Define streaming indexed recursive WARP architecture #1303
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| tags: ['v*.*.*', 'v*.*.*-*'] | |
| pull_request: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| jobs: | |
| # ── IRONCLAD M9 static firewall ────────────────────────────────────────── | |
| # The `type-firewall` job below is the required aggregate status check. Its | |
| # child jobs run the static gates in parallel so PRs wait for the slowest | |
| # static lane instead of the sum of every static lane. | |
| type-firewall-types: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Gate 1: TypeScript compiler (advisory — JSDoc JS produces false positives across module boundaries)' | |
| continue-on-error: true | |
| run: npm run typecheck:src | |
| - name: 'Gate 2: IRONCLAD policy checker (any/wildcard/ts-ignore ban)' | |
| run: npm run typecheck:policy | |
| - name: 'Gate 3: Consumer type surface test' | |
| run: npm run typecheck:consumer | |
| type-firewall-lint: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Gate 4: ESLint (typed rules + no-explicit-any)' | |
| run: npm run lint | |
| - name: 'Gate 4b: Lint ratchet (zero-error invariant)' | |
| run: npm run lint:ratchet | |
| - name: 'Gate 4c: Anti-sludge shell checks (junk-drawer filenames)' | |
| run: npm run lint:sludge | |
| type-firewall-semgrep: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Gate 4d: Install semgrep' | |
| run: python -m pip install --upgrade pip semgrep | |
| - name: 'Gate 4e: Semgrep anti-sludge with rule-scoped quarantines' | |
| run: npm run lint:semgrep | |
| type-firewall-quarantine: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Gate 4f: Contamination map matches checked-in manifests (no stale quarantines)' | |
| run: | | |
| npm run lint:contamination | |
| git diff --exit-code -- policy/quarantines/ | |
| - name: 'Gate 4g: Fetch base branch for quarantine-graduate-check' | |
| # Required for `git merge-base origin/main HEAD` on shallow | |
| # CI clones. If the fetch fails (e.g. PR from a fork with | |
| # limited perms), the graduate-check will skip gracefully. | |
| run: git fetch --no-tags --depth=1 origin main || true | |
| - name: 'Gate 4h: Quarantine graduate-check (touched quarantined files must graduate or narrow)' | |
| env: | |
| GIT_WARP_QUARANTINE_BASE: origin/main | |
| run: npm run lint:quarantine-graduate | |
| type-firewall-surface: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Gate 5: Declaration surface validator (manifest vs index.d.ts vs index.js)' | |
| run: npm run typecheck:surface | |
| type-firewall-generated-sdk: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Gate 5a: Install pinned Wesley generator' | |
| run: >- | |
| cargo install | |
| --git https://github.com/flyingrobots/wesley.git | |
| --rev 4891a631f888c5b2f70e117e3704538dd1362c2f | |
| --locked | |
| wesley-cli | |
| - name: 'Gate 5b: Wesley vocabulary IR drift' | |
| run: npm run check:vocabulary-ir | |
| - name: 'Gate 5c: v19 capability artifact drift' | |
| run: npm run check:capabilities | |
| - name: 'Gate 5d: Generated SDK source and reference drift' | |
| run: npm run check:sdk-fixture | |
| - name: 'Gate 5e: Packed generated SDK with disposable real Git' | |
| run: npm run test:sdk-fixture | |
| - name: 'Gate 5f: All twelve v19 acceptance gates' | |
| run: npm run test:v19-acceptance | |
| type-firewall-docs: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Gate 6: Markdown lint (fenced code blocks require language)' | |
| run: npm run lint:md | |
| - name: 'Gate 7: Markdown JS/TS code-sample syntax check' | |
| run: npm run lint:md:code | |
| - name: 'Gate 8: Public documentation topology' | |
| run: npm run lint:docs-topology | |
| type-firewall-audit-advisory: | |
| runs-on: ubuntu-latest | |
| continue-on-error: true | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Gate 8: Security audit (runtime deps, advisory)' | |
| run: npm audit --omit=dev --audit-level=high | |
| type-firewall: | |
| runs-on: ubuntu-latest | |
| needs: | |
| - type-firewall-types | |
| - type-firewall-lint | |
| - type-firewall-semgrep | |
| - type-firewall-quarantine | |
| - type-firewall-surface | |
| - type-firewall-generated-sdk | |
| - type-firewall-docs | |
| if: ${{ always() }} | |
| steps: | |
| - name: 'IRONCLAD M9 aggregate gate' | |
| run: | | |
| echo "types: ${{ needs['type-firewall-types'].result }}" | |
| echo "lint: ${{ needs['type-firewall-lint'].result }}" | |
| echo "semgrep: ${{ needs['type-firewall-semgrep'].result }}" | |
| echo "quarantine: ${{ needs['type-firewall-quarantine'].result }}" | |
| echo "surface: ${{ needs['type-firewall-surface'].result }}" | |
| echo "sdk: ${{ needs['type-firewall-generated-sdk'].result }}" | |
| echo "docs: ${{ needs['type-firewall-docs'].result }}" | |
| test "${{ needs['type-firewall-types'].result }}" = "success" | |
| test "${{ needs['type-firewall-lint'].result }}" = "success" | |
| test "${{ needs['type-firewall-semgrep'].result }}" = "success" | |
| test "${{ needs['type-firewall-quarantine'].result }}" = "success" | |
| test "${{ needs['type-firewall-surface'].result }}" = "success" | |
| test "${{ needs['type-firewall-generated-sdk'].result }}" = "success" | |
| test "${{ needs['type-firewall-docs'].result }}" = "success" | |
| typecheck-test-advisory: | |
| runs-on: ubuntu-latest | |
| continue-on-error: true | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Advisory: JS test checkJs surface' | |
| run: npm run typecheck:test | |
| test-node: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| matrix: | |
| node: [22] | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '${{ matrix.node }}' | |
| cache: 'npm' | |
| - name: Install BATS | |
| run: sudo apt-get update && sudo apt-get install -y bats | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Build CLI | |
| run: npm run build --silent | |
| - name: Install CLI shims | |
| run: | | |
| sudo install -m 0755 bin/git-warp /usr/local/bin/git-warp | |
| sudo sh -c "printf '%s\n' '#!/usr/bin/env bash' 'exec node \"$GITHUB_WORKSPACE/dist/bin/warp-graph.js\" \"\$@\"' > /usr/local/bin/warp-graph" | |
| sudo chmod +x /usr/local/bin/warp-graph | |
| - name: Run unit + integration tests | |
| run: npm run test:node22:ci | |
| test-bun: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Run Bun integration tests | |
| run: docker compose -f docker/docker-compose.test.yml run --rm test-bun | |
| test-deno: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Run Deno integration tests | |
| run: docker compose -f docker/docker-compose.test.yml run --rm test-deno | |
| coverage-threshold: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd | |
| with: | |
| persist-credentials: false | |
| - name: Use Node.js | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e | |
| with: | |
| node-version: '22' | |
| cache: 'npm' | |
| - run: npm ci | |
| - name: 'Gate 9: Unit and V18 optic coverage threshold' | |
| run: npm run test:coverage:ci |