Skip to content

Commit 50cd787

Browse files
committed
Release stable Year 1 software with examples and verification
0 parents  commit 50cd787

60 files changed

Lines changed: 9794 additions & 0 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
name: Advisory Artifact Adapter
2+
3+
on:
4+
workflow_dispatch:
5+
inputs:
6+
envelope_path:
7+
description: Repository-relative advisory envelope JSON path
8+
required: true
9+
default: tests/fixtures/contracts/patch-propagation-envelope-v1.json
10+
type: string
11+
envelope_schema_path:
12+
description: Repository-relative central envelope schema path
13+
required: true
14+
default: tests/fixtures/contracts/advisory-artifact-envelope-v1.schema.json
15+
type: string
16+
producer_payload_path:
17+
description: Repository-relative producer payload JSON path
18+
required: true
19+
default: tests/fixtures/3.1b/stage2-real-candidate-pxe.public-safe.json
20+
type: string
21+
producer_schema_path:
22+
description: Repository-relative producer schema path
23+
required: true
24+
default: tests/fixtures/3.1b/report-v0.2.schema.json
25+
type: string
26+
27+
permissions:
28+
contents: read
29+
30+
# Queue rather than cancel: concurrent manual dispatches validating different
31+
# artifacts on the same branch should not abort each other.
32+
concurrency:
33+
group: advisory-artifact-adapter-${{ github.repository }}-${{ github.ref }}
34+
cancel-in-progress: false
35+
36+
jobs:
37+
validate-and-render:
38+
runs-on: ubuntu-latest
39+
timeout-minutes: 10
40+
steps:
41+
- name: Check out source
42+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
43+
44+
- name: Set up Python
45+
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
46+
with:
47+
python-version: '3.11'
48+
cache: pip
49+
cache-dependency-path: requirements-adapter.txt
50+
51+
- name: Install pinned model-free dependencies
52+
run: python -m pip install --requirement requirements-adapter.txt
53+
54+
- name: Validate shared advisory policy
55+
run: >-
56+
python .github/workflows/pyScripts/validate_shared_policy.py
57+
--policy policies/tianoshield-ai-action-policy.yaml
58+
--expected-digest f8626719e0e1e39df82e587a950b1f4f166ba139abf3b57bf33165b21023acd3
59+
60+
- name: Run adapter contract tests
61+
run: >-
62+
python -m unittest discover --start-directory tests
63+
--pattern test_advisory_artifact_adapter.py --verbose
64+
65+
- name: Validate and render saved advisory artifact
66+
env:
67+
ENVELOPE_PATH: ${{ inputs.envelope_path }}
68+
ENVELOPE_SCHEMA_PATH: ${{ inputs.envelope_schema_path }}
69+
PRODUCER_PAYLOAD_PATH: ${{ inputs.producer_payload_path }}
70+
PRODUCER_SCHEMA_PATH: ${{ inputs.producer_schema_path }}
71+
run: >-
72+
python .github/workflows/pyScripts/advisory_artifact_adapter.py
73+
--workspace-root "$GITHUB_WORKSPACE"
74+
--envelope "$ENVELOPE_PATH"
75+
--envelope-schema "$ENVELOPE_SCHEMA_PATH"
76+
--producer-payload "$PRODUCER_PAYLOAD_PATH"
77+
--producer-schema "$PRODUCER_SCHEMA_PATH"
78+
--output artifacts/advisory-adapter/summary.md
79+
--github-summary "$GITHUB_STEP_SUMMARY"
80+
81+
- name: Upload validation artifact
82+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
83+
with:
84+
name: advisory-artifact-${{ github.run_id }}
85+
path: artifacts/advisory-adapter
86+
if-no-files-found: error
87+
retention-days: 7

