Files
zulip-platform-plugins/.gitea/workflows/ci.yml
T
Mumuni 9edc258245
CI / validate (pull_request) Failing after 14s
fix(ci): make the validate job actually able to run — it never had
ci.yml has been invalid YAML since introduction: the 'Config validation'
and old inline checks dedented out of their run:| block scalar, so Gitea
could never parse the workflow — CI never ran on any PR despite
CI_STATUS.md claiming 'Active'. The old 'No secrets check' also always
passed (|| echo swallows the grep hit) and never scanned *.yml — where
six embedded credentials were living.

- validation logic moved to ci_check.py (testable locally: python3 ci_check.py all)
- secrets check now FAILS on embedded http-basic URLs and long api_keys,
  across .py/.ts/.yaml/.yml/.cjs/.sh, with placeholder allowlist
- added workflow-YAML parse gate so this class of breakage can't recur
- py_compile steps no longer swallow errors with '|| echo skipped'
- removed ci.yml's duplicate deploy job: deploy.yml is the sole deploy
  pipeline (rc tags → Tanko canary only; stable → all agents). The ci.yml
  copy would have deployed Mumuni on rc tags too, breaking canary policy,
  and never ran anyway.
- CI_STATUS.md rewritten with the real state + caveats (history still
  contains the old creds — rotation is a server-side task)
2026-09-25 15:50:16 +00:00

39 lines
927 B
YAML

# Gitea Actions CI — zulip-platform-plugins
name: CI
on:
pull_request:
branches: [main]
push:
branches: [main]
tags:
- v*
jobs:
validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: python3 --version
- run: node --version
- run: echo "Runner works!"
- name: Python syntax check
run: |
python3 -m py_compile plugins/platforms/zulip/adapter.py && echo "✅ adapter.py OK"
python3 -m py_compile agent-zero-zulip/src/agent_zero_zulip/adapter.py && echo "✅ a2a adapter OK"
- name: Workflow YAML parse check
run: python3 ci_check.py workflows
- name: Config validation
run: python3 ci_check.py config
- name: No secrets check
run: python3 ci_check.py secrets
- name: Deploy script syntax
run: bash -n scripts/deploy.sh && echo "✅ deploy.sh syntax OK"