AIOSAI
9048666c65
ci: OSSF scorecard hardening (DPLAN-0243) — hash-pin all standalone workflow pip installs via .github/requirements/ locks (pip/lint/build/e2e/audit, pip-compile --generate-hashes, 11/11 target-env closure verified incl. Windows colorama marker fix) + provenance attestation on publish (attest-build-provenance v4.1.1 SHA-pinned, id-token+attestations perms) + dependabot pip ecosystem for the new locks. Editable -e . installs untouched byte-identical. 5/5 fresh-venv --require-hashes installs green, 5/5 YAML parse, pinned ruff matches repo lint. First SSH-signed commit (repo config wired this session).
2026-07-15 12:21:22 -07:00
dependabot[bot]
aea90da5c6
ci(deps): bump actions/setup-python from 6.2.0 to 6.3.0
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 6.2.0 to 6.3.0.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...ece7cb06caefa5fff74198d8649806c4678c61a1 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: 6.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-27 08:02:22 +00:00
dependabot[bot]
ef5ae933d0
ci(deps): bump actions/checkout from 6.0.3 to 7.0.0
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-20 08:02:50 +00:00
dependabot[bot]
8a0cc001bd
ci(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0
...
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action ) from 6.0.1 to 7.0.0.
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/codecov/codecov-action/compare/e79a6962e0d4c0c17b229090214935d2e33f8354...fb8b3582c8e4def4969c97caa2f19720cb33a72f )
---
updated-dependencies:
- dependency-name: codecov/codecov-action
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-13 08:02:29 +00:00
dependabot[bot]
285a8a5b5f
ci(deps): bump actions/checkout from 6.0.2 to 6.0.3
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 6.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 07:20:25 +00:00
AIOSAI and Claude Opus 4.8
27a175b2c9
ci(seedgo-audit): install memory extra so pyright resolves chromadb/numpy (DPLAN-0195)
...
Final straggler: memory scored 98% (diagnostics 55% = 9 pyright errors) in CI
while 100% locally. Proven cause: the diagnostics standard runs pyright over
every branch; memory's handlers import chromadb/numpy at module level. These
are declared in the 'memory' optional-dependencies group, NOT 'dev' — and the
audit job installed only '.[dev]', so pyright flagged them unresolved
(reportMissingImports=error) → 9 false errors. My local .venv happens to have
chromadb, which is why local audits read 100%.
Fix: audit job installs '.[dev,memory]'. pyright now resolves memory's real,
declared deps and the standard measures actual type-correctness (and matches a
local audit). api imports openai (llm extra) but guards it lazily, so it stays
100% without that extra — only memory needed this.
12/13 were already green after the readme check-ignore fix; this clears the
13th.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-06 00:32:29 -07:00
AIOSAI
176f68439c
ci(standards): full-history checkout for audit + honest aipass README refresh
2026-06-05 22:29:19 -07:00
AIOSAI and Claude Opus 4.8
668841417f
fix(portability): aipass init UTF-8 stdout on Windows + CI e2e lane (DPLAN-0194)
...
The real T1 Windows bug (diagnosed via the now-reverted error-surfacing
probe): aipass init scaffolds fine, then crashes printing its success
banner — Rich writes the success glyphs through a cp1252 stdout
(UnicodeEncodeError 'charmap'). Same class as the drone fix. The aipass
entry point now reconfigure()s stdout/stderr to UTF-8 in place on Windows.
Also: ci.yml's broad 'pytest --rootdir=.' swept in tests/e2e (which build
a wheel via the dedicated e2e-wheel.yml), failing the unit lane since the
harness landed; now --ignore=tests/e2e in both pytest jobs.
route_command error-surfacing probe reverted to honor 'no function change'
(the masked-error mislabel is noted as a separate @aipass recommendation).
Local: e2e 14/14 green, aipass units 24/24, ruff clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-06-04 01:17:56 -07:00
AIOSAI
efa5aced74
ci: harden workflows — least-privilege permissions + SHA-pinned actions
2026-05-29 23:47:27 -07:00
AIOSAI
dc0c75cb04
fix: move seedgo audit to script file (inline Python broke YAML parsing)
2026-05-14 20:50:59 -07:00
AIOSAI
ea39bacc7c
feat: seedgo audit in CI + windows_compat test skipif enforcement
2026-05-14 20:33:06 -07:00
AIOSAI
453c847359
fix(ci): auto-format on commit, decouple lint from tests, add codecov threshold
2026-05-12 22:41:03 -07:00
AIOSAI and @devpulse
3b8fa1fa5a
feat(system): test
...
Co-Authored-By: @devpulse <devpulse@aipass>
2026-05-12 17:33:34 -07:00
AIOSAI and @devpulse
cd387f9666
feat(system): fix(ci): remove coverage fail-under gate — codecov tracks coverage without blocking CI
...
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-25 21:46:53 -07:00
dependabot[bot]
aeb028437b
ci(deps): bump codecov/codecov-action from 4 to 6 ( #136 )
...
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action ) from 4 to 6.
- [Release notes](https://github.com/codecov/codecov-action/releases )
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/codecov/codecov-action/compare/v4...v6 )
---
updated-dependencies:
- dependency-name: codecov/codecov-action
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-28 10:58:51 -07:00
AIOSAI and Claude Opus 4.6
f30443504c
chore: add hooks, CI/CD infrastructure, ignore runtime JSON
...
- Transfer Claude Code hooks from internal: identity injector, email
notification, auto-fix diagnostics, pre-compact recovery
- Add notification sounds for tool use, stop, and alerts
- Wire all hooks in .claude/settings.json
- Add global system prompt (.aipass/aipass_global_prompt.md)
- Add branch-local prompt placeholders for all modules
- Set up CI pipeline: lint (ruff) → test matrix (3.10-3.13) → coverage
- Add workflows: PyPI publish, security scanning, stale issues
- Add GitHub issue templates, dependabot, editorconfig
- Configure pytest norecursedirs and coverage fail-under=70
- Add *.json to gitignore — runtime JSON files constantly change
- Untrack runtime JSON (registry, plans, seed bypass, module data)
- Keep source JSON tracked via negation rules (json_templates, pack,
spawn templates, settings, pyrightconfig)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-06 20:33:40 -08:00
AIOSAI and Claude Opus 4.6
b564248de2
feat: initial repository scaffold
...
- README with project overview
- pyproject.toml with trinity-pattern dependency
- src/aipass/ package with version
- Basic CI workflow (Python 3.10-3.13, ruff, pytest)
- MIT license
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-27 08:04:44 -08:00