Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
89 commits
Select commit Hold shift + click to select a range
ac3fc48
fix(core): exclude vm-dev tag from git describe version glob (#843)
mjamiv Apr 15, 2026
25d2530
fix(inference): allowlist routed request headers (#826)
johntmyers Apr 15, 2026
3b21df1
feat(sandbox): load system CA certificates for upstream TLS connectio…
matz3 Apr 16, 2026
5718553
feat(release): publish standalone openshell-gateway binaries (#853)
drew Apr 16, 2026
3bc8e44
docs(rfc): adopt per-RFC folder structure (#870)
drew Apr 17, 2026
4e8dbcf
fix(sandbox): harden seccomp, inference routing, and process limits (…
johntmyers Apr 17, 2026
e4d6f92
feat(vm): add standalone libkrun compute driver (#858)
drew Apr 17, 2026
2c9c146
docs: fix TOC structure (#797)
miyoungc Apr 17, 2026
b7c7632
docs: refresh user-facing docs for recent sandbox and inference chang…
miyoungc Apr 17, 2026
5c3015a
docs(contributing): add bash shell setup example for mise (#877)
mrunalp Apr 17, 2026
ae7e901
fix(sandbox): strip " (deleted)" suffix from unlinked /proc/<pid>/exe…
mjamiv Apr 17, 2026
e39bb38
test(sandbox): fix flaky arm64 procfs binary_path tests (#881)
pimlock Apr 18, 2026
40e9bf6
feat(policy): add incremental sandbox policy updates (#860)
johntmyers Apr 20, 2026
7a0a3d0
fix(cli,tui): escape and validate SSH session response fields (#876)
johntmyers Apr 20, 2026
8a813ab
fix(sandbox): apply supervisor seccomp prelude (#891)
johntmyers Apr 20, 2026
b39f5aa
feat(install-vm): install gateway + vm driver, add --driver-dir resol…
drew Apr 20, 2026
9ac725f
fix(cli): sandbox get returns currently active runtime policy (#880)
TaylorMutch Apr 20, 2026
c960d48
fix(sandbox): canonicalize HTTP request-targets before L7 policy eval…
johntmyers Apr 21, 2026
a6d4552
feat(server,sandbox): supervisor-initiated SSH connect and exec over …
pimlock Apr 21, 2026
ba56206
feat(server): add request-level logging via tower-http TraceLayer (#895)
sjenning Apr 21, 2026
bd11395
feat(server): serve health endpoints on separate unauthenticated port…
sjenning Apr 21, 2026
42c3cf6
fix(k8s-driver): use dedicated kube client without read_timeout for w…
sjenning Apr 21, 2026
cbcc4b7
feat(server): allow disabling health check listener (#915)
TaylorMutch Apr 22, 2026
78b685e
feat: add configurable timeout for image transfer to gateway containe…
tmckayus Apr 22, 2026
e28ca07
fix(sandbox): preserve explicit read-only baseline paths (#910)
johntmyers Apr 22, 2026
f954e59
fix(sandbox): resolve sandbox host aliases in SSRF checks (#912)
johntmyers Apr 22, 2026
2f8e8ac
fix(sandbox): inject GIT_SSL_CAINFO so git clone trusts the sandbox C…
laitingsheng Apr 22, 2026
30ddca4
ci(e2e): enable E2E to run on external forks throught the copy-pr-bot…
pimlock Apr 22, 2026
4483c86
feat(server,driver-vm,e2e): gateway-owned readiness + VM compute driv…
drew Apr 22, 2026
d0a29b6
fix(driver-vm): preflight supervisor cross-compile toolchain in start…
pimlock Apr 23, 2026
89dd10b
fix(ci): e2e gate must verify work actually ran, not just top-level s…
pimlock Apr 23, 2026
c6f5792
fix(ci): bump ci-image tooling versions to address vendored CVEs (#929)
johntmyers Apr 23, 2026
c5d5855
fix(ci): bump helm to 4.1.4 to address plugin vulnerabilities (#928)
johntmyers Apr 23, 2026
8405cea
fix(skills): remove --assignee @me from gh pr/issue create commands (…
sjenning Apr 23, 2026
b19a3dc
chore(mise): replace deprecated ubi: prefix by github: prefix (#923)
benoitf Apr 23, 2026
9bc2e2c
fix(ci): rename mise --no-prepare to --no-deps (#942)
pimlock Apr 23, 2026
3b7d309
feat(server): add Prometheus metrics infrastructure and gRPC/HTTP req…
sjenning Apr 23, 2026
ab3f3e0
fix(ci): post E2E Gate check to the PR when workflow_run fires (#938)
pimlock Apr 23, 2026
550c6e4
chore(helm): remove unused ClusterRole and ClusterRoleBinding (#943)
TaylorMutch Apr 23, 2026
0a09404
feat(ci): add shadow-shared-cpu-spike workflow for OS-49 Phase 2 (#934)
jtoelke2 Apr 23, 2026
75b880b
chore(ci): add ARC baseline collector for OS-49 runner migration (#927)
jtoelke2 Apr 23, 2026
ef2d993
fix(ci): expose GHA sccache env in shadow-shared-cpu-spike (#950)
jtoelke2 Apr 24, 2026
a4dfa5a
feat(ci): add driver input to setup-buildx action (#941)
jtoelke2 Apr 24, 2026
0d301d5
fix(cli): preserve directory basename when uploading to sandbox (#952)
mjamiv Apr 24, 2026
7f8e210
fix(sandbox): route console logs to stderr (#949)
johntmyers Apr 24, 2026
87f50f5
fix(e2e): add /dev/urandom to provider test sandbox policy (#948)
derekwaynecarr Apr 24, 2026
a34b25a
test(e2e): fix rust upload path assertions (#960)
drew Apr 24, 2026
8cf5ebd
test(e2e): fix gitignore upload assertion path (#962)
johntmyers Apr 24, 2026
77a88c3
fix(ci): partition GHA sccache cache per arch in shadow spike (#961)
jtoelke2 Apr 24, 2026
d44d8a1
feat: Openshell driver podman (#904)
maxamillion Apr 24, 2026
df38d1f
