Skip to content

release: codeguard-plugin v0.5.4 with codeguard-skills v0.1.1 #7

release: codeguard-plugin v0.5.4 with codeguard-skills v0.1.1

release: codeguard-plugin v0.5.4 with codeguard-skills v0.1.1 #7

Workflow file for this run

name: skills-check
on:
pull_request:
push:
branches: [main]
jobs:
vendor-check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
fetch-depth: 0
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: "3.12"
- name: Verify vendored skills match the lockfile digests
run: python3 scripts/vendor/skill_vendor.py check --offline
- name: Verify lockfile pins still match upstream refs and content
run: python3 scripts/vendor/skill_vendor.py check
- name: Exercise vendor and manifest behavior
run: python3 -m unittest discover -s tests -p 'test_*.py' -v
- name: Run plugin regression suite
run: python3 tests/run_all.py
- name: Reject direct edits to externally managed skills
if: github.event_name == 'pull_request'
run: |
changed="$(git diff --name-only "origin/${{ github.base_ref }}...HEAD")"
CHANGED="$changed" python3 - <<'PY'
import json
import os
import sys
changed = {line for line in os.environ["CHANGED"].splitlines() if line}
if "skills.lock.json" in changed:
raise SystemExit(0)
lock = json.load(open("skills.lock.json", encoding="utf-8"))
prefixes = {
f"{source['dest'].rstrip('/')}/{name}/"
for source in lock["sources"]
for name in source["skills"]
}
bypassed = sorted(path for path in changed if any(path.startswith(prefix) for prefix in prefixes))
if bypassed:
print("::error::Externally managed skills changed without skills.lock.json: " + ", ".join(bypassed))
print("Edit codeguard-skills, release a new tag, then run scripts/vendor/skill_vendor.py update.")
sys.exit(1)
PY