Files
zulip-platform-plugins/CI_STATUS.md
T
Mumuni 9edc258245
CI / validate (pull_request) Failing after 14s
fix(ci): make the validate job actually able to run — it never had
ci.yml has been invalid YAML since introduction: the 'Config validation'
and old inline checks dedented out of their run:| block scalar, so Gitea
could never parse the workflow — CI never ran on any PR despite
CI_STATUS.md claiming 'Active'. The old 'No secrets check' also always
passed (|| echo swallows the grep hit) and never scanned *.yml — where
six embedded credentials were living.

- validation logic moved to ci_check.py (testable locally: python3 ci_check.py all)
- secrets check now FAILS on embedded http-basic URLs and long api_keys,
  across .py/.ts/.yaml/.yml/.cjs/.sh, with placeholder allowlist
- added workflow-YAML parse gate so this class of breakage can't recur
- py_compile steps no longer swallow errors with '|| echo skipped'
- removed ci.yml's duplicate deploy job: deploy.yml is the sole deploy
  pipeline (rc tags → Tanko canary only; stable → all agents). The ci.yml
  copy would have deployed Mumuni on rc tags too, breaking canary policy,
  and never ran anyway.
- CI_STATUS.md rewritten with the real state + caveats (history still
  contains the old creds — rotation is a server-side task)
2026-09-25 15:50:16 +00:00

1.3 KiB

CI Pipeline Status

Last verified: 2026-09-25 — see PR "main security + truncate + CI repair".

Reality check (before that PR)

ci.yml was invalid YAML — the inline run: | blocks for the config and secrets checks dedented out of their block scalar, so Gitea Actions could never parse the workflow. CI never ran on any PR, and this file's "Active" status was fiction. The old "No secrets check" also swallowed hits with || echo (always green) and never scanned .yml files — which is where six embedded credentials were living.

Current pipeline

Trigger Job Checks
PR → main, push main, tag v* validate adapter + a2a py_compile; workflow YAML parse; config.yaml.example; secret scan; bash -n scripts/deploy.sh
tag v* deploy Tanko canary + Mumuni via scripts/deploy.sh (native mode)

All validation logic lives in ci_check.py — run python3 ci_check.py all locally before pushing; it fails the check on real hits instead of echoing warnings.

Known caveats

  • The removed credentials still exist in git history (pre-July commits) — rotating abiba-bot's password is a server-side task, out of repo scope.
  • Runner availability (zulip-runner on CT 116) is not verifiable from agents — the first green run after merge is the proof.