feat(ci): add Markdown and Mermaid linting (#933)
pimlock Apr 24, 2026
8a3c0b0
feat(docker): add BINARY_SOURCE selector for prebuilt Rust binaries (…
jtoelke2 Apr 24, 2026
25c827d
test(e2e): fix filtered upload path assertion (#963)
drew Apr 24, 2026
d331ed5
feat(ci): add shadow-docker-build workflow for OS-49 Phase 3 (#964)
jtoelke2 Apr 24, 2026
daa7d7d
fix(ci): use nv-gha-runners buildkit mirror to avoid Docker Hub rate …
jtoelke2 Apr 24, 2026
a01b6dd
fix(docs): scope fenced code language linting (#965)
pimlock Apr 24, 2026
55b0266
fix(ci): make buildkitd-config opt-in for setup-buildx (#970)
jtoelke2 Apr 24, 2026
bb5bdb4
fix(ci): ignore local artifacts in license checks (#974)
johntmyers Apr 24, 2026
f8fb382
fix(scripts): handle docker cleanup when no containers are running (#…
derekwaynecarr Apr 27, 2026
5e28ea3
feat(server): add object meta convention to top-level objects (#919)
derekwaynecarr Apr 27, 2026
30115bd
fix(ci): patch CI container vulnerability toolchain (#959)
johntmyers Apr 27, 2026
e5360b3
docs(rfc): add core architecture RFC (#836)
drew Apr 27, 2026
de9dce0
fix(e2e): use high UID range to avoid host user conflicts (#978)
derekwaynecarr Apr 27, 2026
e703b59
ci(e2e): add label dispatcher and contributor CI docs (#975)
pimlock Apr 27, 2026
c428664
ci(e2e): replace label dispatcher with comment-only helper (#990)
pimlock Apr 27, 2026
aee7443
fix(deps): add missing cargo-zigbuild dep for macOS cross-compilation…
benoitf Apr 27, 2026
cde20dc
docs: weekly documentation refresh (#993)
miyoungc Apr 27, 2026
2646b8c
fix(sandbox): deny ambiguous socket ownership (#958)
johntmyers Apr 27, 2026
c890f0e
chore(ci): relax agent diagnostic gate (#1001)
johntmyers Apr 27, 2026
b264cb8
chore(mise): add lockfile with multi-platform support and version pin…
pimlock Apr 27, 2026
385855c
fix(podman): use podman machine socket path on macOS (#999)
benoitf Apr 27, 2026
5975805
feat(server): add bundled docker compute driver (#888)
drew Apr 28, 2026
c49ae09
fix(ci): grant actions:read and contents:read to E2E label helper (#995)
pimlock Apr 28, 2026
cd5c16d
chore(tools): sync mise version to v2026.4.25 (#1013)
TaylorMutch Apr 28, 2026
3e69c36
feat(ci): add shadow-rust-native-build workflow for OS-49 Phase 4 (PR…
jtoelke2 Apr 28, 2026
d414e69
refactor(server): unify policy persistence in objects table (#972)
johntmyers Apr 28, 2026
20ffc72
fix(cli): preserve directory basename for filtered uploads (#1028)
johntmyers Apr 29, 2026
4510b0d
fix(net): catch IPv4-mapped blocked ranges in is_always_blocked_net (…
mesutoezdil Apr 29, 2026
c0ffa93
feat(openshell-vm): allow to have tty with exec (#939)
benoitf Apr 29, 2026
2adddaa
feat: Adding qemu vm driver support with GPU pass-through (#992)
vince-brisebois Apr 29, 2026
2472474
ci(rust): enforce -D warnings on clippy (#1008)
drew Apr 29, 2026
0914f3f
fix(sandbox): log L7 parse denials (#1072)
johntmyers Apr 29, 2026
ee2de81
fix(sandbox): preserve encoded slash policy from proto (#1073)
pimlock Apr 29, 2026
a656ed7
ci(docker): use prebuilt Rust binaries by default (#1027)
jtoelke2 Apr 30, 2026
78f0b6f
ci(rust): keep sccache stats non-blocking
jtoelke2 Apr 30, 2026
ebbd9de
docs(examples): add multi-agent notepad demo (#991)
zredlined Apr 30, 2026
5c77b06
ci: add OS-49 phase 5 shadow workflows (#1075)
jtoelke2 Apr 30, 2026
0845054
feat(auth): add OIDC/Keycloak authentication with RBAC and scope-base…
mrunalp Apr 30, 2026
2942c21
feat(server): add auto-detection of compute driver at startup
sjenning Apr 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
1 change: 0 additions & 1 deletion .agents/skills/build-from-issue/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -478,7 +478,6 @@ Create the PR:
```bash
gh pr create \
--title "<type>(<scope>): <short description>" \
--assignee "@me" \
--body "$(cat <<'EOF'
> **🏗️ build-from-issue-agent**

Expand Down
1 change: 0 additions & 1 deletion .agents/skills/create-github-issue/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,7 +114,6 @@ GitHub built-in issue types (`Bug`, `Feature`, `Task`) should come from the matc
| `--title, -t` | Issue title (required) |
| `--body, -b` | Issue description |
| `--label, -l` | Add label (can use multiple times) |
| `--assignee, -a` | Assign to user |
| `--milestone, -m` | Add to milestone |
| `--project, -p` | Add to project |
| `--web` | Open in browser after creation |
Expand Down
21 changes: 1 addition & 20 deletions .agents/skills/create-github-pr/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -99,30 +99,13 @@ gh pr create --title "PR title" --body "PR description"
- `refactor(models): simplify deployment logic`
- `chore(ci): update Python version in pipeline`

## Required PR Fields

Every PR **must** have:

1. **Assignee** - Always assign to yourself

## Assignee and Reviewer

### Always Assign to Yourself

**Every PR must be assigned to the user creating it.** Use the `--assignee` flag:

