From a95a8711f5644f42dce001a47bc1221977f0bbef Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 08:23:47 +0530 Subject: [PATCH 01/13] test: innocent bystander commit --- src/utils.ts | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/utils.ts b/src/utils.ts index 3a350b2..3ed45ea 100644 --- a/src/utils.ts +++ b/src/utils.ts @@ -2,9 +2,11 @@ export function funcA(input: string): string { // This is the function we plan to change. return `Processed A: ${input}`; + //right change } export function funcB(input: string): string { // This function should NOT be changed. return `Processed B: ${input}`; + // outside change } \ No newline at end of file From 42d798d4ee3127c800b263aa2b8f4df79a5f1fe7 Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 08:34:37 +0530 Subject: [PATCH 02/13] re-triggering CI with v14 approval From f21903a50ef3d966043f5d4f7a2c71b186b5fef9 Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 09:13:36 +0530 Subject: [PATCH 03/13] final re-trigger with pushed intent From b43e085df67d6aad323be770be3aea4be122ed66 Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 09:22:30 +0530 Subject: [PATCH 04/13] fix --- .github/workflows/ripple.yml | 48 ++++++++++++++++++++++++++++++++++-- 1 file changed, 46 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ripple.yml b/.github/workflows/ripple.yml index 7408b1b..a644240 100644 --- a/.github/workflows/ripple.yml +++ b/.github/workflows/ripple.yml @@ -10,9 +10,48 @@ permissions: checks: write jobs: + # JOB 1: BUILD THE TOOL + # This job's ONLY purpose is to build your CLI from the correct branch of your tool's repository. + build-ripple-cli: + name: Build Ripple CLI + runs-on: ubuntu-latest + steps: + - name: Checkout Ripple Main Repo from Dev Branch + uses: actions/checkout@v4 + with: + repository: raushankcode/ripple + ref: v14-innocent-test # <-- CRITICAL: ENSURE THIS IS YOUR CORRECT DEV BRANCH NAME + path: ripple-main + token: ${{ secrets.CROSS_REPO_PAT }} + + - name: Setup Node.js + uses: actions/setup-node@v4 + with: + node-version: 20 + + - name: Build and Pack Ripple CLI + working-directory: ./ripple-main + run: | + npm install + npm run build --workspaces + npm pack --workspace @getripple/core + npm pack --workspace @getripple/cli + + - name: Upload CLI Artifact + uses: actions/upload-artifact@v4 + with: + name: ripple-cli-packages + path: | + ripple-main/getripple-core-*.tgz + ripple-main/getripple-cli-*.tgz + + # JOB 2: RUN THE GATE + # This job ONLY runs after the build job succeeds. It uses the tool we just built. ripple-gate: name: Ripple authorization gate runs-on: ubuntu-latest + needs: build-ripple-cli # <-- This is the key. It waits for Job 1 to finish. + steps: - name: Checkout PR Code uses: actions/checkout@v4 @@ -24,14 +63,19 @@ jobs: with: node-version: 20 + - name: Download Ripple CLI Artifact + uses: actions/download-artifact@v4 + with: + name: ripple-cli-packages + - name: Ripple CI gate env: RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} run: | - # Install the local packages we copied into the repo + # Install the downloaded packages from the artifact npm install ./getripple-core-*.tgz npm install ./getripple-cli-*.tgz - # Run the gate using the now-installed binary + # Run the gate using the locally installed binary. This is now guaranteed to be the correct version. ./node_modules/.bin/ripple ci --base origin/${{ github.base_ref || 'main' }} --github-annotations --sha ${{ github.event.pull_request.head.sha || github.sha }} From 855f0b9b9f4029163128b80a578e978ce28f12ee Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 09:29:24 +0530 Subject: [PATCH 05/13] fixed --- .github/workflows/ripple.yml | 15 ++++----------- 