Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# Require the repository owner's review for CI policy changes.
# Enable "Require review from Code Owners" on main after this file lands.
/.github/ @Divkix
/scripts/test_sdk_ci_gate.py @Divkix
3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,9 @@ jobs:
with:
persist-credentials: false

- name: Validate SDK CI gates
run: python3 -m unittest discover -s scripts -p test_sdk_ci_gate.py

- name: Install pnpm and Node.js
uses: pnpm/setup@703c52620218391530e48b9e8870d5c0082e1b9b # v2.1.0
with:
Expand Down
65 changes: 53 additions & 12 deletions .github/workflows/sdk-go.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,6 @@ on:
- ".github/workflows/sdk-go.yml"
pull_request:
branches: [main]
paths:
- "sdks/go/**"
- ".github/workflows/sdk-go.yml"
workflow_dispatch:

permissions:
Expand All @@ -29,11 +26,45 @@ env:
GOTOOLCHAIN: local

jobs:
changes:
name: SDK Go Change Detection
runs-on: ubuntu-latest
timeout-minutes: 5
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- name: Checkout PR merge commit
if: github.event_name == 'pull_request'
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Detect SDK changes
id: detect
working-directory: .
env:
EVENT_NAME: ${{ github.event_name }}
BASE_SHA: ${{ github.event.pull_request.base.sha }}
run: |
if [[ "$EVENT_NAME" != 'pull_request' ]]; then
echo 'run=true' >> "$GITHUB_OUTPUT"
exit 0
fi
git fetch --no-tags --depth=1 origin "$BASE_SHA"
if git diff --quiet "$BASE_SHA" HEAD -- sdks/go/ .github/workflows/sdk-go.yml; then
echo 'run=false' >> "$GITHUB_OUTPUT"
else
status=$?
if [[ "$status" -ne 1 ]]; then exit "$status"; fi
echo 'run=true' >> "$GITHUB_OUTPUT"
fi

# =============================================================================
# Lint
# =============================================================================
lint:
name: Lint
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -63,6 +94,8 @@ jobs:
# =============================================================================
test:
name: Test (Go ${{ matrix.go-version }})
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10
strategy:
Expand Down Expand Up @@ -90,6 +123,8 @@ jobs:
# =============================================================================
coverage:
name: Coverage
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -127,21 +162,27 @@ jobs:
# Final Status Check (required for branch protection)
# =============================================================================
ci-success:
name: CI Success
name: SDK Go CI Success
runs-on: ubuntu-latest
timeout-minutes: 5
needs: [lint, test, coverage]
needs: [changes, lint, test, coverage]
if: always()
env:
CHANGE_RESULT: ${{ needs.changes.result }}
SHOULD_RUN: ${{ needs.changes.outputs.run }}
LINT: ${{ needs.lint.result }}
TEST: ${{ needs.test.result }}
COVERAGE: ${{ needs.coverage.result }}

steps:
- name: Check all jobs status
run: |
results=("${{ needs.lint.result }}" "${{ needs.test.result }}" "${{ needs.coverage.result }}")
for result in "${results[@]}"; do
if [[ "$result" != "success" && "$result" != "skipped" ]]; then
echo "Job failed with result: $result"
exit 1
fi
[[ "$CHANGE_RESULT" == 'success' ]] || exit 1
if [[ "$SHOULD_RUN" == 'true' ]]; then expected=success
elif [[ "$SHOULD_RUN" == 'false' ]]; then expected=skipped
else exit 1
fi
for result in "$LINT" "$TEST" "$COVERAGE"; do
[[ "$result" == "$expected" ]] || exit 1
done
echo "All jobs passed or were skipped"
working-directory: .
76 changes: 72 additions & 4 deletions .github/workflows/sdk-python.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,14 +8,10 @@ on:
- ".github/workflows/sdk-python.yml"
pull_request:
branches: [main]
paths:
- "sdks/python/**"
- ".github/workflows/sdk-python.yml"
workflow_dispatch:

permissions:
contents: read
id-token: write

# Cancel in-progress runs on same branch/PR
concurrency:
Expand All @@ -27,11 +23,45 @@ defaults:
working-directory: sdks/python

jobs:
changes:
name: SDK Python Change Detection
runs-on: ubuntu-latest
timeout-minutes: 5
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- name: Checkout PR merge commit
if: github.event_name == 'pull_request'
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Detect SDK changes
id: detect
working-directory: .
env:
EVENT_NAME: ${{ github.event_name }}
BASE_SHA: ${{ github.event.pull_request.base.sha }}
run: |
if [[ "$EVENT_NAME" != 'pull_request' ]]; then
echo 'run=true' >> "$GITHUB_OUTPUT"
exit 0
fi
git fetch --no-tags --depth=1 origin "$BASE_SHA"
if git diff --quiet "$BASE_SHA" HEAD -- sdks/python/ .github/workflows/sdk-python.yml; then
echo 'run=false' >> "$GITHUB_OUTPUT"
else
status=$?
if [[ "$status" -ne 1 ]]; then exit "$status"; fi
echo 'run=true' >> "$GITHUB_OUTPUT"
fi