```bash
gh pr create --title "Title" --assignee "@me"
```

### Link to an Issue

Use `Closes #<issue-number>` in the body to auto-close the issue when merged:

```bash
gh pr create \
--title "Fix validation error for empty requests" \
--assignee "@me" \
--body "Closes #123

## Summary
Expand All @@ -135,7 +118,7 @@ gh pr create \
For work-in-progress that's not ready for review:

```bash
gh pr create --draft --title "WIP: New feature" --assignee "@me"
gh pr create --draft --title "WIP: New feature"
```

### With Labels
Expand Down Expand Up @@ -185,7 +168,6 @@ Populate the testing checklist based on what was actually run. Check boxes for s
```bash
gh pr create \
--title "feat(cli): add pagination to sandbox list" \
--assignee "@me" \
--body "$(cat <<'EOF'
## Summary

Expand Down Expand Up @@ -222,7 +204,6 @@ EOF
| ------------------- | ------------------------------------------ |
| `--title, -t` | PR title (use conventional commit format) |
| `--body, -b` | PR description |
| `--assignee, -a` | Assign to user (use `@me` for yourself) |
| `--reviewer, -r` | Request review from user |
| `--draft` | Create as draft (WIP) |
| `--label, -l` | Add label (can use multiple times) |
Expand Down
49 changes: 32 additions & 17 deletions .agents/skills/debug-openshell-cluster/SKILL.md

Large diffs are not rendered by default.

1 change: 0 additions & 1 deletion .agents/skills/fix-security-issue/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -207,7 +207,6 @@ Create a PR that closes the security issue. Put the full fix summary in the PR d
```bash
gh pr create \
--title "fix(security): <short description>" \
--assignee "@me" \
--label "topic:security" \
--body "$(cat <<'EOF'
> **🔧 security-fix-agent**
Expand Down
13 changes: 9 additions & 4 deletions .agents/skills/openshell-cli/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -421,10 +421,14 @@ Watch for `deny` actions that indicate the user's work is being blocked by polic

