fix codex review findings: import-safe modules, evidence_id remap, re… #28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| backend: | |
| name: backend (lint + tests + format) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| services: | |
| postgres: | |
| image: pgvector/pgvector:pg16 | |
| env: | |
| POSTGRES_USER: scholarrag | |
| POSTGRES_PASSWORD: scholarrag | |
| POSTGRES_DB: scholarrag | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U scholarrag" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| env: | |
| DATABASE_URL: postgresql://scholarrag:scholarrag@127.0.0.1:5432/scholarrag | |
| PGHOST: 127.0.0.1 | |
| PGPORT: "5432" | |
| PGUSER: scholarrag | |
| PGPASSWORD: scholarrag | |
| PGDATABASE: scholarrag | |
| EMBEDDING_PROVIDER: stub | |
| OPENAI_API_KEY: test-key | |
| # Anchor floor (current actual ≈ 47%). Bump as new tests land. | |
| COVERAGE_MIN: "45" | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| cache: pip | |
| - name: Install deps (pinned via requirements-dev.txt) | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -r requirements.txt -r requirements-dev.txt | |
| - name: Show toolchain versions (for drift debugging) | |
| run: | | |
| ruff --version | |
| pytest --version | |
| python --version | |
| - name: Init schema | |
| run: | | |
| PGPASSWORD=$PGPASSWORD psql -h 127.0.0.1 -U $PGUSER -d $PGDATABASE -f db/init.sql | |
| - name: Lint (ruff) | |
| run: ruff check backend/ scripts/ | |
| - name: Format check (ruff) | |
| run: ruff format --check backend/ scripts/ | |
| - name: Tests + coverage gate | |
| run: | | |
| pytest backend/tests \ | |
| --cov=backend --cov-report=term-missing --cov-report=xml \ | |
| --cov-fail-under=$COVERAGE_MIN --maxfail=5 | |
| - name: Upload coverage report | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: backend-coverage | |
| path: coverage.xml | |
| retention-days: 14 | |
| frontend: | |
| name: frontend (lint + typecheck + build) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| defaults: | |
| run: | |
| working-directory: frontend | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| cache: npm | |
| cache-dependency-path: frontend/package-lock.json | |
| - run: npm ci | |
| - name: Lint | |
| run: npx eslint . --max-warnings 0 | |
| - name: Typecheck | |
| run: npx tsc --noEmit | |
| - name: Build | |
| run: npm run build | |
| security: | |
| name: security (secret scan + filesystem scan) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| security-events: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Gitleaks (committed-secret scan) | |
| uses: gitleaks/gitleaks-action@v2 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| continue-on-error: true | |
| - name: Trivy filesystem scan (deps + IaC) | |
| uses: aquasecurity/trivy-action@master | |
| with: | |
| scan-type: fs | |
| scan-ref: . | |
| format: sarif | |
| output: trivy-results.sarif | |
| severity: HIGH,CRITICAL | |
| ignore-unfixed: true | |
| exit-code: "0" | |
| continue-on-error: true | |
| - name: Upload Trivy SARIF | |
| if: always() | |
| uses: github/codeql-action/upload-sarif@v3 | |
| with: | |
| sarif_file: trivy-results.sarif | |
| continue-on-error: true | |
| sbom: | |
| name: sbom (cyclonedx) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 8 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| - name: Generate Python SBOM (CycloneDX) | |
| run: | | |
| pip install cyclonedx-bom | |
| cyclonedx-py requirements -i requirements.txt -o sbom-python.json --output-format JSON | |
| - uses: actions/upload-artifact@v4 | |
| with: | |
| name: sbom | |
| path: sbom-python.json | |
| retention-days: 90 |