working-directory: sdk/rust
- uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with: { dotnet-version: "8.0.x" }
- run: dotnet restore --locked-mode
working-directory: sdk/dotnet
- name: Expose native library to the per-OS loader
# GITHUB_PATH covers the Windows DLL search path; the *_LIBRARY_PATH
# vars cover the ELF/Mach-O loaders. Native.cs has no custom
# resolver, so these are the only search knobs.
shell: bash
run: echo "${{ github.workspace }}/sdk/rust/target/release" >> "$GITHUB_PATH"
- name: Test
run: dotnet test test/AgentHooks.Tests/ --nologo
working-directory: sdk/dotnet
env:
LD_LIBRARY_PATH: ${{ github.workspace }}/sdk/rust/target/release
DYLD_LIBRARY_PATH: ${{ github.workspace }}/sdk/rust/target/release
# Workflow files were ungated until a duplicate mapping key invalidated
# release.yml for every event (PR #25) — actionlint gates them now, and
# the version surfaces are checked for agreement (VERSIONING.md).
# Advisory: not in the required-check set yet (names must prove stable).
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: actionlint (pinned, checksum-verified)
run: |
curl -sSfL -o actionlint.tgz \
https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz
echo "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 actionlint.tgz" | sha256sum -c -
tar -xzf actionlint.tgz actionlint
./actionlint -color
- name: Version surfaces agree across SDK manifests
run: python3 scripts/check-version-consistency.py
# Dependency advisories, license allowlist, bans and source checks for
# every cargo root. deny.toml at the repository root governs
# all three; the vendored JCS serializer's one retained dependency
# (ryu-js) is covered like every other node.
cargo-deny:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: taiki-e/install-action@5b4d68e2e660441203ab128a23676f1e4faf1532 # v2.86.3
with:
tool: cargo-deny@0.20.2
- name: cargo deny (all three cargo roots)
run: |
for root in sdk/rust sdk/python sdk/typescript; do
echo "::group::$root"
(cd "$root" && cargo deny --locked check advisories licenses bans sources)
echo "::endgroup::"
done
python-xplat:
strategy:
fail-fast: false
matrix:
os: [macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with: { python-version: "3.12" }
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with: { toolchain: stable }
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
- name: Install and test
# requirements-dev.lock is compiled on Linux and is not portable;
# this advisory job installs the package (Rust side still pinned
# via [tool.maturin] locked=true) plus the test dependencies.
shell: bash
run: |
uv pip install --system ./sdk/python "pytest>=9.1.1" "jsonschema>=4.26.0"
pytest sdk/python/tests -p no:agent_hooks_ctk
typescript-xplat:
strategy:
fail-fast: false
matrix:
os: [macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with: { toolchain: stable }
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with: { node-version: "22" }
- name: Build native binding and test
# Mirrors the Linux typescript job minus the drift gate: napi
# writes the host-platform .node next to binding.js, tsc emits
# dist/ (the tests import dist/index.js), then the full suite runs.
shell: bash
run: |
npm ci
cargo fetch --locked
npm run build:native:debug
npx tsc
node --test test/*.mjs
working-directory: sdk/typescript
go-xplat:
# The Windows leg builds the ffi crate for x86_64-pc-windows-gnu:
# cgo links with the GNU toolchain, which cannot consume the
# msvc-built cdylib (no import library for mingw gcc). The gnu
# target emits libagent_hooks_ffi.dll.a next to the dll, so the
# runner's mingw gcc resolves -lagent_hooks_ffi directly.
# Advisory: not in the required-check set yet (names must prove stable).
strategy:
fail-fast: false
matrix:
os: [macos-latest, windows-latest]
# include only attaches `target` to existing os entries, so the
# check names stay `go-xplat (<os>)`.
include:
- { os: macos-latest, target: aarch64-apple-darwin }
- { os: windows-latest, target: x86_64-pc-windows-gnu }
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master
with:
toolchain: stable
targets: ${{ matrix.target }}
- name: Install ${{ matrix.target }} for the pinned toolchain
# rust-toolchain.toml pins the toolchain inside sdk/rust; the
# setup action installs targets for `stable` only, so the target
# must be added in the pinned context (as in release.yml ffi-build).
shell: bash
run: rustup target add ${{ matrix.target }}
working-directory: sdk/rust
- name: Build ffi cdylib
shell: bash
run: cargo build --locked -p agent-hooks-ffi --release --target ${{ matrix.target }}
working-directory: sdk/rust
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with: { go-version: "1.22" }
- name: Expose native library to the per-OS loader
# GITHUB_PATH covers the Windows DLL search path (mirrors
# dotnet-xplat); DYLD_LIBRARY_PATH below covers the Mach-O loader.
shell: bash
run: echo "${{ github.workspace }}/sdk/rust/target/${{ matrix.target }}/release" >> "$GITHUB_PATH"
- name: Build and test
shell: bash
run: |
go build ./...
go test ./...
working-directory: sdk/go
env:
CGO_LDFLAGS: -L${{ github.workspace }}/sdk/rust/target/${{ matrix.target }}/release -lagent_hooks_ffi
DYLD_LIBRARY_PATH: ${{ github.workspace }}/sdk/rust/target/${{ matrix.target }}/release