When denied actions are observed:

1. Pull current policy: `openshell policy get work-session --full > policy.yaml`
2. Modify the policy to allow the blocked actions (use `generate-sandbox-policy` skill for content)
3. Push the update: `openshell policy set work-session --policy policy.yaml --wait`
4. Verify: `openshell policy list work-session`
1. Prefer incremental updates for additive network changes:
`openshell policy update work-session --add-endpoint api.github.com:443:read-only:rest:enforce --binary /usr/bin/gh --wait`
`openshell policy update work-session --add-allow 'api.github.com:443:POST:/repos/*/issues' --wait`
2. Use full YAML replacement when the change is broad or touches non-network fields:
`openshell policy get work-session --full > policy.yaml`
Modify the policy to allow the blocked actions (use `generate-sandbox-policy` skill for content)
`openshell policy set work-session --policy policy.yaml --wait`
3. Verify: `openshell policy list work-session`

The user does not need to disconnect -- policy updates are hot-reloaded within ~30 seconds (or immediately when using `--wait`, which polls for confirmation).

Expand Down Expand Up @@ -543,6 +547,7 @@ $ openshell sandbox upload --help
| Create with custom policy | `openshell sandbox create --policy ./p.yaml` |
| Connect to sandbox | `openshell sandbox connect <name>` |
| Stream live logs | `openshell logs <name> --tail` |
| Incremental policy update | `openshell policy update <name> --add-endpoint host:443:read-only:rest:enforce --binary /usr/bin/curl --wait` |
| Pull current policy | `openshell policy get <name> --full > p.yaml` |
| Push updated policy | `openshell policy set <name> --policy p.yaml --wait` |
| Policy revision history | `openshell policy list <name>` |
Expand Down
31 changes: 29 additions & 2 deletions .agents/skills/openshell-cli/cli-reference.md
Original file line number Diff line number Diff line change
Expand Up @@ -181,7 +181,11 @@ Create a sandbox, wait for readiness, then connect or execute the trailing comma

### `openshell sandbox get <name>`

Show sandbox details (id, name, namespace, phase, policy).
Show sandbox details (id, name, namespace, phase) and the **active** policy from the gateway (same source whether policy is sandbox-scoped or global). Metadata includes **Policy source** (`sandbox` or `global`) and **Revision** (global policy row when source is global, otherwise sandbox policy row).

| Flag | Description |
|------|-------------|
| `--policy-only` | Print only the active policy YAML to stdout (same policy as above; use for scripts and piping) |

### `openshell sandbox list`

Expand Down Expand Up @@ -268,9 +272,32 @@ View sandbox logs. Supports one-shot and streaming.

## Policy Commands

### `openshell policy update <name>`

Incrementally merge live network policy changes into the current sandbox policy. Multiple flags in one invocation are applied as one atomic batch and create at most one new revision.

| Flag | Default | Description |
|------|---------|-------------|
| `--add-endpoint <SPEC>` | repeatable | `host:port[:access[:protocol[:enforcement]]]`. Adds or merges an endpoint. `access`: `read-only`, `read-write`, `full`. `protocol`: `rest`, `sql`. `enforcement`: `enforce`, `audit`. |
| `--remove-endpoint <SPEC>` | repeatable | `host:port`. Removes the endpoint or just the requested port from a multi-port endpoint. |
| `--add-allow <SPEC>` | repeatable | `host:port:METHOD:path_glob`. Adds REST allow rules to an existing `protocol: rest` endpoint. |
| `--add-deny <SPEC>` | repeatable | `host:port:METHOD:path_glob`. Adds REST deny rules to an existing `protocol: rest` endpoint that already has an allow base. |
| `--remove-rule <NAME>` | repeatable | Deletes a named network rule. |
| `--binary <PATH>` | repeatable | Adds binaries to each `--add-endpoint` rule. Valid only with `--add-endpoint`. |
| `--rule-name <NAME>` | none | Overrides the generated rule name. Valid only when exactly one `--add-endpoint` is provided. |
| `--dry-run` | false | Preview the merged policy locally without sending an update to the gateway. |
| `--wait` | false | Wait for the sandbox to confirm the new policy revision is loaded. |
| `--timeout <SECS>` | 60 | Timeout for `--wait`. |

Notes:

- `--add-allow` and `--add-deny` currently operate only on `protocol: rest` endpoints.
- `--wait` cannot be combined with `--dry-run`.
- Use `policy set` when replacing the full policy or changing static sections.

