mirror of
https://github.com/semantica-agi/semantica.git
synced 2026-09-04 04:01:07 +00:00
Distribution and trust-signal infrastructure to make pip install semantica
frictionless in downstream CI, and to bring the release pipeline in line
with mature OSS practice.
- .github/actions/setup-semantica: reusable composite action other repos
can call to install + verify semantica in one step
- install-matrix.yml: verifies the published package installs and imports
cleanly across Ubuntu/macOS/Windows x Python 3.9-3.12, weekly and on
release; backs a new README badge
- scorecard.yml: OpenSSF Scorecard analysis, weekly and on push to main,
backing a new README badge
- release.yml: twine check gate before publish, catching a broken PyPI
long-description render before it ships
- CITATION.cff: enables GitHub's native "Cite this repository" button
- examples/ci/: copy-paste GitHub Actions, GitLab CI, and CircleCI
templates for projects adopting semantica
- GROWTH.md: tracked checklist of distribution channels, what's done vs
outstanding, with guardrails against inflating metrics artificially
Fixes folded in along the way:
- Re-pinned softprops/action-gh-release to the immutable v3.0.3 tag
instead of the floating v3, after verify-action-pins.sh caught the
mutable tag had drifted to a newer commit
- setup-semantica now passes extras/version through env vars instead of
interpolating ${{ inputs.* }} directly into the bash script, closing
a script-injection vector for callers deriving these from event data
- install-matrix now triggers on the Release workflow's completion
(workflow_run) instead of release: published, since the GitHub release
is created before the PyPI upload runs and the old trigger could race
the publish
- The workflow_run path derives the expected version from the triggering
tag and passes it into setup-semantica's version input, so pip
installs and verifies the exact release instead of whatever's latest
on PyPI at the time
- setup-semantica's pip caching is now opt-in (default disabled), since
actions/setup-python errors out with cache: 'pip' enabled when the
caller repo has no requirements.txt/pyproject.toml to key on
- examples/ci/github-actions.yml pins actions/checkout and
actions/setup-python to verified commit SHAs instead of mutable tags
- examples/ci templates guard the requirements.txt install step with
-f requirements.txt and call out pyproject.toml/Poetry/Pipenv as
alternatives, since not every project has a requirements.txt
60 lines
2.0 KiB
YAML
60 lines
2.0 KiB
YAML
name: Install Matrix
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
schedule:
|
|
- cron: '0 6 * * 1' # weekly, catches upstream dependency breakage between releases
|
|
workflow_run:
|
|
# The Release workflow publishes the GitHub release *before* it uploads to
|
|
# PyPI (see release.yml), so triggering on `release: published` would race
|
|
# the PyPI upload and could pass by silently installing the prior version.
|
|
# workflow_run fires only after the whole Release workflow - including the
|
|
# PyPI publish step - has finished.
|
|
workflows: ['Release']
|
|
types: [completed]
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
verify-install:
|
|
if: github.event_name != 'workflow_run' || github.event.workflow_run.conclusion == 'success'
|
|
name: pip install semantica (${{ matrix.os }}, py${{ matrix.python-version }})
|
|
runs-on: ${{ matrix.os }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
os: [ubuntu-latest, macos-latest, windows-latest]
|
|
python-version: ['3.9', '3.10', '3.11', '3.12']
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
|
|
|
- name: Pin expected version for release-triggered runs
|
|
id: expected-version
|
|
if: github.event_name == 'workflow_run'
|
|
shell: bash
|
|
env:
|
|
EXPECTED_TAG: ${{ github.event.workflow_run.head_branch }}
|
|
run: |
|
|
expected="${EXPECTED_TAG#v}"
|
|
if [ -z "$expected" ]; then
|
|
echo "::error::Could not determine a release tag from the triggering workflow run (head_branch was empty)."
|
|
exit 1
|
|
fi
|
|
echo "constraint===$expected" >> "$GITHUB_OUTPUT"
|
|
|
|
- id: setup-semantica
|
|
uses: ./.github/actions/setup-semantica
|
|
with:
|
|
python-version: ${{ matrix.python-version }}
|
|
cache: 'pip'
|
|
version: ${{ steps.expected-version.outputs.constraint }}
|
|
|
|
- name: Smoke test import
|
|
shell: bash
|
|
run: |
|
|
python -c "
|
|
import semantica
|
|
print('semantica', semantica.__version__, 'installed and importable')
|
|
"
|