# =============================================================================
# Lint & Type Check
# =============================================================================
lint:
name: Lint & Type Check
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -68,6 +98,8 @@ jobs:
# =============================================================================
test-unit:
name: Unit Tests
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10
strategy:
Expand Down Expand Up @@ -101,6 +133,8 @@ jobs:
# =============================================================================
test-integration:
name: Integration Tests
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -131,6 +165,8 @@ jobs:
# =============================================================================
coverage:
name: Coverage Report
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -167,6 +203,8 @@ jobs:
# =============================================================================
build:
name: Build & Verify
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -211,6 +249,9 @@ jobs:
# =============================================================================
publish:
name: Publish to PyPI
permissions:
contents: read
id-token: write
runs-on: ubuntu-latest
timeout-minutes: 10
needs: [lint, test-unit, test-integration, coverage, build]
Expand Down Expand Up @@ -282,3 +323,30 @@ jobs:
echo "" >> $GITHUB_STEP_SUMMARY
echo "Version \`${{ steps.version-check.outputs.local_version }}\` already exists on PyPI." >> $GITHUB_STEP_SUMMARY
echo "Bump the version in \`sdks/python/pyproject.toml\` to trigger a new publish." >> $GITHUB_STEP_SUMMARY

sdk-ci-success:
name: SDK Python CI Success
runs-on: ubuntu-latest
timeout-minutes: 5
needs: [changes, lint, test-unit, test-integration, coverage, build]
if: always()
env:
CHANGE_RESULT: ${{ needs.changes.result }}
SHOULD_RUN: ${{ needs.changes.outputs.run }}
LINT: ${{ needs.lint.result }}
UNIT: ${{ needs.test-unit.result }}
INTEGRATION: ${{ needs.test-integration.result }}
COVERAGE: ${{ needs.coverage.result }}
BUILD: ${{ needs.build.result }}
steps:
- name: Require all applicable SDK checks
working-directory: .
run: |
[[ "$CHANGE_RESULT" == 'success' ]] || exit 1
if [[ "$SHOULD_RUN" == 'true' ]]; then expected=success
elif [[ "$SHOULD_RUN" == 'false' ]]; then expected=skipped
else exit 1
fi
for result in "$LINT" "$UNIT" "$INTEGRATION" "$COVERAGE" "$BUILD"; do
[[ "$result" == "$expected" ]] || exit 1
done
77 changes: 73 additions & 4 deletions .github/workflows/sdk-typescript.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,16 +6,16 @@ on:
paths:
- "sdks/typescript/**"
- ".github/workflows/sdk-typescript.yml"
- "pnpm-workspace.yaml"
- "tsconfig.json"
- "package.json"
- "pnpm-lock.yaml"
pull_request:
branches: [main]
paths:
- "sdks/typescript/**"
- ".github/workflows/sdk-typescript.yml"
workflow_dispatch:

permissions:
contents: read
id-token: write

# Cancel in-progress runs on same branch/PR
concurrency:
Expand All @@ -27,11 +27,45 @@ defaults:
working-directory: sdks/typescript

jobs:
changes:
name: SDK TypeScript Change Detection
runs-on: ubuntu-latest
timeout-minutes: 5
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- name: Checkout PR merge commit
if: github.event_name == 'pull_request'
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Detect SDK changes
id: detect
working-directory: .
env:
EVENT_NAME: ${{ github.event_name }}
BASE_SHA: ${{ github.event.pull_request.base.sha }}
run: |
if [[ "$EVENT_NAME" != 'pull_request' ]]; then
echo 'run=true' >> "$GITHUB_OUTPUT"
exit 0
fi
git fetch --no-tags --depth=1 origin "$BASE_SHA"
if git diff --quiet "$BASE_SHA" HEAD -- sdks/typescript/ .github/workflows/sdk-typescript.yml pnpm-workspace.yaml tsconfig.json package.json pnpm-lock.yaml; then
echo 'run=false' >> "$GITHUB_OUTPUT"
else
status=$?
if [[ "$status" -ne 1 ]]; then exit "$status"; fi
echo 'run=true' >> "$GITHUB_OUTPUT"
fi

# =============================================================================
# Lint & Type Check
# =============================================================================
lint:
name: Lint & Type Check
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -72,6 +106,8 @@ jobs:
# =============================================================================
test-unit:
name: Unit Tests
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -100,6 +136,8 @@ jobs:
# =============================================================================
test-integration:
name: Integration Tests
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -128,6 +166,8 @@ jobs:
# =============================================================================
build:
name: Build & Verify
needs: changes
if: needs.changes.outputs.run == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10

Expand Down Expand Up @@ -169,6 +209,9 @@ jobs:
# =============================================================================
publish:
name: Publish to npm
permissions:
contents: read
id-token: write
runs-on: ubuntu-latest
timeout-minutes: 10
needs: [lint, test-unit, test-integration, build]
Expand Down Expand Up @@ -285,3 +328,29 @@ jobs:
echo "## ℹ️ JSR Publish Skipped" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "Version \`${{ steps.jsr-version-check.outputs.jsr_version }}\` already exists on JSR." >> $GITHUB_STEP_SUMMARY

sdk-ci-success:
name: SDK TypeScript CI Success
runs-on: ubuntu-latest
timeout-minutes: 5
needs: [changes, lint, test-unit, test-integration, build]
if: always()
env:
CHANGE_RESULT: ${{ needs.changes.result }}
SHOULD_RUN: ${{ needs.changes.outputs.run }}
LINT: ${{ needs.lint.result }}
UNIT: ${{ needs.test-unit.result }}
INTEGRATION: ${{ needs.test-integration.result }}
BUILD: ${{ needs.build.result }}
steps:
- name: Require all applicable SDK checks
working-directory: .
run: |
[[ "$CHANGE_RESULT" == 'success' ]] || exit 1
if [[ "$SHOULD_RUN" == 'true' ]]; then expected=success
elif [[ "$SHOULD_RUN" == 'false' ]]; then expected=skipped
else exit 1
fi
for result in "$LINT" "$UNIT" "$INTEGRATION" "$BUILD"; do
[[ "$result" == "$expected" ]] || exit 1
done
Loading
Loading