‎.github/workflows/ai-triage.yml‎

Lines changed: 154 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,154 @@
1+
name: TianoForge Issue Advisory
2+
3+
on:
4+
issues:
5+
types: [opened]
6+
pull_request:
7+
paths:
8+
- '.github/workflows/ai-triage.yml'
9+
- '.github/workflows/pyScripts/**'
10+
- 'requirements.txt'
11+
- 'tests/**'
12+
workflow_dispatch:
13+
inputs:
14+
run_mode:
15+
description: Run a model-free demonstration, a real issue advisory, or the historical benchmark
16+
required: true
17+
default: demonstration
18+
type: choice
19+
options:
20+
- demonstration
21+
- issue
22+
- benchmark
23+
issue_number:
24+
description: Existing issue number for issue mode; blank uses the public test fixture
25+
required: false
26+
type: string
27+
issue_model:
28+
description: Catalog model ID used for every stage in issue mode
29+
required: false
30+
type: string
31+
model_tier:
32+
description: Model tier for model-backed runs
33+
required: true
34+
default: cheap
35+
type: choice
36+
options:
37+
- cheap
38+
- benchmark
39+
benchmark_models:
40+
description: Newline-separated model IDs used only in historical benchmark mode
41+
required: false
42+
type: string
43+
benchmark_tasks:
44+
description: Newline-separated historical benchmark tasks
45+
required: false
46+
default: |-
47+
bugassignment
48+
duplicatedetection
49+
priorityclassification
50+
type: string
51+
52+
permissions:
53+
contents: read
54+
issues: read
55+
56+
concurrency:
57+
group: tianoforge-advisory-${{ github.repository }}-${{ github.event.issue.number || inputs.issue_number || github.run_id }}
58+
cancel-in-progress: false
59+
60+
jobs:
61+
issue-advisory:
62+
runs-on: ubuntu-latest
63+
timeout-minutes: 120
64+
env:
65+
GITHUBKEY: ${{ github.token }}
66+
TASKSTORUN: ${{ inputs.benchmark_tasks || vars.TASKSTORUN }}
67+
TIANOFORGE_TASKS: ${{ vars.TIANOFORGE_TASKS }}
68+
LLMSTOUSE: ${{ inputs.benchmark_models || vars.LLMSTOUSE }}
69+
TIANOFORGE_DEFAULT_MODEL: ${{ inputs.issue_model || vars.TIANOFORGE_DEFAULT_MODEL }}
70+
TIANOFORGE_TASK_MODELS: ${{ vars.TIANOFORGE_TASK_MODELS }}
71+
TIANOFORGE_TOP_K: ${{ vars.TIANOFORGE_TOP_K }}
72+
TIANOFORGE_REFERENCE_DATA: ${{ vars.TIANOFORGE_REFERENCE_DATA }}
73+
TIANOSHIELD_CHEAP_MODEL_IDS: ${{ vars.TIANOSHIELD_CHEAP_MODEL_IDS }}
74+
AVAILABLEASSIGNEES: ${{ vars.AVAILABLEASSIGNEES }}
75+
TIANOSHIELD_MODEL_TIER: ${{ github.event_name == 'issues' && 'cheap' || inputs.model_tier }}
76+
TIANOSHIELD_OUTPUT_DIR: ${{ github.workspace }}/artifacts/ai-triage
77+
TIANOSHIELD_POLICY_DIGEST: f8626719e0e1e39df82e587a950b1f4f166ba139abf3b57bf33165b21023acd3
78+
TIANOSHIELD_POLICY_NAME: tianoshield-ai-action-policy
79+
TIANOSHIELD_POLICY_VERSION: '0.2'
80+
81+
steps:
82+
- name: Check out source
83+
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
84+
85+
- name: Set up Python
86+
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
87+
with:
88+
python-version: '3.11'
89+
cache: pip
90+
91+
- name: Install pinned dependencies
92+
run: python -m pip install --requirement requirements.txt
93+
94+
- name: Validate shared advisory policy
95+
working-directory: .github/workflows/pyScripts
96+
run: >-
97+
python validate_shared_policy.py
98+
--policy "$GITHUB_WORKSPACE/policies/tianoshield-ai-action-policy.yaml"
99+
--expected-digest "$TIANOSHIELD_POLICY_DIGEST"
100+
101+
- name: Run tests
102+
if: github.event_name != 'issues'
103+
run: python -m unittest discover --start-directory tests --verbose
104+
105+
- name: Run four-stage issue pipeline
106+
id: issue_pipeline
107+
if: github.event_name == 'issues' || inputs.run_mode != 'benchmark'
108+
env:
109+
OPENAIKEY: ${{ secrets.OPENAIKEY }}
110+
ANTHROPICKEY: ${{ secrets.ANTHROPICKEY }}
111+
TIANOSHIELD_DEMONSTRATION: ${{ github.event_name == 'pull_request' || (github.event_name == 'workflow_dispatch' && inputs.run_mode == 'demonstration') }}
112+
TIANOSHIELD_ISSUE_NUMBER: ${{ inputs.issue_number }}
113+
TIANOSHIELD_ISSUE_FIXTURE: ${{ github.workspace }}/tests/fixtures/issues/opened.json
114+
working-directory: .github/workflows/pyScripts
115+
run: python run_issue_pipeline.py
116+
117+
- name: Run historical benchmark
118+
id: benchmark
119+
if: github.event_name == 'workflow_dispatch' && inputs.run_mode == 'benchmark'
120+
env:
121+
OPENAIKEY: ${{ secrets.OPENAIKEY }}
122+
ANTHROPICKEY: ${{ secrets.ANTHROPICKEY }}
123+
working-directory: .github/workflows/pyScripts
124+
run: python -m aiTriage
125+
126+
- name: Render benchmark summary
127+
if: always() && inputs.run_mode == 'benchmark'
128+
env:
129+
TRIAGE_OUTCOME: ${{ steps.benchmark.outcome }}
130+
CACHE_HIT: 'false'
131+
working-directory: .github/workflows/pyScripts
132+
run: >-
133+
python render_advisory_summary.py
134+
--output-dir "$TIANOSHIELD_OUTPUT_DIR"
135+
--github-summary "$GITHUB_STEP_SUMMARY"
136+
137+
- name: Publish issue advisory to job summary
138+
if: always() && (github.event_name == 'issues' || inputs.run_mode != 'benchmark')
139+
run: |
140+
if [[ -f "$TIANOSHIELD_OUTPUT_DIR/tianoforge-issue-advisory.md" ]]; then
141+
cat "$TIANOSHIELD_OUTPUT_DIR/tianoforge-issue-advisory.md" >> "$GITHUB_STEP_SUMMARY"
142+
else
143+
echo "## TianoForge issue advisory failed" >> "$GITHUB_STEP_SUMMARY"
144+
echo "No advisory artifact was produced. Inspect the failed step." >> "$GITHUB_STEP_SUMMARY"
145+
fi
146+
147+
- name: Upload advisory artifact
148+
if: always()
149+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
150+
with:
151+
name: tianoforge-advisory-${{ github.run_id }}
152+
path: artifacts/ai-triage
153+
if-no-files-found: warn
154+
retention-days: 7

0 commit comments

Comments
 (0)