### `openshell policy set <name> --policy <PATH>`

Update the policy on a live sandbox. Only the dynamic `network_policies` field can be changed at runtime.
Replace the full policy on a live sandbox. Only the dynamic `network_policies` field can be changed at runtime.

| Flag | Default | Description |
|------|---------|-------------|
Expand Down
14 changes: 1 addition & 13 deletions .agents/skills/triage-issue/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,19 +85,7 @@ Check whether the issue body contains a substantive agent diagnostic section. Lo
```bash
gh issue edit <id> --add-label "state:triage-needed"
```
2. Post a comment with the triage marker:
```
> **📋 triage-agent**
>
> This issue was opened without an agent investigation.
>
> OpenShell is an agent-first project - before we triage this, please point your coding agent at the repo and have it investigate. Your agent can load skills like `debug-openshell-cluster` (for cluster issues), `debug-inference` (for inference setup issues), `openshell-cli` (for usage questions), or `generate-sandbox-policy` (for policy help).
>
> See [CONTRIBUTING.md](https://github.com/NVIDIA/OpenShell/blob/main/CONTRIBUTING.md#before-you-open-an-issue) for the full workflow.
>
> **Classification:** needs-more-info (agent diagnostic required)
```
3. Stop. Do not proceed with diagnosis until the reporter provides diagnostics.
2. Do not post a standalone redirect comment. Report the missing diagnostic to the operator and stop unless a human explicitly asks you to continue triage anyway.

**If the diagnostic section is substantive**, proceed to Step 4.

Expand Down
62 changes: 62 additions & 0 deletions .github/actions/pr-gate/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
name: PR Gate
description: >
Resolve PR metadata for a `pull-request/<N>` push from copy-pr-bot and decide
whether the workflow should run. Sets `should-run=true` only when the pushed
SHA still matches the PR head SHA. If `required_label` is provided, the PR
must also carry that label. For non-`push` events (e.g. `workflow_dispatch`),
always sets `should-run=true`.

inputs:
required_label:
description: Optional PR label required to enable the run (e.g. "test:e2e").
required: false
default: ""

outputs:
should_run:
description: "true if the workflow should proceed, false otherwise"
value: ${{ steps.gate.outputs.should_run }}

runs:
using: composite
steps:
- id: get_pr_info
if: github.event_name == 'push'
continue-on-error: true
uses: nv-gha-runners/get-pr-info@main

- id: gate
shell: bash
env:
EVENT_NAME: ${{ github.event_name }}
GITHUB_SHA_VALUE: ${{ github.sha }}
GET_PR_INFO_OUTCOME: ${{ steps.get_pr_info.outcome }}
PR_INFO: ${{ steps.get_pr_info.outputs.pr-info }}
REQUIRED_LABEL: ${{ inputs.required_label }}
run: |
if [ "$EVENT_NAME" != "push" ]; then
echo "should_run=true" >> "$GITHUB_OUTPUT"
exit 0
fi

if [ "$GET_PR_INFO_OUTCOME" != "success" ]; then
echo "should_run=false" >> "$GITHUB_OUTPUT"
exit 0
fi

head_sha="$(jq -r '.head.sha' <<< "$PR_INFO")"
if [ -z "$REQUIRED_LABEL" ]; then
has_label=true
else
has_label="$(jq -r --arg L "$REQUIRED_LABEL" '[.labels[].name] | index($L) != null' <<< "$PR_INFO")"
fi