1 file changed, 4 insertions(+), 11 deletions(-) diff --git a/.github/workflows/ripple.yml b/.github/workflows/ripple.yml index a644240..8f94737 100644 --- a/.github/workflows/ripple.yml +++ b/.github/workflows/ripple.yml @@ -10,8 +10,6 @@ permissions: checks: write jobs: - # JOB 1: BUILD THE TOOL - # This job's ONLY purpose is to build your CLI from the correct branch of your tool's repository. build-ripple-cli: name: Build Ripple CLI runs-on: ubuntu-latest @@ -20,14 +18,14 @@ jobs: uses: actions/checkout@v4 with: repository: raushankcode/ripple - ref: v14-innocent-test # <-- CRITICAL: ENSURE THIS IS YOUR CORRECT DEV BRANCH NAME + ref: v14-innocent-test # Or your correct dev branch name path: ripple-main token: ${{ secrets.CROSS_REPO_PAT }} - name: Setup Node.js uses: actions/setup-node@v4 with: - node-version: 20 + node-version: "22.x" # <-- UPDATED FOR HYGIENE - name: Build and Pack Ripple CLI working-directory: ./ripple-main @@ -45,12 +43,10 @@ jobs: ripple-main/getripple-core-*.tgz ripple-main/getripple-cli-*.tgz - # JOB 2: RUN THE GATE - # This job ONLY runs after the build job succeeds. It uses the tool we just built. ripple-gate: name: Ripple authorization gate runs-on: ubuntu-latest - needs: build-ripple-cli # <-- This is the key. It waits for Job 1 to finish. + needs: build-ripple-cli steps: - name: Checkout PR Code @@ -61,7 +57,7 @@ jobs: - name: Setup Node.js uses: actions/setup-node@v4 with: - node-version: 20 + node-version: "22.x" # <-- UPDATED FOR HYGIENE - name: Download Ripple CLI Artifact uses: actions/download-artifact@v4 @@ -73,9 +69,6 @@ jobs: RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} run: | - # Install the downloaded packages from the artifact npm install ./getripple-core-*.tgz npm install ./getripple-cli-*.tgz - - # Run the gate using the locally installed binary. This is now guaranteed to be the correct version. ./node_modules/.bin/ripple ci --base origin/${{ github.base_ref || 'main' }} --github-annotations --sha ${{ github.event.pull_request.head.sha || github.sha }} From 886374dee8261c35484f098f14b119bd9a9cc69a Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 11:47:36 +0530 Subject: [PATCH 06/13] merge test --- src/utils.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/utils.ts b/src/utils.ts index 3ed45ea..4010b89 100644 --- a/src/utils.ts +++ b/src/utils.ts @@ -2,7 +2,7 @@ export function funcA(input: string): string { // This is the function we plan to change. return `Processed A: ${input}`; - //right change + //right change, love } export function funcB(input: string): string { From 99f3d7ffa540eeeee1060dacb398e65c34a154fb Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 11:55:29 +0530 Subject: [PATCH 07/13] workflow --- .github/workflows/ripple.yml | 58 +++++------------------------------- 1 file changed, 7 insertions(+), 51 deletions(-) diff --git a/.github/workflows/ripple.yml b/.github/workflows/ripple.yml index 8f94737..684f1e7 100644 --- a/.github/workflows/ripple.yml +++ b/.github/workflows/ripple.yml @@ -2,7 +2,8 @@ name: Ripple Enterprise Gate on: pull_request: - types: [opened, synchronize, reopened] + push: + branches: [main, master] permissions: contents: read @@ -10,65 +11,20 @@ permissions: checks: write jobs: - build-ripple-cli: - name: Build Ripple CLI - runs-on: ubuntu-latest - steps: - - name: Checkout Ripple Main Repo from Dev Branch - uses: actions/checkout@v4 - with: - repository: raushankcode/ripple - ref: v14-innocent-test # Or your correct dev branch name - path: ripple-main - token: ${{ secrets.CROSS_REPO_PAT }} - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: "22.x" # <-- UPDATED FOR HYGIENE - - - name: Build and Pack