Files
AIPass/.github/workflows/e2e-wheel.yml
T
AIOSAIandClaude Opus 4.8 dab8d29645 security(ci): add least-privilege permissions block to e2e-wheel workflow
e2e-wheel.yml was the only workflow missing a top-level permissions: block
(added during cross-OS work after PR #624 hardened the rest), so it ran with
default broad GITHUB_TOKEN scopes -> OpenSSF Scorecard Token-Permissions = 0.
Add 'permissions: contents: read' to match the other 7 workflows. CHANGELOG
W24 entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-08 10:09:00 -07:00

56 lines
1.7 KiB
YAML

name: e2e-wheel
# Cross-OS end-to-end WIRING test (FPLAN-0239, P1 of DPLAN-0194).
# Builds the wheel, installs it into a clean venv (handled by the pytest
# fixtures in tests/e2e/conftest.py), and runs the 4-tier wiring ladder.
#
# RED-FIRST: Windows is EXPECTED to fail in known places (symlink init,
# bin-vs-Scripts, /tmp). Do not "fix" Windows here — the red is the deliverable.
on:
push:
branches: [main, dev]
paths:
- "tests/e2e/**"
- ".github/workflows/e2e-wheel.yml"
- "pyproject.toml"
- "src/**"
pull_request:
paths:
- "tests/e2e/**"
- ".github/workflows/e2e-wheel.yml"
- "pyproject.toml"
- "src/**"
workflow_dispatch:
# Least-privilege token (Scorecard Token-Permissions). This workflow only
# reads the repo to build + smoke-test the wheel; it needs no write scopes.
permissions:
contents: read
jobs:
e2e-wheel:
name: e2e-wheel (${{ matrix.os }})
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]
python-version: ["3.12"]
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version: ${{ matrix.python-version }}
- name: Install build tooling
run: python -m pip install --upgrade pip build pytest
- name: Run cross-OS e2e wiring harness
# conftest.py builds the wheel + clean venv internally; the outer env
# only needs build + pytest.
run: python -m pytest tests/e2e -v