Spaces:
Running
Running
SilverElixir
Medium wave 4: validated env numbers, Upstash backend and shutdown flush tests, deno check/lint in CI, reproducible pip step, docs for missing variables
7786593 Download .github/workflows/ci.yml from SilverElixir/Lumen: direct link, hf CLI and curl.
- Browser
- Download file 2.6 kB
-
https://huggingface.co/spaces/SilverElixir/Lumen/resolve/main/.github/workflows/ci.yml
- Command line
-
hf download hf://spaces/SilverElixir/Lumen/.github/workflows/ci.yml
-
curl -L -o ci.yml https://huggingface.co/spaces/SilverElixir/Lumen/resolve/main/.github/workflows/ci.yml
2.6 kB
| name: CI | |
| # Минимум прав для автодеплоя в прод ("зелёный CI = прод", см. AGENTS.md). | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ci-${{ github.ref }} | |
| cancel-in-progress: true | |
| on: | |
| push: | |
| pull_request: | |
| schedule: | |
| # Еженедельный прогон без единого пуша (аудит техдолга, 26 августа 2026): | |
| # requirements.txt зафиксирован через == (см. комментарий в самом файле) — | |
| # pip-audit сверяется с базой CVE на КАЖДЫЙ push/PR, но если пушей долго нет, | |
| # новая CVE в уже задеплоенной версии оставалась бы незамеченной до следующего | |
| # случайного пуша. Понедельник 06:00 UTC — произвольный, но стабильный слот. | |
| - cron: "0 6 * * 1" | |
| jobs: | |
| test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/setup-python@v7 | |
| with: | |
| python-version: "3.13" | |
| - run: pip install -r requirements.txt -r requirements-dev.txt | |
| # тот же самый гейт, что и раньше гонялся вручную (см. README) — | |
| # явный список плюс glob по каталогам, чтобы ловить кросс-файловые проблемы | |
| - run: pyflakes bot.py lumen_*.py system_prompt.py tests/*.py | |
| - run: pytest -q | |
| # Deno-тесты прокси (proxy/proxy_test.ts — без внешних импортов, офлайн). | |
| - uses: denoland/setup-deno@v2 | |
| with: | |
| deno-version: v2.x | |
| - run: deno test proxy/proxy_test.ts | |
| # Типы и линт прокси: до этого в CI не проверялось ничего, кроме тестов, | |
| # поэтому @ts-ignore на duplex:"half" и опечатки в proxy.ts проходили молча | |
| # (аудит 26.09.2026). deno check ловит и типы, и неиспользуемые импорты. | |
| - run: deno check proxy/proxy.ts | |
| - run: deno lint proxy/proxy.ts | |
| # проверка requirements.txt на известные CVE в зафиксированных версиях — | |
| # requirements-dev.txt (pytest/pyflakes/pip-audit) не сканируем: это | |
| # dev-инструменты, не попадающие в рантайм-образ (см. Dockerfile/.dockerignore) | |
| - run: pip-audit -r requirements.txt | |