Compare commits

..
Author SHA1 Message Date
dependabot[bot] a4eae3ef31 ci(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.3 to 2.4.4.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](https://github.com/ossf/scorecard-action/compare/4eaacf0543bb3f2c246792bd56e8cdeffafb205a...2d1146689b8cda280b9bc96326124645441f03bc)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-25 08:03:03 +00:00
11 changed files with 53 additions and 58 deletions
+4 -4
View File
@@ -17,7 +17,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.13"
# Hash-pinned tool install (Scorecard: Pinned-Dependencies). Pins ruff to
@@ -34,7 +34,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: ${{ matrix.python-version }}
- run: |
@@ -55,7 +55,7 @@ jobs:
# makes every file look born at HEAD, so every README false-fails as
# "stale". Full history makes CI match a local audit exactly.
fetch-depth: 0
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.13"
- run: |
@@ -77,7 +77,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.13"
- run: |
+1 -1
View File
@@ -42,7 +42,7 @@ jobs:
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: ${{ matrix.python-version }}
+1 -1
View File
@@ -20,7 +20,7 @@ jobs:
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: '3.12'
+1 -1
View File
@@ -21,7 +21,7 @@ jobs:
attestations: write
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.13"
# Hash-pinned tool install (Scorecard: Pinned-Dependencies).
+1 -1
View File
@@ -27,7 +27,7 @@ jobs:
persist-credentials: false
- name: "Run analysis"
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4
with:
results_file: results.sarif
results_format: sarif
+1 -1
View File
@@ -19,7 +19,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.13"
# Upgrade pip first: pip-audit scans the whole environment, and the
+1 -1
View File
@@ -20,7 +20,7 @@ jobs:
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: '3.12'
@@ -5,6 +5,11 @@
"name": ".ai_mail.local",
"path": ".ai_mail.local"
},
"d002": {
"has_branch_placeholder": false,
"name": ".pytest_cache",
"path": ".pytest_cache"
},
"d003": {
"has_branch_placeholder": false,
"name": ".aipass",
@@ -114,6 +119,16 @@
"has_branch_placeholder": false,
"name": "integrations",
"path": "apps/integrations"
},
"d025": {
"has_branch_placeholder": false,
"name": "v",
"path": ".pytest_cache/v"
},
"d026": {
"has_branch_placeholder": false,
"name": "cache",
"path": ".pytest_cache/v/cache"
}
},
"files": {
@@ -196,7 +211,7 @@
"path": ".trinity/observations.json"
},
"f014": {
"content_hash": "98f1e33dace0",
"content_hash": "d523dee2ef39",
"has_branch_placeholder": false,
"name": "passport.json",
"path": ".trinity/passport.json"
@@ -267,6 +282,12 @@
"name": "README.md",
"path": "apps/plugins/README.md"
},
"f026": {
"content_hash": "3ed731b65d06",
"has_branch_placeholder": false,
"name": ".gitignore",
"path": ".pytest_cache/.gitignore"
},
"f027": {
"content_hash": "024209a8c889",
"has_branch_placeholder": true,
@@ -381,6 +402,24 @@
"name": "requirements.project.txt",
"path": "requirements.project.txt"
},
"f046": {
"content_hash": "37dc88ef9a0a",
"has_branch_placeholder": false,
"name": "CACHEDIR.TAG",
"path": ".pytest_cache/CACHEDIR.TAG"
},
"f047": {
"content_hash": "73fd6fccdd80",
"has_branch_placeholder": false,
"name": "README.md",
"path": ".pytest_cache/README.md"
},
"f048": {
"content_hash": "0575fdabafa9",
"has_branch_placeholder": false,
"name": "nodeids",
"path": ".pytest_cache/v/cache/nodeids"
},
"f049": {
"content_hash": "5610e3ccaf8b",
"has_branch_placeholder": false,
@@ -390,7 +429,7 @@
},
"metadata": {
"description": "Template file tracking registry for ID-based updates",
"last_updated": "2026-07-27",
"last_updated": "2026-07-17",
"version": "1.0.0"
}
}
@@ -14,14 +14,12 @@
"alias": "",
"path": "{{CWD}}",
"module": "{{MODULE}}",
"email": "{{EMAIL}}",
"created": "{{DATE}}",
"git_branch": "work/{{branchname}}"
},
"identity": {
"citizen_class": "{{CITIZEN_CLASS}}",
"role": "{{ROLE}}",
"traits": "{{TRAITS}}",
"purpose": "{{PURPOSE_BRIEF}}",
"what_i_do": [],
"what_i_dont_do": []
@@ -14,14 +14,12 @@
"alias": "",
"path": "{{CWD}}",
"module": "{{MODULE}}",
"email": "{{EMAIL}}",
"created": "{{DATE}}",
"git_branch": "main"
},
"identity": {
"citizen_class": "manager",
"role": "{{ROLE}}",
"traits": "{{TRAITS}}",
"purpose": "{{PURPOSE_BRIEF}}",
"what_i_do": [],
"what_i_dont_do": []
+2 -42
View File
@@ -13,9 +13,10 @@ class-aware update, and backward compatibility.
