Complete RC6 supply chain gates
GeoIntel release gates / Compile, test, contracts and builds (push) Canceled after 0s
GeoIntel release gates / Python and npm vulnerability policy (push) Canceled after 0s
GeoIntel release gates / GIS image, SBOM and container scan (push) Canceled after 0s

This commit is contained in:
Codex
2026-07-18 04:15:59 +02:00
parent 944269c25b
commit 027e4b078b
25 changed files with 3915 additions and 52 deletions
-30
View File
@@ -1,30 +0,0 @@
name: GeoIntel CI
on:
push:
branches: [ main, develop, 'build/**' ]
pull_request:
branches: [ main, develop ]
jobs:
docs-smoke:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Validate repository docs
run: |
python scripts/smoke_docs.py
python scripts/validate_fixtures.py
contract-smoke:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Run contract smoke checks
run: python scripts/smoke_contracts.py
+141
View File
@@ -0,0 +1,141 @@
name: GeoIntel release gates
on:
push:
branches: [main, develop, "codex/**", "build/**"]
pull_request:
branches: [main, develop]
workflow_dispatch:
permissions:
contents: read
concurrency:
group: geointel-release-${{ github.ref }}
cancel-in-progress: true
jobs:
quality:
name: Compile, test, contracts and builds
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.11"
cache: pip
cache-dependency-path: backend/requirements-ci.lock
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: npm
cache-dependency-path: frontend/package-lock.json
- name: Install locked backend dependencies
run: |
python -m pip install --disable-pip-version-check --require-hashes -r backend/requirements-ci.lock
python -m pip install --disable-pip-version-check --no-deps -e backend
- name: Install locked frontend dependencies
working-directory: frontend
run: npm ci
- name: Verify dependency lock policy
run: python scripts/verify_python_lock.py
- name: Run complete release readiness gate
env:
PYTHON_BIN: python
run: bash scripts/run_readiness_check.sh
- name: Render migration and Compose evidence
run: |
mkdir -p artifacts
cd backend
python -m alembic upgrade head --sql > ../artifacts/alembic-upgrade.sql
cd ..
docker compose config > artifacts/docker-compose.resolved.yml
- name: Publish quality evidence
if: always()
uses: actions/upload-artifact@v4
with:
name: quality-evidence
path: |
artifacts/alembic-upgrade.sql
artifacts/docker-compose.resolved.yml
if-no-files-found: warn
retention-days: 30
dependency-audit:
name: Python and npm vulnerability policy
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.11"
cache: pip
cache-dependency-path: backend/requirements-ci.lock
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: npm
cache-dependency-path: frontend/package-lock.json
- name: Audit locked Python dependencies
run: |
mkdir -p artifacts
python -m pip install --disable-pip-version-check pip-audit==2.10.1
bash scripts/audit_python_dependencies.sh
- name: Audit locked frontend dependencies
working-directory: frontend
run: |
npm ci
npm audit --audit-level=high --json > ../artifacts/npm-audit.json
- name: Publish dependency evidence
if: always()
uses: actions/upload-artifact@v4
with:
name: dependency-audits
path: |
artifacts/pip-audit-full.json
artifacts/pip-audit-policy.json
artifacts/npm-audit.json
if-no-files-found: warn
retention-days: 30
container:
name: GIS image, SBOM and container scan
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
- uses: actions/checkout@v4
- name: Build non-AI release image
env:
RELEASE_SHA: ${{ github.sha }}
run: |
mkdir -p artifacts
BUILD_TIME="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
docker build \
-f deploy/unraid/Dockerfile.all-in-one \
--build-arg GEOINTEL_INSTALL_AI=false \
--build-arg GEOINTEL_BUILD_SHA="$RELEASE_SHA" \
--build-arg GEOINTEL_BUILD_TIME="$BUILD_TIME" \
-t "geointel-ci:$RELEASE_SHA-gis" \
.
docker image inspect "geointel-ci:$RELEASE_SHA-gis" > artifacts/image-inspect.json
- name: Generate SPDX SBOM
env:
RELEASE_SHA: ${{ github.sha }}
run: bash scripts/generate_container_sbom.sh "geointel-ci:$RELEASE_SHA-gis"
- name: Enforce container vulnerability policy
env:
RELEASE_SHA: ${{ github.sha }}
run: bash scripts/scan_container_image.sh "geointel-ci:$RELEASE_SHA-gis"
- name: Publish container evidence
if: always()
uses: actions/upload-artifact@v4
with:
name: container-evidence
path: |
artifacts/image-inspect.json
artifacts/geointel-sbom.spdx.json
artifacts/geointel-container-vulnerabilities.json
if-no-files-found: warn
retention-days: 30