Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 7 additions & 7 deletions .github/workflows/advisory-review-agent.yml
Original file line number Diff line number Diff line change
Expand Up @@ -164,20 +164,20 @@ jobs:
# An empty ssh-key is ignored by actions/checkout (token auth is enough
# for a public or same-repo reviewer); a private reviewer repo needs it.
- name: Check out the reviewer
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: ${{ inputs.reviewer_repo }}
ref: ${{ inputs.reviewer_ref }}
ssh-key: ${{ secrets.checkout_ssh_key }}
path: .autoresearch
persist-credentials: false
- name: Check out the PR head (read-only; never executed)
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
ref: refs/pull/${{ env.PR_NUMBER }}/head
path: pr-head
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: .autoresearch/uv.lock
Expand Down Expand Up @@ -288,7 +288,7 @@ jobs:
# not `success()`: a session step that died AFTER emitting must still
# deliver its findings (or its skip-stub) to the posting job
if: ${{ !cancelled() }}
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: review-findings-${{ inputs.opinion_id || inputs.backend }}-${{ env.PR_NUMBER }}
path: ${{ runner.temp }}/findings.json
Expand All @@ -311,14 +311,14 @@ jobs:
PR_NUMBER: ${{ github.event.pull_request.number }}
steps:
- name: Check out the reviewer
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: ${{ inputs.reviewer_repo }}
ref: ${{ inputs.reviewer_ref }}
ssh-key: ${{ secrets.checkout_ssh_key }}
path: .autoresearch
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: .autoresearch/uv.lock
Expand All @@ -330,7 +330,7 @@ jobs:
# caller's PR stays green; the job is continue-on-error at job
# level). Observed live 2026-08-15: errored terra sessions posted
# nothing and read as quiet clean days.
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
name: review-findings-${{ inputs.opinion_id || inputs.backend }}-${{ env.PR_NUMBER }}
path: ${{ runner.temp }}
Expand Down
14 changes: 7 additions & 7 deletions .github/workflows/advisory-review-summarize.yml
Original file line number Diff line number Diff line change
Expand Up @@ -96,14 +96,14 @@ jobs:
HERMES_SHA: f80f453ae0679347e38abc917c7f94f717bf96c5
steps:
- name: Check out the reviewer
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: ${{ inputs.reviewer_repo }}
ref: ${{ inputs.reviewer_ref }}
ssh-key: ${{ secrets.checkout_ssh_key }}
path: .autoresearch
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: .autoresearch/uv.lock
Expand Down Expand Up @@ -168,7 +168,7 @@ jobs:
# NO required-download here: the summarizer CLI itself turns "no
# envelopes" into a visible skip-stub, so a died-before-emitting lens
# set still surfaces on the PR rather than failing into silence.
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
pattern: review-findings-lens-*-${{ env.PR_NUMBER }}
path: ${{ runner.temp }}/opinions
Expand Down Expand Up @@ -204,7 +204,7 @@ jobs:
fi
- name: Upload merged findings
if: ${{ !cancelled() }}
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: review-findings-summary-${{ env.PR_NUMBER }}
path: ${{ runner.temp }}/findings.json
Expand All @@ -224,20 +224,20 @@ jobs:
PR_NUMBER: ${{ github.event.pull_request.number }}
steps:
- name: Check out the reviewer
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: ${{ inputs.reviewer_repo }}
ref: ${{ inputs.reviewer_ref }}
ssh-key: ${{ secrets.checkout_ssh_key }}
path: .autoresearch
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: .autoresearch/uv.lock
- name: Download merged findings
id: findings
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
name: review-findings-summary-${{ env.PR_NUMBER }}
path: ${{ runner.temp }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ jobs:
runs-on: ubuntu-24.04
timeout-minutes: 60
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
- uses: eWaterCycle/setup-apptainer@v2
- name: Build
run: sudo -E apptainer build --force agent-py312.sif containers/agent-py312.def
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,11 +20,11 @@ jobs:
ci:
