Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
version: 2
updates:
# Keep the pinned action majors current (checkout, setup-node, …).
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
day: monday
groups:
actions:
patterns: ['*']
labels: [dependencies, ci]

# The kit is deliberately zero-dependency (node:sqlite, node:test) — this
# watches package.json anyway so anything added later gets updates, and
# engine-range advisories still surface.
- package-ecosystem: npm
directory: /
schedule:
interval: weekly
day: monday
groups:
npm:
patterns: ['*']
labels: [dependencies]
47 changes: 47 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
name: ci

on:
push:
branches: [main, npm-kit]
pull_request:
workflow_dispatch:

jobs:
test:
name: test (${{ matrix.os }}, node ${{ matrix.node }})
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
node: [22, 24, 26]
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6 # version comes from package.json packageManager
- uses: actions/setup-node@v6
with:
node-version: ${{ matrix.node }}

# Zero runtime dependencies — no install step by design.
- name: Unit + statusline tests
run: pnpm test

- name: CLI smoke (sandboxed HOME)
shell: bash
env:
# Isolate every home-relative write (kit.json, CLAUDE.md, settings).
HOME: ${{ runner.temp }}/kit-home
USERPROFILE: ${{ runner.temp }}\kit-home
APPDATA: ${{ runner.temp }}\kit-home\AppData\Roaming
run: |
mkdir -p "$HOME"
node bin/agentic-kit.mjs --version
node bin/agentic-kit.mjs --help --all > /dev/null
# status must emit valid JSON and exit deterministically even on a
# machine with no ruflo installed (rows degrade to warn/fail).
node bin/agentic-kit.mjs status --json > status.json || true
node -e "const s=require('./status.json'); if(!Array.isArray(s.rows)||!s.overall) throw new Error('bad status JSON'); console.log('status rows:', s.rows.length, 'overall:', s.overall)"
# managed-block engine round-trip against the sandbox HOME
node bin/agentic-kit.mjs x reference sync
node -e "const fs=require('fs'),os=require('os'),p=require('path').join(os.homedir(),'.claude','CLAUDE.md'); const t=fs.readFileSync(p,'utf8'); for (const s of ['ruflo-preamble','ruflo-reference']) if(!t.includes('<!-- BEGIN '+s+' -->')) throw new Error('missing block '+s); console.log('blocks OK')"
node bin/agentic-kit.mjs uninstall --dry-run
52 changes: 52 additions & 0 deletions .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
name: nightly-live

# Installs the REAL latest ruflo + agentic-qe and runs the kit's checks against
# them — catches upstream drift the day it ships (e.g. the 3.28 aidefence drop,
# ruvnet/ruflo#2670). Scheduled + manual only; failures here mean "upstream
# changed", not "this repo broke".
on:
schedule:
- cron: '17 6 * * *'
workflow_dispatch:

jobs:
live:
name: live (${{ matrix.os }})
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest]
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v6
with:
node-version: 22

# Deliberately npm, not pnpm: this simulates the kit's TARGET environment —
# ruflo/agentic-qe installed via `npm i -g`, whose trees the kit heals with
# npm (lib/heal.mjs). pnpm-managed globals are a separate follow-up.
- name: Install latest ruflo + agentic-qe (native build scripts allowed)
run: npm install -g --allow-scripts=ruflo,agentic-qe,@claude-flow/cli,better-sqlite3,hnswlib-node,agentdb,agentic-flow,argon2,onnxruntime-node,sharp,protobufjs,@google/genai,tldjs,vibium ruflo@latest agentic-qe@latest

- name: Kit heals a fresh install (sync --no-upgrade)
env:
HOME: ${{ runner.temp }}/kit-home
run: |
mkdir -p "$HOME"
node bin/agentic-kit.mjs sync --no-upgrade || true
node bin/agentic-kit.mjs status --json > status.json || true
node -e "
const s = require('./status.json');
console.log(JSON.stringify(s, null, 2));
// Upstream-drift gate: natives + security must be healable to ok.
const bad = s.rows.filter(r => r.level === 'fail' && ['natives','security'].includes(r.subsystem));
if (bad.length) { console.error('UPSTREAM DRIFT:', bad.map(b => b.message).join(' | ')); process.exit(1); }
"

- name: Deep proofs against the live packages
env:
HOME: ${{ runner.temp }}/kit-home
run: |
node bin/agentic-kit.mjs x verify security
node bin/agentic-kit.mjs x verify learning
47 changes: 47 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
name: release

# Publishes to npm when a version tag is pushed (v4.0.0, v4.1.0-alpha.1, …).
# Requires the NPM_TOKEN repository secret (npm "Automation" token: repo
# Settings → Secrets and variables → Actions → New repository secret).
# The tag must match package.json's version — the guard below enforces it.
on:
push:
tags: ['v*']

permissions:
contents: read
id-token: write # npm provenance attestation

jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6 # version comes from package.json packageManager
- uses: actions/setup-node@v6
with:
node-version: 22
registry-url: https://registry.npmjs.org

- name: Test gate
run: pnpm test

- name: Tag ↔ package.json version guard
env:
REF_NAME: ${{ github.ref_name }}
run: |
PKG_VERSION=$(node -p "require('./package.json').version")
if [ "v$PKG_VERSION" != "$REF_NAME" ]; then
echo "tag $REF_NAME does not match package.json version v$PKG_VERSION" >&2
exit 1
fi

- name: Publish to npm registry (with provenance)
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
# prereleases (…-alpha.N) go to the 'next' dist-tag; releases to 'latest'
case "$(node -p "require('./package.json').version")" in
*-*) pnpm publish --provenance --access public --tag next --no-git-checks ;;
*) pnpm publish --provenance --access public --no-git-checks ;;
esac
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -38,3 +38,6 @@ CLAUDE.md.pre-ruflo
*.rvf.lock
*.rvf.idmap.json
*.rvf.manifest.json

# package-manager artifacts (repo is zero-dependency; lockfile IS tracked)
node_modules/
Loading
Loading