Expose handoff source ages and revisions with layered provenance evaluation #511
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Validate | |
| on: | |
| pull_request: | |
| branches: [main] | |
| push: | |
| branches: [main] | |
| jobs: | |
| opencode-macos: | |
| runs-on: macos-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: '3.13' | |
| - name: Check OpenCode fixture portability on macOS | |
| run: python -m unittest discover -s tests -p "test_opencode_conformance.py" -v | |
| validate: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Run repository validation | |
| run: | | |
| chmod +x scripts/*.sh tests/*.sh | |
| bash scripts/validate-all.sh | |
| - name: Measure full-bundle materialization bounds | |
| run: python scripts/measure-bundle-materialization.py --check | |
| # The Python suite shells out to helpers and hashes file bytes, so it is exposed | |
| # to three things a Linux-only matrix cannot see. All three were live on main | |
| # until 2026-08-19 and every one of them was invisible here: | |
| # - "python3" is a Store stub on Windows that runs nothing and prints an ad | |
| # - core.autocrlf=true (system default) rewrites the bytes under a digest check | |
| # - git identity paths come back C:/... but resolve to C:\... | |
| # validate-all.sh stays Linux-only -- it is a bash pipeline with find/chmod in it. | |
| # This job runs just the part that has a real chance of breaking per-platform. | |
| tests-windows: | |
| runs-on: windows-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: '3.13' | |
| - name: Run the Python test suite on Windows | |
| run: python -m unittest discover -s tests -p "test_*.py" -v | |
| - name: Measure full-bundle materialization bounds | |
| run: python scripts/measure-bundle-materialization.py --check | |
| # Nothing exercised the oldest supported Python: the Linux job uses whatever | |
| # the runner ships and the Windows job pins 3.13. A floor no job executes is a | |
| # claim, not a guarantee -- and this one was wrong. Reading the source | |
| # suggested 3.9 (str.removeprefix), but kernel.py calls | |
| # Path.write_text(newline=...), which is 3.10+. The first run of this job | |
| # found it; 11 tests errored on 3.9. Do not lower this pin without moving | |
| # those four call sites off the newline kwarg. | |
| tests-minimum-python: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: '3.10' | |
| - name: Run repository validation on the minimum supported Python | |
| run: | | |
| chmod +x scripts/*.sh tests/*.sh | |
| bash scripts/validate-all.sh |