Repository navigation
113 lines (109 loc) · 5 KB
/
Copy pathpackage.yml
File metadata and controls
113 lines (109 loc) · 5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
name: Package release
on:
push:
branches: ["release/**", "main", "master"]
tags: ["v*"]
pull_request:
branches: ["release/**"]
workflow_dispatch:
jobs:
package:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Set up Python
uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 # v5.4.0
with:
python-version: "3.12"
- name: Install build tooling
run: |
python -m pip install --upgrade pip setuptools wheel build twine
python -m pip install -e "./scientific-authorization-contracts"
python -m pip install -e ".[dev]"
- name: Clean-venv wheel + signed release workflow
run: python scripts/check_clean_venv_imports.py
- name: Verify contracts release identity digests
run: |
python - <<'PY'
import hashlib, json, subprocess, sys
from pathlib import Path
from scientific_authorization_contracts import (
contracts_package_content_hash,
package_version,
)
root = Path(".")
identity_path = root / "docs/release_identity/scientific-authorization-contracts-2.2.0.json"
identity = json.loads(identity_path.read_text(encoding="utf-8"))
for key in ("wheel_sha256", "source_archive_sha256", "release_manifest_sha256"):
value = str(identity.get(key) or "")
if not value or value.startswith("PENDING"):
raise SystemExit(f"release identity {key} still PENDING: {identity_path}")
if package_version() != "2.2.0":
raise SystemExit(f"contracts package_version must be 2.2.0, got {package_version()}")
expected_manifest = identity["release_manifest_sha256"].removeprefix("sha256:")
actual_manifest = contracts_package_content_hash().removeprefix("sha256:")
if expected_manifest != actual_manifest:
raise SystemExit(
"release_manifest_sha256 drift vs installed contracts content: "
f"identity={expected_manifest} actual={actual_manifest}"
)
# Rebuild artifacts for audit logging. Wheel/sdist bytes can differ across
# OS/setuptools; the pinned digests remain the committed release identity.
out = root / "dist" / "contracts-ci"
out.mkdir(parents=True, exist_ok=True)
subprocess.check_call(
[sys.executable, "-m", "build", "--outdir", str(out), "scientific-authorization-contracts"]
)
wheel = next(out.glob("*.whl"))
sdist = next(out.glob("*.tar.gz"))
def hx(p: Path) -> str:
return hashlib.sha256(p.read_bytes()).hexdigest()
print(
"identity non-PENDING; content hash OK;",
"wheel_identity=", identity["wheel_sha256"],
"wheel_rebuild=", hx(wheel),
"sdist_identity=", identity["source_archive_sha256"],
"sdist_rebuild=", hx(sdist),
"signing_key_id=", identity.get("signing_key_id"),
)
PY
- name: Fail-closed dependency audit (release branches/tags)
if: >-
startsWith(github.ref, 'refs/heads/release/') ||
startsWith(github.base_ref, 'release/') ||
startsWith(github.ref, 'refs/tags/v')
run: |
python -m pip install pip-audit
pip-audit --strict
# Mirror ci.sh contract install order for the live-ecosystem job consumers.
contracts-first-smoke:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Set up Python
uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 # v5.4.0
with:
python-version: "3.12"
- name: Install contracts then SCOPE
run: |
python -m pip install --upgrade pip
python -m pip install -e "./scientific-authorization-contracts"
python -m pip install -e ".[dev]"
python -c "from scientific_authorization_contracts import authorization_schema_provenance; from scope import ScopeEngine; print(authorization_schema_provenance()['contracts_package_version'], ScopeEngine)"
# Release tags: package smoke is mandatory (same clean-venv gate).
release-package-smoke:
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Set up Python
uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 # v5.4.0
with:
python-version: "3.12"
- name: Install build tooling
run: |
python -m pip install --upgrade pip setuptools wheel build twine
python -m pip install -e "./scientific-authorization-contracts"
python -m pip install -e ".[dev]"
- name: Clean-venv wheel smoke (mandatory on tags)
run: python scripts/check_clean_venv_imports.py