Ripple CLI - working-directory: ./ripple-main - run: | - npm install - npm run build --workspaces - npm pack --workspace @getripple/core - npm pack --workspace @getripple/cli - - - name: Upload CLI Artifact - uses: actions/upload-artifact@v4 - with: - name: ripple-cli-packages - path: | - ripple-main/getripple-core-*.tgz - ripple-main/getripple-cli-*.tgz - - ripple-gate: + ripple: name: Ripple authorization gate runs-on: ubuntu-latest - needs: build-ripple-cli - steps: - - name: Checkout PR Code + - name: Checkout uses: actions/checkout@v4 with: fetch-depth: 0 - - - name: Setup Node.js + - name: Setup Node uses: actions/setup-node@v4 with: - node-version: "22.x" # <-- UPDATED FOR HYGIENE - - - name: Download Ripple CLI Artifact - uses: actions/download-artifact@v4 - with: - name: ripple-cli-packages - + node-version: 20 - name: Ripple CI gate + run: npx -y @getripple/cli@1.0.12 ci --base origin/\${{ github.base_ref || 'main' }} --github-annotations --sha \${{ github.event.pull_request.head.sha || github.sha }} env: RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} - run: | - npm install ./getripple-core-*.tgz - npm install ./getripple-cli-*.tgz - ./node_modules/.bin/ripple ci --base origin/${{ github.base_ref || 'main' }} --github-annotations --sha ${{ github.event.pull_request.head.sha || github.sha }} From e5a293486073238e76bc55ddf91cf5b32d9e6bc0 Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 11:57:10 +0530 Subject: [PATCH 08/13] workflow test --- src/utils.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/utils.ts b/src/utils.ts index 4010b89..d042eb3 100644 --- a/src/utils.ts +++ b/src/utils.ts @@ -2,7 +2,7 @@ export function funcA(input: string): string { // This is the function we plan to change. return `Processed A: ${input}`; - //right change, love + //right change, love, new } export function funcB(input: string): string { From 0b7e5a6faaba5fe7bec72a2fefb578bc0cf58838 Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 11:59:07 +0530 Subject: [PATCH 09/13] workflow tesets --- src/utils.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/utils.ts b/src/utils.ts index d042eb3..fcf3b5c 100644 --- a/src/utils.ts +++ b/src/utils.ts @@ -2,7 +2,7 @@ export function funcA(input: string): string { // This is the function we plan to change. return `Processed A: ${input}`; - //right change, love, new + //right change, love, new,test } export function funcB(input: string): string { From 38b92265be7ec9e2d546f7e57da36dcb46bfd7ae Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 20:36:14 +0530 Subject: [PATCH 10/13] test: install ripple from local tgz to verify cloud sync --- .github/workflows/ripple.yml | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ripple.yml b/.github/workflows/ripple.yml index 684f1e7..7405eea 100644 --- a/.github/workflows/ripple.yml +++ b/.github/workflows/ripple.yml @@ -19,12 +19,24 @@ jobs: uses: actions/checkout@v4 with: fetch-depth: 0 + - name: Setup Node uses: actions/setup-node@v4 with: node-version: 20 + + - name: Install Ripple from local package + run: | + npm install -g ./getripple-core-1.0.12.tgz + npm install -g ./getripple-cli-1.0.12.tgz + + - name: Verify API key is set + run: node -e "console.log('API KEY SET:', !!process.env.RIPPLE_API_KEY, '| PREFIX:', process.env.RIPPLE_API_KEY?.slice(0,10))" + env: + RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} + - name: Ripple CI gate - run: npx -y @getripple/cli@1.0.12 ci --base origin/\${{ github.base_ref || 'main' }} --github-annotations --sha \${{ github.event.pull_request.head.sha || github.sha }} + run: ripple ci --base origin/${{ github.base_ref || 'main' }} --github-annotations --sha ${{ github.event.pull_request.head.sha || github.sha }} env: RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} From ddaea0fb682282df8fa6ef0e6c372680dcbf74ac Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 21:03:17 +0530 Subject: [PATCH 11/13] test(ci): add direct API test --- .github/workflows/ripple.yml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/.github/workflows/ripple.yml b/.github/workflows/ripple.yml index 7405eea..bb56bb5 100644 --- a/.github/workflows/ripple.yml +++ b/.github/workflows/ripple.yml @@ -1,3 +1,4 @@ + name: Ripple Enterprise Gate on: @@ -24,6 +25,19 @@ jobs: uses: actions/setup-node@v4 with: node-version: 20 + - name: Direct receipt test (bypasses CLI entirely) + run: | + SHA="${{ github.event.pull_request.head.sha || github.sha }}" + RESULT=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$RIPPLE_CLOUD_URL/api/audit" \ + -H "Authorization: Bearer $RIPPLE_API_KEY" \ + -H "Content-Type: application/json" \ + -d "{\"protocol\":\"ripple-audit\",\"intentId\":\"ci-direct-${SHA:0:8}\",\"commitSha\":\"$SHA\",\"branch\":\"test\",\"actor\":\"test\",\"source\":\"ci\",\"decision\":\"continue\",\"payload\":{\"test\":true}}") + echo "Direct audit API status: $RESULT" + if [ "$RESULT" != "200" ]; then echo "❌ API call failed"; exit 1; fi + echo "✅ Direct API call succeeded" + env: + RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} + RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} - name: Install Ripple from local package run: | From d18d79eae02b41134b0461f432d6a14d34b0e88f Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 21:11:08 +0530 Subject: [PATCH 12/13] test(ci): add direct API --- .github/workflows/ripple.yml | 107 +++++++++++++++++------------------ 1 file changed, 51 insertions(+), 56 deletions(-) diff --git a/.github/workflows/ripple.yml b/.github/workflows/ripple.yml index bb56bb5..b47dc98 100644 --- a/.github/workflows/ripple.yml +++ b/.github/workflows/ripple.yml @@ -1,56 +1,51 @@ - -name: Ripple Enterprise Gate - -on: - pull_request: - push: - branches: [main, master] - -permissions: - contents: read - pull-requests: read - checks: write - -jobs: - ripple: - name: Ripple authorization gate - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - - name: Setup Node - uses: actions/setup-node@v4 - with: - node-version: 20 - - name: Direct receipt test (bypasses CLI entirely) - run: | - SHA="${{ github.event.pull_request.head.sha || github.sha }}" - RESULT=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$RIPPLE_CLOUD_URL/api/audit" \ - -H "Authorization: Bearer $RIPPLE_API_KEY" \ - -H "Content-Type: application/json" \ - -d "{\"protocol\":\"ripple-audit\",\"intentId\":\"ci-direct-${SHA:0:8}\",\"commitSha\":\"$SHA\",\"branch\":\"test\",\"actor\":\"test\",\"source\":\"ci\",\"decision\":\"continue\",\"payload\":{\"test\":true}}") - echo "Direct audit API status: $RESULT" - if [ "$RESULT" != "200" ]; then echo "❌ API call failed"; exit 1; fi - echo "✅ Direct API call succeeded" - env: - RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} - RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} - - - name: Install Ripple from local package - run: | - npm install -g ./getripple-core-1.0.12.tgz - npm install -g ./getripple-cli-1.0.12.tgz - - - name: Verify API key is set - run: node -e "console.log('API KEY SET:', !!process.env.RIPPLE_API_KEY, '| PREFIX:', process.env.RIPPLE_API_KEY?.slice(0,10))" - env: - RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} - - - name: Ripple CI gate - run: ripple ci --base origin/${{ github.base_ref || 'main' }} --github-annotations --sha ${{ github.event.pull_request.head.sha || github.sha }} - env: - RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} - RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} +ripple-gate: + name: Ripple authorization gate + runs-on: ubuntu-latest + needs: build-ripple-cli # Keep this if you are using the two-job workflow + + steps: + - name: Checkout PR Code + uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Setup Node.js + uses: actions/setup-node@v4 + with: + node-version: "22.x" # Updated to a current LTS version + + # THIS STEP IS NOW CORRECTLY INDENTED + - name: Direct receipt test (bypasses CLI entirely) + run: | + SHA="${{ github.event.pull_request.head.sha || github.sha }}" + echo "Testing with SHA: $SHA" + RESULT=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$RIPPLE_CLOUD_URL/api/audit" \ + -H "Authorization: Bearer $RIPPLE_API_KEY" \ + -H "Content-Type: application/json" \ + -d "{\"protocol\":\"ripple-audit\",\"intentId\":\"ci-direct-${SHA:0:8}\",\"commitSha\":\"$SHA\",\"branch\":\"test\",\"actor\":\"direct-test\",\"source\":\"ci\",\"decision\":\"continue\",\"payload\":{\"test\":true}}") + + echo "Direct audit API call returned HTTP status: $RESULT" + + if [ "$RESULT" != "200" ]; then + echo "❌ Direct API call failed. This proves a problem with secrets, network, or the cloud API endpoint itself." + exit 1 + fi + + echo "✅ Direct API call succeeded. The connection to the cloud is healthy." + env: + RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} + RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} + + - name: Download Ripple CLI Artifact + uses: actions/download-artifact@v4 + with: + name: ripple-cli-packages + + - name: Ripple CI gate + env: + RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} + RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} + run: | + npm install ./getripple-core-*.tgz + npm install ./getripple-cli-*.tgz + ./node_modules/.bin/ripple ci --base origin/${{ github.base_ref || 'main' }} --github-annotations --sha ${{ github.event.pull_request.head.sha || github.sha }} From 95435fe6c5800d414b9d40144d276e0a57e6c6e8 Mon Sep 17 00:00:00 2001 From: Raushan Kumar <155806959+raushankcode@users.noreply.github.com> Date: Thu, 9 Jul 2026 21:13:48 +0530 Subject: [PATCH 13/13] test(ci): add direct --- .github/workflows/ripple.yml | 152 +++++++++++++++++++++++------------ 1 file changed, 101 insertions(+), 51 deletions(-) diff --git a/.github/workflows/ripple.yml b/.github/workflows/ripple.yml index b47dc98..6317b0c 100644 --- a/.github/workflows/ripple.yml +++ b/.github/workflows/ripple.yml @@ -1,51 +1,101 @@ -ripple-gate: - name: Ripple authorization gate - runs-on: ubuntu-latest - needs: build-ripple-cli # Keep this if you are using the two-job workflow - - steps: - - name: Checkout PR Code - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: "22.x" # Updated to a current LTS version - - # THIS STEP IS NOW CORRECTLY INDENTED - - name: Direct receipt test (bypasses CLI entirely) - run: | - SHA="${{ github.event.pull_request.head.sha || github.sha }}" - echo "Testing with SHA: $SHA" - RESULT=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$RIPPLE_CLOUD_URL/api/audit" \ - -H "Authorization: Bearer $RIPPLE_API_KEY" \ - -H "Content-Type: application/json" \ - -d "{\"protocol\":\"ripple-audit\",\"intentId\":\"ci-direct-${SHA:0:8}\",\"commitSha\":\"$SHA\",\"branch\":\"test\",\"actor\":\"direct-test\",\"source\":\"ci\",\"decision\":\"continue\",\"payload\":{\"test\":true}}") - - echo "Direct audit API call returned HTTP status: $RESULT" - - if [ "$RESULT" != "200" ]; then - echo "❌ Direct API call failed. This proves a problem with secrets, network, or the cloud API endpoint itself." - exit 1 - fi - - echo "✅ Direct API call succeeded. The connection to the cloud is healthy." - env: - RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} - RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} - - - name: Download Ripple CLI Artifact - uses: actions/download-artifact@v4 - with: - name: ripple-cli-packages - - - name: Ripple CI gate - env: - RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} - RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} - run: | - npm install ./getripple-core-*.tgz - npm install ./getripple-cli-*.tgz - ./node_modules/.bin/ripple ci --base origin/${{ github.base_ref || 'main' }} --github-annotations --sha ${{ github.event.pull_request.head.sha || github.sha }} +# This is the top-level name of your entire workflow +name: Ripple Enterprise Gate + +# This defines WHEN the workflow runs +on: + pull_request: + types: [opened, synchronize, reopened] + +# This defines the permissions the workflow has +permissions: + contents: read + pull-requests: read + checks: write + +# THIS IS THE MISSING 'jobs:' KEY +jobs: + # This is your first job, correctly indented under 'jobs' + build-ripple-cli: + name: Build Ripple CLI + runs-on: ubuntu-latest + steps: + - name: Checkout Ripple Main Repo from Dev Branch + uses: actions/checkout@v4 + with: + repository: raushankcode/ripple + ref: v13-test # Or your correct dev branch name + path: ripple-main + token: ${{ secrets.CROSS_REPO_PAT }} + + - name: Setup Node.js + uses: actions/setup-node@v4 + with: + node-version: "22.x" + + - name: Build and Pack Ripple CLI + working-directory: ./ripple-main + run: | + npm install + npm run build --workspaces + npm pack --workspace @getripple/core + npm pack --workspace @getripple/cli + + - name: Upload CLI Artifact + uses: actions/upload-artifact@v4 + with: + name: ripple-cli-packages + path: | + ripple-main/getripple-core-*.tgz + ripple-main/getripple-cli-*.tgz + + # This is your second job, also correctly indented under 'jobs' + ripple-gate: + name: Ripple authorization gate + runs-on: ubuntu-latest + needs: build-ripple-cli + + steps: + - name: Checkout PR Code + uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Setup Node.js + uses: actions/setup-node@v4 + with: + node-version: "22.x" + + - name: Direct receipt test (bypasses CLI entirely) + run: | + SHA="${{ github.event.pull_request.head.sha || github.sha }}" + echo "Testing with SHA: $SHA" + RESULT=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$RIPPLE_CLOUD_URL/api/audit" \ + -H "Authorization: Bearer $RIPPLE_API_KEY" \ + -H "Content-Type: application/json" \ + -d "{\"protocol\":\"ripple-audit\",\"intentId\":\"ci-direct-${SHA:0:8}\",\"commitSha\":\"$SHA\",\"branch\":\"test\",\"actor\":\"direct-test\",\"source\":\"ci\",\"decision\":\"continue\",\"payload\":{\"test\":true}}") + + echo "Direct audit API call returned HTTP status: $RESULT" + + if [ "$RESULT" != "200" ]; then + echo "❌ Direct API call failed. This proves a problem with secrets, network, or the cloud API endpoint itself." + exit 1 + fi + + echo "✅ Direct API call succeeded. The connection to the cloud is healthy." + env: + RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} + RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} + + - name: Download Ripple CLI Artifact + uses: actions/download-artifact@v4 + with: + name: ripple-cli-packages + + - name: Ripple CI gate + env: + RIPPLE_API_KEY: ${{ secrets.RIPPLE_API_KEY }} + RIPPLE_CLOUD_URL: ${{ secrets.RIPPLE_CLOUD_URL }} + run: | + npm install ./getripple-core-*.tgz + npm install ./getripple-cli-*.tgz + ./node_modules/.bin/ripple ci --base origin/${{ github.base_ref || 'main' }} --github-annotations --sha ${{ github.event.pull_request.head.sha || github.sha }}