-
Notifications
You must be signed in to change notification settings - Fork 56
115 lines (102 loc) · 4.61 KB
/
Copy pathvalidate.yml
File metadata and controls
115 lines (102 loc) · 4.61 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
name: Validate rules
# PR gate for the rule packs: build the Trustabl engine and strict-load every
# pack against its rule schema. Catches schema, parse, duplicate-ID, missing
# field, out-of-range confidence, and unknown-predicate errors before a change
# can merge. Signing/publishing of bundles is a separate workflow (added once
# signing keys are provisioned).
on:
push:
branches: [main]
pull_request:
branches: [main]
# The engine's discovery uses tree-sitter (a C library), so building the
# validator binary needs cgo.
env:
CGO_ENABLED: "1"
# contents: write is only exercised on a push to main, to refresh the generated
# rule-count badge. PR runs never write.
permissions:
contents: write
pull-requests: write
jobs:
validate:
runs-on: ubuntu-latest
steps:
- name: Checkout rules
uses: actions/checkout@v4
with:
path: rules
# Validate against the engine's rule schema. A coordinated change ships as
# paired PRs (one in trustabl/agent-reliability-analyzer, one here)
# sharing a branch name, so check out the engine at the same-named branch
# when it exists, otherwise main. This mirrors the engine repo's own
# rules-sync job in reverse, and means a schema bump in the engine and the
# rules that use it validate together before either merges.
- name: Resolve engine ref
id: engineref
run: |
ref="${{ github.head_ref }}"
if [ -n "$ref" ] && git ls-remote --exit-code --heads \
https://github.com/trustabl/agent-reliability-analyzer.git "$ref" >/dev/null 2>&1; then
echo "ref=$ref" >> "$GITHUB_OUTPUT"
else
echo "ref=main" >> "$GITHUB_OUTPUT"
fi
- name: Checkout engine
uses: actions/checkout@v4
with:
repository: trustabl/agent-reliability-analyzer
ref: ${{ steps.engineref.outputs.ref }}
path: engine
- uses: actions/setup-go@v5
with:
go-version-file: engine/go.mod
cache: true
cache-dependency-path: engine/go.sum
- name: Build the validator
working-directory: engine
run: go build -o "$RUNNER_TEMP/trustabl" ./cmd/trustabl
- name: Validate rule packs
id: validate
run: |
out="$("$RUNNER_TEMP/trustabl" rules validate ./rules)"
echo "$out"
count=$(printf '%s' "$out" | sed -n 's/.*, \([0-9][0-9]*\) rule(s) valid.*/\1/p')
echo "count=$count" >> "$GITHUB_OUTPUT"
# The rule count was hardcoded in three places and disagreed with reality in
# all three (206 badge / 206 prose / 185+ prose, actual 204). It is generated
# from the validator's own output instead, so there is one source and it
# cannot go stale. shields.io reads badges/rules.json as an endpoint badge.
#
# This lands via a PR rather than a direct push. main is protection-gated, and
# the earlier direct-push version failed silently: it committed the right
# number, could not push, and the `|| warning` left the job green while the
# badge sat stale. A PR cannot fail quietly.
- name: Refresh the rule-count badge
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
working-directory: rules
run: |
n='${{ steps.validate.outputs.count }}'
[ -n "$n" ] || { echo "::error::no rule count parsed from validator"; exit 1; }
mkdir -p badges
printf '{"schemaVersion":1,"label":"rules","message":"%s","color":"brightgreen"}\n' "$n" \
> badges/rules.json
- name: Open or update the badge PR
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
uses: peter-evans/create-pull-request@v7
with:
token: ${{ secrets.GITHUB_TOKEN }}
path: rules
add-paths: badges/rules.json
branch: chore/rule-count-badge
base: main
commit-message: "chore(badges): rule count -> ${{ steps.validate.outputs.count }}"
title: "chore(badges): rule count -> ${{ steps.validate.outputs.count }}"
body: |
Regenerated from `trustabl rules validate`, which reported
**${{ steps.validate.outputs.count }}** rules on this commit.
Updates `badges/rules.json`, the shields endpoint the README badge
reads. No-ops when the count is unchanged. Safe to merge.
author: "github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>"
committer: "github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>"
delete-branch: false