Repository navigation
接通 Rust 默认生命周期、固定原生复检入口与 32-grammar 运行时候选 #219
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: skills-check | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| jobs: | |
| rust-runtime-contract: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: "24" | |
| package-manager-cache: false | |
| - name: Check candidate runtime syntax and fail-incomplete behavior | |
| run: | | |
| node --check runtime/codeguard_runtime.cjs | |
| node --check hooks/rust_runtime_dispatch.cjs | |
| node --test --test-concurrency=1 tests/test_rust_runtime.cjs tests/test_rust_lifecycle.cjs | |
| vendor-check: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| python-version: ["3.11", "3.12", "3.13"] | |
| name: vendor-check (py${{ matrix.python-version }}) | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| - name: Install requirements (mcp SDK so MCP server tests run, not skip) | |
| run: python3 -m pip install --disable-pip-version-check -r requirements.txt | |
| - name: Install dev baseline (ruff as python checker + test precondition) | |
| run: python3 -m pip install --disable-pip-version-check -r requirements-dev.txt | |
| - name: Check executable code quality | |
| run: ruff check hooks scripts tests | |
| - name: Verify core dependency boundaries and import cycles | |
| run: python3 scripts/check_architecture.py | |
| - name: Verify vendored skills match the lockfile digests | |
| run: python3 scripts/vendor/skill_vendor.py check --offline | |
| - name: Verify lockfile pins still match upstream refs and content | |
| run: python3 scripts/vendor/skill_vendor.py check | |
| - name: Exercise vendor and manifest behavior | |
| run: python3 -m pip install --disable-pip-version-check coverage && python3 -m coverage run -m unittest discover -s tests -p 'test_*.py' -v | |
| - name: Coverage report (advisory, non-gating) | |
| run: python3 -m coverage report --include='scripts/**,hooks/**' --skip-empty | |
| - name: Validate languages.json schema | |
| run: python3 scripts/validate_languages_json.py | |
| - name: Run plugin regression suite | |
| run: python3 tests/run_all.py | |
| - name: Reject direct edits to externally managed skills | |
| if: github.event_name == 'pull_request' | |
| run: | | |
| changed="$(git diff --name-only "origin/${{ github.base_ref }}...HEAD")" | |
| CHANGED="$changed" python3 - <<'PY' | |
| import json | |
| import os | |
| import sys | |
| changed = {line for line in os.environ["CHANGED"].splitlines() if line} | |
| if "skills.lock.json" in changed: | |
| raise SystemExit(0) | |
| lock = json.load(open("skills.lock.json", encoding="utf-8")) | |
| prefixes = { | |
| f"{source['dest'].rstrip('/')}/{name}/" | |
| for source in lock["sources"] | |
| for name in source["skills"] | |
| } | |
| bypassed = sorted(path for path in changed if any(path.startswith(prefix) for prefix in prefixes)) | |
| if bypassed: | |
| print("::error::Externally managed skills changed without skills.lock.json: " + ", ".join(bypassed)) | |
| print("Edit codeguard-skills, release a new tag, then run scripts/vendor/skill_vendor.py update.") | |
| sys.exit(1) | |
| PY |