Skip to content

fix codex review findings: import-safe modules, evidence_id remap, re… #28

fix codex review findings: import-safe modules, evidence_id remap, re…

fix codex review findings: import-safe modules, evidence_id remap, re… #28

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
backend:
name: backend (lint + tests + format)
runs-on: ubuntu-latest
timeout-minutes: 15
services:
postgres:
image: pgvector/pgvector:pg16
env:
POSTGRES_USER: scholarrag
POSTGRES_PASSWORD: scholarrag
POSTGRES_DB: scholarrag
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U scholarrag"
--health-interval 10s
--health-timeout 5s
--health-retries 10
env:
DATABASE_URL: postgresql://scholarrag:scholarrag@127.0.0.1:5432/scholarrag
PGHOST: 127.0.0.1
PGPORT: "5432"
PGUSER: scholarrag
PGPASSWORD: scholarrag
PGDATABASE: scholarrag
EMBEDDING_PROVIDER: stub
OPENAI_API_KEY: test-key
# Anchor floor (current actual ≈ 47%). Bump as new tests land.
COVERAGE_MIN: "45"
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.11"
cache: pip
- name: Install deps (pinned via requirements-dev.txt)
run: |
python -m pip install --upgrade pip
pip install -r requirements.txt -r requirements-dev.txt
- name: Show toolchain versions (for drift debugging)
run: |
ruff --version
pytest --version
python --version
- name: Init schema
run: |
PGPASSWORD=$PGPASSWORD psql -h 127.0.0.1 -U $PGUSER -d $PGDATABASE -f db/init.sql
- name: Lint (ruff)
run: ruff check backend/ scripts/
- name: Format check (ruff)
run: ruff format --check backend/ scripts/
- name: Tests + coverage gate
run: |
pytest backend/tests \
--cov=backend --cov-report=term-missing --cov-report=xml \
--cov-fail-under=$COVERAGE_MIN --maxfail=5
- name: Upload coverage report
if: always()
uses: actions/upload-artifact@v4
with:
name: backend-coverage
path: coverage.xml
retention-days: 14
frontend:
name: frontend (lint + typecheck + build)
runs-on: ubuntu-latest
timeout-minutes: 10
defaults:
run:
working-directory: frontend
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: "20"
cache: npm
cache-dependency-path: frontend/package-lock.json
- run: npm ci
- name: Lint
run: npx eslint . --max-warnings 0
- name: Typecheck
run: npx tsc --noEmit
- name: Build
run: npm run build
security:
name: security (secret scan + filesystem scan)
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Gitleaks (committed-secret scan)
uses: gitleaks/gitleaks-action@v2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
continue-on-error: true
- name: Trivy filesystem scan (deps + IaC)
uses: aquasecurity/trivy-action@master
with:
scan-type: fs
scan-ref: .
format: sarif
output: trivy-results.sarif
severity: HIGH,CRITICAL
ignore-unfixed: true
exit-code: "0"
continue-on-error: true
- name: Upload Trivy SARIF
if: always()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: trivy-results.sarif
continue-on-error: true
sbom:
name: sbom (cyclonedx)
runs-on: ubuntu-latest
timeout-minutes: 8
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Generate Python SBOM (CycloneDX)
run: |
pip install cyclonedx-bom
cyclonedx-py requirements -i requirements.txt -o sbom-python.json --output-format JSON
- uses: actions/upload-artifact@v4
with:
name: sbom
path: sbom-python.json
retention-days: 90