# CI Pipeline Status **Last verified: 2026-09-25** — see PR "main security + truncate + CI repair". ## Reality check (before that PR) `ci.yml` was **invalid YAML** — the inline `run: |` blocks for the config and secrets checks dedented out of their block scalar, so Gitea Actions could never parse the workflow. CI never ran on any PR, and this file's "Active" status was fiction. The old "No secrets check" also swallowed hits with `|| echo` (always green) and never scanned `.yml` files — which is where six embedded credentials were living. ## Current pipeline | Trigger | Job | Checks | |---|---|---| | PR → main, push main, tag `v*` | `validate` | adapter + a2a `py_compile`; workflow YAML parse; `config.yaml.example`; secret scan; `bash -n scripts/deploy.sh` | | tag `v*` | `deploy` | Tanko canary + Mumuni via `scripts/deploy.sh` (native mode) | All validation logic lives in **`ci_check.py`** — run `python3 ci_check.py all` locally before pushing; it fails the check on real hits instead of echoing warnings. ## Known caveats - The removed credentials still exist in git history (pre-July commits) — rotating `abiba-bot`'s password is a **server-side** task, out of repo scope. - Runner availability (`zulip-runner` on CT 116) is not verifiable from agents — the first green run after merge is the proof.