# Only trust copied pull-request/* pushes that still match the PR head
# SHA and, when configured, carry the required label.
if [ "$head_sha" = "$GITHUB_SHA_VALUE" ] && [ "$has_label" = "true" ]; then
should_run=true
else
should_run=false
fi

echo "should_run=$should_run" >> "$GITHUB_OUTPUT"
39 changes: 33 additions & 6 deletions .github/actions/setup-buildx/action.yml
Original file line number Diff line number Diff line change
@@ -1,24 +1,41 @@
name: Setup Docker Buildx
description: >
Create a multi-arch Docker Buildx builder using remote BuildKit nodes.
The builder is automatically removed when the job finishes (cleanup is
enabled by default in docker/setup-buildx-action).
Create a Docker Buildx builder. Two modes:
* driver=remote (default) — multi-arch builder against in-cluster BuildKit
pods. Requires EKS connectivity. Behaviour unchanged from prior versions.
* driver=local — single-node buildx on the local docker-container driver.
Pair with cache-to/cache-from=type=gha on build steps for persistence.
Works on nv-gha-runners; no EKS needed.
Cleanup is automatic when the job finishes (docker/setup-buildx-action default).

inputs:
driver:
description: "buildx driver: 'remote' or 'local'"
default: remote
amd64-endpoint:
description: BuildKit endpoint for linux/amd64
description: BuildKit endpoint for linux/amd64 (remote driver only)
default: tcp://buildkit-amd64.buildkit:1234
arm64-endpoint:
description: BuildKit endpoint for linux/arm64
description: BuildKit endpoint for linux/arm64 (remote driver only)
default: tcp://buildkit-arm64.buildkit:1234
name:
description: Builder instance name
default: openshell
buildkitd-config:
description: >
Path to a buildkitd.toml to configure the builder with (e.g. the
nv-gha-runners Docker Hub mirror at /etc/buildkit/buildkitd.toml).
Must be readable *from where this action runs* — in a containerized
job that means the caller must bind-mount the host path into the job
container (e.g. `volumes: [/etc/buildkit:/etc/buildkit:ro]`). Empty
disables the config (default).
default: ""

runs:
using: composite
steps:
- name: Set up Docker Buildx
- name: Set up Docker Buildx (remote)
if: inputs.driver == 'remote'
uses: docker/setup-buildx-action@v3
with:
name: ${{ inputs.name }}
Expand All @@ -28,3 +45,13 @@ runs:
append: |
- endpoint: ${{ inputs.arm64-endpoint }}
platforms: linux/arm64
buildkitd-config: ${{ inputs.buildkitd-config }}

- name: Set up Docker Buildx (local)
if: inputs.driver == 'local'
uses: docker/setup-buildx-action@v3
with:
name: ${{ inputs.name }}
driver: docker-container
platforms: linux/amd64,linux/arm64
buildkitd-config: ${{ inputs.buildkitd-config }}
54 changes: 51 additions & 3 deletions .github/workflows/branch-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,37 @@ permissions:
packages: read

jobs:
mise-lockfile:
name: mise Lockfile
runs-on: build-amd64
container:
image: ghcr.io/nvidia/openshell/ci:latest
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
steps:
- uses: actions/checkout@v4

- name: Mark workspace as safe for git
run: git config --global --add safe.directory "$GITHUB_WORKSPACE"

- name: Detect mise config changes
id: changed
uses: tj-actions/changed-files@aa08304bd477b800d468db44fe10f6c61f7f7b11 # v42.1.0
with:
files: |
mise.toml
mise.lock

- name: Verify mise.lock is in sync with mise.toml
if: steps.changed.outputs.any_changed == 'true'
run: |
mise lock
if ! git diff --exit-code mise.lock; then
echo "::error::mise.lock is out of sync with mise.toml. Run 'mise lock' locally and commit the result." >&2
exit 1
fi

license-headers:
name: License Headers
runs-on: build-amd64
Expand All @@ -25,7 +56,7 @@ jobs:
- uses: actions/checkout@v4

- name: Install tools
run: mise install
run: mise install --locked

- name: Check license headers
run: mise run license:check
Expand All @@ -46,7 +77,7 @@ jobs:
- uses: actions/checkout@v4

- name: Install tools
run: mise install
run: mise install --locked

- name: Configure sccache remote cache
if: vars.SCCACHE_MEMCACHED_ENDPOINT != ''
Expand Down Expand Up @@ -90,7 +121,7 @@ jobs:
- uses: actions/checkout@v4

- name: Install tools
run: mise install
run: mise install --locked

- name: Install dependencies
run: uv sync --frozen
Expand All @@ -100,3 +131,20 @@ jobs:

- name: Test
run: mise run test:python

markdown:
name: Markdown
runs-on: build-amd64
container:
image: ghcr.io/nvidia/openshell/ci:latest
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
steps:
- uses: actions/checkout@v4

- name: Install tools
run: mise install

- name: Lint
run: mise run markdown:lint
Loading
Loading