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
# Full history: gitleaks scans it (this repo handles credentials).
fetch-depth: 0
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
- run: uv sync --locked
Expand Down
22 changes: 11 additions & 11 deletions .github/workflows/maintenance-agent.yml
Original file line number Diff line number Diff line change
Expand Up @@ -100,19 +100,19 @@ jobs:
HERMES_SHA: f80f453ae0679347e38abc917c7f94f717bf96c5
steps:
- name: Check out the kernel
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: ${{ inputs.reviewer_repo }}
ref: ${{ inputs.reviewer_ref }}
path: .autoresearch
persist-credentials: false
- name: Check out the tree to scan (the default branch's resolved commit)
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
ref: ${{ needs.resolve.outputs.sha }}
path: tree
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: .autoresearch/uv.lock
Expand Down Expand Up @@ -195,7 +195,7 @@ jobs:
fi
- name: Upload findings
if: ${{ !cancelled() }}
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: maintenance-findings-lens-${{ matrix.lens }}-${{ github.run_id }}
path: ${{ runner.temp }}/findings.json
Expand All @@ -217,13 +217,13 @@ jobs:
HERMES_SHA: f80f453ae0679347e38abc917c7f94f717bf96c5
steps:
- name: Check out the kernel
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: ${{ inputs.reviewer_repo }}
ref: ${{ inputs.reviewer_ref }}
path: .autoresearch
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: .autoresearch/uv.lock
Expand Down Expand Up @@ -276,7 +276,7 @@ jobs:
;;
esac
- name: Download lens opinions
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
pattern: maintenance-findings-lens-*-${{ github.run_id }}
path: ${{ runner.temp }}/opinions
Expand Down Expand Up @@ -311,7 +311,7 @@ jobs:
fi
- name: Upload the merged digest
if: ${{ !cancelled() }}
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: maintenance-findings-summary-${{ github.run_id }}
path: ${{ runner.temp }}/findings.json
Expand All @@ -330,19 +330,19 @@ jobs:
issues: write
steps:
- name: Check out the kernel
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: ${{ inputs.reviewer_repo }}
ref: ${{ inputs.reviewer_ref }}
path: .autoresearch
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: .autoresearch/uv.lock
- name: Download the merged digest
id: findings
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
name: maintenance-findings-summary-${{ github.run_id }}
path: ${{ runner.temp }}
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,10 @@ jobs:
build:
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v6
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@v10.0.1
- run: uv build
- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v7
with:
name: dist
path: dist/
Expand All @@ -33,7 +33,7 @@ jobs:
permissions:
id-token: write # mint the OIDC token Trusted Publishing exchanges
steps:
- uses: actions/download-artifact@v4
- uses: actions/download-artifact@v8
with:
name: dist
path: dist/
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/review-agent.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,17 +50,17 @@ jobs:
BACKEND: ${{ inputs.backend }}
steps:
- name: Check out the reviewer
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
path: .autoresearch
persist-credentials: false
- name: Check out the PR head (read-only; never executed)
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
ref: refs/pull/${{ inputs.pr_number }}/head
path: pr-head
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: .autoresearch/uv.lock
Expand Down
16 changes: 8 additions & 8 deletions .github/workflows/verify-agent.yml
Original file line number Diff line number Diff line change
Expand Up @@ -120,28 +120,28 @@ jobs:
# force-owns (recreates) before the session; a colliding checkout there
# would be destroyed.
- name: Check out the verifier
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: ${{ inputs.verifier_repo }}
ref: ${{ inputs.verifier_ref }}
ssh-key: ${{ secrets.checkout_ssh_key }}
path: kernel
persist-credentials: false
- name: Check out the PR head (the change under review)
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
ref: refs/pull/${{ env.PR_NUMBER }}/head
path: pr-head
persist-credentials: false
# The base tree carries the TRUSTED contract and ruler — the brief
# directs all ruler reads here, never at the PR head.
- name: Check out the base branch (trusted contract + ruler)
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
ref: ${{ github.event.pull_request.base.ref }}
path: base
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: kernel/uv.lock
Expand Down Expand Up @@ -183,7 +183,7 @@ jobs:
- name: Upload the verdict
# not success(): a session that died AFTER emitting must still deliver
if: ${{ !cancelled() }}
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: verify-verdict-${{ env.PR_NUMBER }}
path: ${{ runner.temp }}/verdict.json
Expand Down Expand Up @@ -211,14 +211,14 @@ jobs:
PR_NUMBER: ${{ github.event.pull_request.number }}
steps:
- name: Check out the verifier
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: ${{ inputs.verifier_repo }}
ref: ${{ inputs.verifier_ref }}
ssh-key: ${{ secrets.checkout_ssh_key }}
path: kernel
persist-credentials: false
- uses: astral-sh/setup-uv@v6
- uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
cache-dependency-glob: kernel/uv.lock
Expand All @@ -227,7 +227,7 @@ jobs:
# NO continue-on-error: every session outcome uploads an envelope, so a
# missing artifact means the session died before emitting — fail this
# job visibly (the caller's PR stays green; job is continue-on-error).
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
name: verify-verdict-${{ env.PR_NUMBER }}
path: ${{ runner.temp }}
Expand Down
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -652,6 +652,11 @@ Versions follow [SemVer](https://semver.org).

### Changed

- CI and reusable-workflow Actions bumped to current majors: actions/checkout
v7, astral-sh/setup-uv v10, upload-artifact v7, download-artifact v8. The
single-name artifact downloads stay flat and the pattern download reads
recursively, so the review split is unaffected; the node24 runtime is on the
hosted runners.
- The tick reads its run records once per phase instead of once per service: a
single snapshot after the mutation phase feeds the read services, and one
feeds the board pass. About twelve full run-directory scans per tick become
Expand Down
Loading