Repository navigation
172 lines (165 loc) · 6.87 KB
/
Copy pathjudgement.yml
File metadata and controls
172 lines (165 loc) · 6.87 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
name: Judgement
on:
pull_request_target:
branches: [main, develop]
types: [opened, synchronize, reopened, ready_for_review, edited]
permissions: {}
concurrency:
group: judgement-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
pending:
name: Mark Judgement pending
runs-on: ubuntu-24.04
permissions:
statuses: write
steps:
- name: Mark the PR check pending
env:
GH_TOKEN: ${{ github.token }}
PR_HEAD: ${{ github.event.pull_request.head.sha }}
run: |
gh api --silent "repos/$GITHUB_REPOSITORY/statuses/$PR_HEAD" \
-f state=pending -f context=Judgement \
-f description='Checking repository rules' \
-f target_url="$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID"
collect:
name: Collect Git evidence
needs: pending
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: read
outputs:
base: ${{ steps.export.outputs.base }}
env:
PR_HEAD: ${{ github.event.pull_request.head.sha }}
PR_BASE: ${{ github.event.pull_request.base.sha }}
steps:
# This job has no inference secret or repository write permission.
- name: Checkout trusted base
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: ${{ github.event.pull_request.base.sha }}
fetch-depth: 0
persist-credentials: false
- name: Export snapshot objects
id: export
run: |
set -euo pipefail
[[ "$PR_HEAD" =~ ^[0-9a-f]{40}$ && "$PR_BASE" =~ ^[0-9a-f]{40}$ ]]
git fetch --no-tags origin "$PR_HEAD"
base="$(git merge-base "$PR_BASE" "$PR_HEAD")"
git cat-file -e "$base:.judgement/rules.json"
mkdir -p "$RUNNER_TEMP/judgement-evidence"
# Transfer objects only: no worktree, Git config, hooks, or full history.
{
printf '%s\n' "$base" "$PR_HEAD"
git rev-list --objects --no-object-names "$base^{tree}" "$PR_HEAD^{tree}"
} | sort -u | git pack-objects --stdout > "$RUNNER_TEMP/judgement-evidence/objects.pack"
echo "base=$base" >> "$GITHUB_OUTPUT"
- name: Upload snapshot objects
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: judgement-evidence
path: ${{ runner.temp }}/judgement-evidence/objects.pack
if-no-files-found: error
retention-days: 1
compression-level: 0
judgement:
name: Judge Git evidence
needs: collect
outputs:
coverage: ${{ steps.check.outputs.coverage }}
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions: {}
env:
PR_HEAD: ${{ github.event.pull_request.head.sha }}
JUDGEMENT_BASE: ${{ needs.collect.outputs.base }}
steps:
# No repository checkout in this job. The checker is installed separately.
- name: Set up Node
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
with:
node-version: '24.13.1'
- name: Install trusted checker
run: |
mkdir -p "$RUNNER_TEMP/judgement-tool"
cd "$RUNNER_TEMP/judgement-tool"
npm install --ignore-scripts --no-audit --no-fund \
'@roo-code/judgement@0.4.1'
- name: Download snapshot objects
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
name: judgement-evidence
path: ${{ runner.temp }}/judgement-evidence
- name: Import snapshot objects without checkout
id: import
run: |
set -euo pipefail
[[ "$PR_HEAD" =~ ^[0-9a-f]{40}$ && "$JUDGEMENT_BASE" =~ ^[0-9a-f]{40}$ ]]
git init --quiet --template= "$RUNNER_TEMP/judgement-input"
cd "$RUNNER_TEMP/judgement-input"
git index-pack --stdin < "$RUNNER_TEMP/judgement-evidence/objects.pack"
git cat-file -e "$JUDGEMENT_BASE^{commit}"
git cat-file -e "$PR_HEAD^{commit}"
git cat-file -e "$JUDGEMENT_BASE:.judgement/rules.json"
git update-ref refs/heads/evidence "$JUDGEMENT_BASE"
git symbolic-ref HEAD refs/heads/evidence
- name: Check repository rules
id: check
env:
TYPESAFE_API_KEY: ${{ secrets.TYPESAFE_API_KEY }}
JUDGEMENT_MODEL: ${{ vars.JUDGEMENT_MODEL || 'jev-1.13.0' }}
run: |
set -euo pipefail
if [ -z "$TYPESAFE_API_KEY" ]; then
echo 'Configure the TYPESAFE_API_KEY repository secret for Judgement.' >&2
exit 2
fi
result=0
node "$RUNNER_TEMP/judgement-tool/node_modules/@roo-code/judgement/src/cli.js" \
check --cwd "$RUNNER_TEMP/judgement-input" \
--base "$JUDGEMENT_BASE" --head "$PR_HEAD" \
--model "$JUDGEMENT_MODEL" --timeout-ms 120000 --no-cache || result=$?
case "$result" in
0) echo 'coverage=complete' >> "$GITHUB_OUTPUT" ;;
3)
# All incomplete results are non-blocking, including evidence or
# inference failures caught by the checker. Confirmed violations
# take precedence and exit 1, even with partial coverage.
echo 'coverage=incomplete' >> "$GITHUB_OUTPUT"
echo '::warning::Judgement found no violations, but coverage is incomplete. See the check log.'
echo 'Judgement found no violations, but coverage is incomplete. See the check log for unresolved rules.' >> "$GITHUB_STEP_SUMMARY"
;;
*) exit "$result" ;;
esac
report:
name: Publish Judgement result
needs: [pending, collect, judgement]
if: ${{ always() && !cancelled() && needs.pending.result == 'success' }}
runs-on: ubuntu-24.04
permissions:
statuses: write
steps:
# This job receives only the conclusion and coverage flag, never repository contents or secrets.
- name: Publish result
env:
GH_TOKEN: ${{ github.token }}
PR_HEAD: ${{ github.event.pull_request.head.sha }}
CHECK_OUTCOME: ${{ needs.judgement.result }}
CHECK_COVERAGE: ${{ needs.judgement.outputs.coverage }}
run: |
state=failure
description='Judgement failed or did not complete; inspect the run'
if [ "$CHECK_OUTCOME" = success ]; then
state=success
description='Repository rule check completed without findings'
if [ "$CHECK_COVERAGE" = incomplete ]; then
description='No rule violations found; coverage incomplete (see run)'
fi
fi
gh api --silent "repos/$GITHUB_REPOSITORY/statuses/$PR_HEAD" \
-f state="$state" -f context=Judgement -f description="$description" \
-f target_url="$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID"