Skip to content

About

Stable Year 1 advisory triage workflows, model-free examples, and artifact handoff checks.

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

TianoForge CI 0.1.0

Start with the model-free example.

GitHub Actions integration for the TianoForge EDK II triage pipeline.

Issue-triage workflow

For each newly opened issue it runs four advisory stages in order:

  1. invalid-issue detection;
  2. duplicate detection;
  3. priority classification; and
  4. maintainer assignment suggestion.

Invalid and duplicate suggestions stop later stages pending human review. The workflow produces a structured JSON result, a maintainer-facing Markdown summary, and a seven-day Actions artifact governed by repository access. It never comments, assigns, labels, closes, or otherwise mutates an issue.

Safety and integration boundaries are documented in docs/AI_TRIAGE_POLICY_ALIGNMENT.md.

The historical three-task benchmark from main remains available through manual dispatch using run_mode=benchmark. The propagation artifact adapter for saved patch-status reports also remains a separate, model-free workflow.

Local validation and demonstration

Install the pinned dependencies, then run the tests:

python -m pip install --requirement requirements.txt
python -m unittest discover --start-directory tests --verbose

Run the complete four-stage model-free demonstration:

TIANOSHIELD_DEMONSTRATION=true \
GITHUB_EVENT_NAME=workflow_dispatch \
TIANOSHIELD_ISSUE_FIXTURE=tests/fixtures/issues/opened.json \
TIANOSHIELD_OUTPUT_DIR=artifacts/ai-triage \
python .github/workflows/pyScripts/run_issue_pipeline.py

The demonstration exercises inputs, retrieval, stage sequencing, validation, and artifact generation without making a model call or claiming a real classification.

Live evaluation requires OPENAIKEY or ANTHROPICKEY (the compatible local names OPENAI_API_KEY and ANTHROPIC_API_KEY also work). Never put secret values in source files. Generated data and results are ignored by Git.

The pinned shared policy is vendored at policies/tianoshield-ai-action-policy.yaml and verified by SHA-256 before each run. Updating it requires an explicit reviewed commit that also updates the expected digest; CI does not need cross-repository credentials.

GitHub Actions posture

The workflow runs for issues: opened and supports manual dispatch for a model-free demonstration, an existing issue, or the historical benchmark. It uses read-only permissions, validates the pinned shared TianoShield action policy, discovers provider model availability before live calls, defaults to a cheap model, and emits only a job summary plus a seven-day workflow artifact.

GitHub only dispatches issues events using workflow definitions on the default branch. Before merge, use the manual demonstration mode to validate a feature branch; after merge, newly opened issues use the same code path with real event data.

Runtime configuration

Setting Purpose
TIANOFORGE_TASKS Optional comma/newline-separated operational stages; defaults to all four
TIANOFORGE_DEFAULT_MODEL Default model ID/label for all operational stages
TIANOFORGE_TASK_MODELS Optional JSON map from stage name to model
TIANOSHIELD_CHEAP_MODEL_IDS Optional newline/comma-separated cheap-tier allowlist
TIANOFORGE_TOP_K Number of retrieved historical examples; default 5
TIANOFORGE_REFERENCE_DATA Approved CSV path; defaults to data/full-edkII-dd.csv
LLMSTOUSE, TASKSTORUN Historical benchmark configuration only

Model values may be catalog labels/IDs or explicit openai:model-id and anthropic:model-id values. Live runs query the configured provider APIs and fail before inference if a selected model is unavailable.

Model-free artifact adapter

Advisory Artifact Adapter is a separate manual-only workflow. It accepts repository-relative paths for a saved advisory envelope, central envelope schema, producer payload, and producer schema. It validates both contract layers, rejects non-advisory or publishable envelopes, and renders a concise job summary plus local workflow artifact without calling a model. Its workflow installs only jsonschema and PyYAML from requirements-adapter.txt; no model SDK or credential is needed.

The checked-in defaults exercise a real public-safe 3.1b patch-propagation report. Local usage is also supported:

python .github/workflows/pyScripts/advisory_artifact_adapter.py \
  --envelope tests/fixtures/contracts/patch-propagation-envelope-v1.json \
  --envelope-schema tests/fixtures/contracts/advisory-artifact-envelope-v1.schema.json \
  --producer-payload tests/fixtures/3.1b/stage2-real-candidate-pxe.public-safe.json \
  --producer-schema tests/fixtures/3.1b/report-v0.2.schema.json \
  --output artifacts/advisory-adapter/summary.md

Current evidence boundary

The CI adapter uses the committed 2,610-row TianoForge reference dataset in data/full-edkII-dd.csv: 2,535 Bugzilla-transferred records and 75 GitHub-native records, including 37 with known first assignees. Its recorded SHA-256 is 54329441858ac0074310c8b045fbcafe8274abf046dc283e47c72554d9438237.

Retrieval is a portable TF-IDF + BM25 reciprocal-rank implementation. It does not yet claim BGE/Chroma parity because the Bugzilla XML files and saved embedding index used by TianoForge are not present.

Public repository operation

Actions logs, job summaries, and retained artifacts in a public repository may be publicly readable. Use public inputs in these workflows. The software does not make an artifact private merely by naming it advisory or private.

See VERIFICATION.md, OPENSSF.md, and YEAR1_RELEASE_INDEX.md. Original CI code is GPL-3.0-only; third-party notices preserve upstream attribution. Use issues for ordinary feedback and SECURITY.md for private vulnerability reporting.

About

Stable Year 1 advisory triage workflows, model-free examples, and artifact handoff checks.

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages