mirror of
https://github.com/semantica-agi/semantica.git
synced 2026-09-09 04:00:52 +00:00
Distribution and trust-signal infrastructure to make pip install semantica
frictionless in downstream CI, and to bring the release pipeline in line
with mature OSS practice.
- .github/actions/setup-semantica: reusable composite action other repos
can call to install + verify semantica in one step
- install-matrix.yml: verifies the published package installs and imports
cleanly across Ubuntu/macOS/Windows x Python 3.9-3.12, weekly and on
release; backs a new README badge
- scorecard.yml: OpenSSF Scorecard analysis, weekly and on push to main,
backing a new README badge
- release.yml: twine check gate before publish, catching a broken PyPI
long-description render before it ships
- CITATION.cff: enables GitHub's native "Cite this repository" button
- examples/ci/: copy-paste GitHub Actions, GitLab CI, and CircleCI
templates for projects adopting semantica
- GROWTH.md: tracked checklist of distribution channels, what's done vs
outstanding, with guardrails against inflating metrics artificially
Fixes folded in along the way:
- Re-pinned softprops/action-gh-release to the immutable v3.0.3 tag
instead of the floating v3, after verify-action-pins.sh caught the
mutable tag had drifted to a newer commit
- setup-semantica now passes extras/version through env vars instead of
interpolating ${{ inputs.* }} directly into the bash script, closing
a script-injection vector for callers deriving these from event data
- install-matrix now triggers on the Release workflow's completion
(workflow_run) instead of release: published, since the GitHub release
is created before the PyPI upload runs and the old trigger could race
the publish
- The workflow_run path derives the expected version from the triggering
tag and passes it into setup-semantica's version input, so pip
installs and verifies the exact release instead of whatever's latest
on PyPI at the time
- setup-semantica's pip caching is now opt-in (default disabled), since
actions/setup-python errors out with cache: 'pip' enabled when the
caller repo has no requirements.txt/pyproject.toml to key on
- examples/ci/github-actions.yml pins actions/checkout and
actions/setup-python to verified commit SHAs instead of mutable tags
- examples/ci templates guard the requirements.txt install step with
-f requirements.txt and call out pyproject.toml/Poetry/Pipenv as
alternatives, since not every project has a requirements.txt
41 lines
1.3 KiB
YAML
41 lines
1.3 KiB
YAML
# Drop this in as .circleci/config.yml in your own project.
|
|
version: 2.1
|
|
|
|
jobs:
|
|
test:
|
|
docker:
|
|
- image: cimg/python:3.11
|
|
steps:
|
|
- checkout
|
|
# A content-hashed cache key (e.g. `{{ checksum "requirements.txt" }}`)
|
|
# is more precise but breaks if that exact file doesn't exist in your
|
|
# project - swap in one matched to however you declare dependencies
|
|
# once you've adjusted the install step below.
|
|
- restore_cache:
|
|
keys:
|
|
- pip-cache-v1
|
|
- run:
|
|
name: Install dependencies
|
|
command: |
|
|
pip install --upgrade pip
|
|
pip install semantica
|
|
# Install your own project's dependencies however your project
|
|
# declares them - adjust this to match, e.g. `pip install -e .`
|
|
# for pyproject.toml / setup.cfg, or `poetry install`.
|
|
if [ -f requirements.txt ]; then pip install -r requirements.txt; fi
|
|
- save_cache:
|
|
key: pip-cache-v1
|
|
paths:
|
|
- ~/.cache/pip
|
|
- run:
|
|
name: Smoke test
|
|
command: python -c "import semantica; print('semantica', semantica.__version__)"
|
|
- run:
|
|
name: Run tests
|
|
command: pytest
|
|
|
|
workflows:
|
|
test:
|
|
jobs:
|
|
- test
|