Start with the model-free example.
GitHub Actions integration for the TianoForge EDK II triage pipeline.
For each newly opened issue it runs four advisory stages in order:
- invalid-issue detection;
- duplicate detection;
- priority classification; and
- maintainer assignment suggestion.
Invalid and duplicate suggestions stop later stages pending human review. The workflow produces a structured JSON result, a maintainer-facing Markdown summary, and a seven-day Actions artifact governed by repository access. It never comments, assigns, labels, closes, or otherwise mutates an issue.
Safety and integration boundaries are documented in
docs/AI_TRIAGE_POLICY_ALIGNMENT.md.
The historical three-task benchmark from main remains available through
manual dispatch using run_mode=benchmark. The propagation artifact adapter
for saved patch-status reports also remains a separate, model-free workflow.
Install the pinned dependencies, then run the tests:
python -m pip install --requirement requirements.txt
python -m unittest discover --start-directory tests --verboseRun the complete four-stage model-free demonstration:
TIANOSHIELD_DEMONSTRATION=true \
GITHUB_EVENT_NAME=workflow_dispatch \
TIANOSHIELD_ISSUE_FIXTURE=tests/fixtures/issues/opened.json \
TIANOSHIELD_OUTPUT_DIR=artifacts/ai-triage \
python .github/workflows/pyScripts/run_issue_pipeline.pyThe demonstration exercises inputs, retrieval, stage sequencing, validation, and artifact generation without making a model call or claiming a real classification.
Live evaluation requires OPENAIKEY or ANTHROPICKEY (the compatible local
names OPENAI_API_KEY and ANTHROPIC_API_KEY also work). Never put secret
values in source files. Generated data and results are ignored by Git.
The pinned shared policy is vendored at
policies/tianoshield-ai-action-policy.yaml and verified by SHA-256 before
each run. Updating it requires an explicit reviewed commit that also updates
the expected digest; CI does not need cross-repository credentials.
The workflow runs for issues: opened and supports manual dispatch for a
model-free demonstration, an existing issue, or the historical benchmark. It
uses read-only permissions, validates the pinned shared TianoShield action
policy, discovers provider model availability before live calls, defaults to a
cheap model, and emits only a job summary plus a seven-day workflow artifact.
GitHub only dispatches issues events using workflow definitions on the
default branch. Before merge, use the manual demonstration mode to validate a
feature branch; after merge, newly opened issues use the same code path with
real event data.
| Setting | Purpose |
|---|---|
TIANOFORGE_TASKS |
Optional comma/newline-separated operational stages; defaults to all four |
TIANOFORGE_DEFAULT_MODEL |
Default model ID/label for all operational stages |
TIANOFORGE_TASK_MODELS |
Optional JSON map from stage name to model |
TIANOSHIELD_CHEAP_MODEL_IDS |
Optional newline/comma-separated cheap-tier allowlist |
TIANOFORGE_TOP_K |
Number of retrieved historical examples; default 5 |
TIANOFORGE_REFERENCE_DATA |
Approved CSV path; defaults to data/full-edkII-dd.csv |
LLMSTOUSE, TASKSTORUN |
Historical benchmark configuration only |
Model values may be catalog labels/IDs or explicit openai:model-id and
anthropic:model-id values. Live runs query the configured provider APIs and
fail before inference if a selected model is unavailable.
Advisory Artifact Adapter is a separate manual-only workflow. It accepts
repository-relative paths for a saved advisory envelope, central envelope
schema, producer payload, and producer schema. It validates both contract
layers, rejects non-advisory or publishable envelopes, and renders a concise job
summary plus local workflow artifact without calling a model.
Its workflow installs only jsonschema and PyYAML from
requirements-adapter.txt; no model SDK or credential is needed.
The checked-in defaults exercise a real public-safe 3.1b patch-propagation report. Local usage is also supported:
python .github/workflows/pyScripts/advisory_artifact_adapter.py \
--envelope tests/fixtures/contracts/patch-propagation-envelope-v1.json \
--envelope-schema tests/fixtures/contracts/advisory-artifact-envelope-v1.schema.json \
--producer-payload tests/fixtures/3.1b/stage2-real-candidate-pxe.public-safe.json \
--producer-schema tests/fixtures/3.1b/report-v0.2.schema.json \
--output artifacts/advisory-adapter/summary.mdThe CI adapter uses the committed 2,610-row TianoForge reference dataset in
data/full-edkII-dd.csv: 2,535 Bugzilla-transferred records and 75
GitHub-native records, including 37 with known first assignees. Its recorded
SHA-256 is
54329441858ac0074310c8b045fbcafe8274abf046dc283e47c72554d9438237.
Retrieval is a portable TF-IDF + BM25 reciprocal-rank implementation. It does not yet claim BGE/Chroma parity because the Bugzilla XML files and saved embedding index used by TianoForge are not present.
Actions logs, job summaries, and retained artifacts in a public repository may be publicly readable. Use public inputs in these workflows. The software does not make an artifact private merely by naming it advisory or private.
See VERIFICATION.md, OPENSSF.md, and YEAR1_RELEASE_INDEX.md. Original CI code is GPL-3.0-only; third-party notices preserve upstream attribution. Use issues for ordinary feedback and SECURITY.md for private vulnerability reporting.