"""
import json
from pathlib import Path
import pytest
from pathlib import Path
# =============================================================================
# CLASS REGISTRY TESTS
@@ -171,7 +172,6 @@ class TestClassAwareUpdate:
def test_update_cli_accepts_class_with_all(self):
"""update aipass_framework --all should parse correctly and call update_all with class filter."""
from unittest.mock import patch
from aipass.spawn.apps.modules.update import handle_update
# Mock update_all to isolate from real branch state
@@ -220,16 +220,6 @@ class TestTemplateStructure:
passport = json.loads((tpl / ".trinity" / "passport.json").read_text())
assert passport["identity"]["citizen_class"] == "{{CITIZEN_CLASS}}"
@pytest.mark.parametrize("class_name", ["aipass_framework", "project_agent"])
def test_template_passport_has_traits_and_email_placeholders(self, class_name):
"""Agent template passports reference TRAITS and EMAIL — unreferenced, both are built and discarded."""
from aipass.spawn.apps.handlers.class_registry import get_template_dir
tpl = get_template_dir(class_name)
passport = json.loads((tpl / ".trinity" / "passport.json").read_text())
assert passport["identity"]["traits"] == "{{TRAITS}}"
assert passport["branch_info"]["email"] == "{{EMAIL}}"
def test_no_agent_template_dir(self):
"""Old agent.template directory should not exist."""
spawn_root = Path(__file__).parents[1]
@@ -296,36 +286,6 @@ class TestAgentScaffoldContent:
passport = json.loads((target / ".trinity" / "passport.json").read_text())
assert passport["identity"]["role"] == "Data Analyst"
def test_created_agent_passport_has_traits(self, tmp_path):
"""Passport should include the agent's traits if provided."""
from aipass.spawn.apps.modules.core import _spawn_agent
target = tmp_path / "traits_test"
_spawn_agent(str(target), role="Analyst", traits="curious, terse", purpose="Reports")
passport = json.loads((target / ".trinity" / "passport.json").read_text())
assert passport["identity"]["traits"] == "curious, terse"
def test_created_agent_passport_traits_empty_without_flag(self, tmp_path):
"""Omitting traits leaves an empty string — the identity hook skips the line when falsy."""
from aipass.spawn.apps.modules.core import _spawn_agent
target = tmp_path / "no_traits_test"
_spawn_agent(str(target), purpose="Testing default")
passport = json.loads((target / ".trinity" / "passport.json").read_text())
assert passport["identity"]["traits"] == ""
def test_created_agent_passport_has_email(self, tmp_path):
"""Passport carries the branch address, so identity does not render 'Email: unknown'."""
from aipass.spawn.apps.modules.core import _spawn_agent
target = tmp_path / "email_test"
_spawn_agent(str(target), purpose="Testing email")
passport = json.loads((target / ".trinity" / "passport.json").read_text())
assert passport["branch_info"]["email"] == "@email_test"
# =============================================================================
# MULTI-AGENT COEXISTENCE TESTS