Complete RC6 supply chain gates
This commit is contained in:
@@ -1,30 +0,0 @@
|
||||
name: GeoIntel CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ main, develop, 'build/**' ]
|
||||
pull_request:
|
||||
branches: [ main, develop ]
|
||||
|
||||
jobs:
|
||||
docs-smoke:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: '3.11'
|
||||
- name: Validate repository docs
|
||||
run: |
|
||||
python scripts/smoke_docs.py
|
||||
python scripts/validate_fixtures.py
|
||||
|
||||
contract-smoke:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: '3.11'
|
||||
- name: Run contract smoke checks
|
||||
run: python scripts/smoke_contracts.py
|
||||
@@ -0,0 +1,141 @@
|
||||
name: GeoIntel release gates
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main, develop, "codex/**", "build/**"]
|
||||
pull_request:
|
||||
branches: [main, develop]
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: geointel-release-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
quality:
|
||||
name: Compile, test, contracts and builds
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 45
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: "3.11"
|
||||
cache: pip
|
||||
cache-dependency-path: backend/requirements-ci.lock
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: "20"
|
||||
cache: npm
|
||||
cache-dependency-path: frontend/package-lock.json
|
||||
- name: Install locked backend dependencies
|
||||
run: |
|
||||
python -m pip install --disable-pip-version-check --require-hashes -r backend/requirements-ci.lock
|
||||
python -m pip install --disable-pip-version-check --no-deps -e backend
|
||||
- name: Install locked frontend dependencies
|
||||
working-directory: frontend
|
||||
run: npm ci
|
||||
- name: Verify dependency lock policy
|
||||
run: python scripts/verify_python_lock.py
|
||||
- name: Run complete release readiness gate
|
||||
env:
|
||||
PYTHON_BIN: python
|
||||
run: bash scripts/run_readiness_check.sh
|
||||
- name: Render migration and Compose evidence
|
||||
run: |
|
||||
mkdir -p artifacts
|
||||
cd backend
|
||||
python -m alembic upgrade head --sql > ../artifacts/alembic-upgrade.sql
|
||||
cd ..
|
||||
docker compose config > artifacts/docker-compose.resolved.yml
|
||||
- name: Publish quality evidence
|
||||
if: always()
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: quality-evidence
|
||||
path: |
|
||||
artifacts/alembic-upgrade.sql
|
||||
artifacts/docker-compose.resolved.yml
|
||||
if-no-files-found: warn
|
||||
retention-days: 30
|
||||
|
||||
dependency-audit:
|
||||
name: Python and npm vulnerability policy
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 20
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: "3.11"
|
||||
cache: pip
|
||||
cache-dependency-path: backend/requirements-ci.lock
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: "20"
|
||||
cache: npm
|
||||
cache-dependency-path: frontend/package-lock.json
|
||||
- name: Audit locked Python dependencies
|
||||
run: |
|
||||
mkdir -p artifacts
|
||||
python -m pip install --disable-pip-version-check pip-audit==2.10.1
|
||||
bash scripts/audit_python_dependencies.sh
|
||||
- name: Audit locked frontend dependencies
|
||||
working-directory: frontend
|
||||
run: |
|
||||
npm ci
|
||||
npm audit --audit-level=high --json > ../artifacts/npm-audit.json
|
||||
- name: Publish dependency evidence
|
||||
if: always()
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: dependency-audits
|
||||
path: |
|
||||
artifacts/pip-audit-full.json
|
||||
artifacts/pip-audit-policy.json
|
||||
artifacts/npm-audit.json
|
||||
if-no-files-found: warn
|
||||
retention-days: 30
|
||||
|
||||
container:
|
||||
name: GIS image, SBOM and container scan
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 60
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- name: Build non-AI release image
|
||||
env:
|
||||
RELEASE_SHA: ${{ github.sha }}
|
||||
run: |
|
||||
mkdir -p artifacts
|
||||
BUILD_TIME="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
|
||||
docker build \
|
||||
-f deploy/unraid/Dockerfile.all-in-one \
|
||||
--build-arg GEOINTEL_INSTALL_AI=false \
|
||||
--build-arg GEOINTEL_BUILD_SHA="$RELEASE_SHA" \
|
||||
--build-arg GEOINTEL_BUILD_TIME="$BUILD_TIME" \
|
||||
-t "geointel-ci:$RELEASE_SHA-gis" \
|
||||
.
|
||||
docker image inspect "geointel-ci:$RELEASE_SHA-gis" > artifacts/image-inspect.json
|
||||
- name: Generate SPDX SBOM
|
||||
env:
|
||||
RELEASE_SHA: ${{ github.sha }}
|
||||
run: bash scripts/generate_container_sbom.sh "geointel-ci:$RELEASE_SHA-gis"
|
||||
- name: Enforce container vulnerability policy
|
||||
env:
|
||||
RELEASE_SHA: ${{ github.sha }}
|
||||
run: bash scripts/scan_container_image.sh "geointel-ci:$RELEASE_SHA-gis"
|
||||
- name: Publish container evidence
|
||||
if: always()
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: container-evidence
|
||||
path: |
|
||||
artifacts/image-inspect.json
|
||||
artifacts/geointel-sbom.spdx.json
|
||||
artifacts/geointel-container-vulnerabilities.json
|
||||
if-no-files-found: warn
|
||||
retention-days: 30
|
||||
Reference in New Issue
Block a user