From d021f0a05b22f9436ac1865bade2f66123c8aa78 Mon Sep 17 00:00:00 2001 From: erivan Date: Mon, 21 Sep 2026 18:00:55 +0200 Subject: [PATCH] secure CI for fork and trusted pull requests --- .github/workflows/run_tests.yml | 45 ++++++++++++++++++++++++++------- 1 file changed, 36 insertions(+), 9 deletions(-) diff --git a/.github/workflows/run_tests.yml b/.github/workflows/run_tests.yml index 607281c..108c447 100644 --- a/.github/workflows/run_tests.yml +++ b/.github/workflows/run_tests.yml @@ -1,28 +1,55 @@ name: Unit Tests for CAIS Core Functions +permissions: + contents: read + on: push: branches: [main] - pull_request_target: + pull_request: types: [opened, ready_for_review, reopened, synchronize] repository_dispatch: types: [create-pull-request] workflow_dispatch: jobs: - test: - name: pytest + fork-tests: + name: pytest without external API access + if: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.repo.fork }} runs-on: ubuntu-latest - environment: - name: ${{ github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.fork && 'causal-agent' || '' }} - deployment: false strategy: matrix: python-version: ["3.10"] steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v4 + + - name: Set up Python ${{ matrix.python-version }} + uses: actions/setup-python@v5 with: - ref: ${{ github.event.pull_request.head.sha }} # checks out the fork's code + python-version: ${{ matrix.python-version }} + + - name: Install dependencies + run: | + python -m pip install --upgrade pip + pip install coverage pytest + pip install -r requirements.txt + + - name: Test with pytest + run: coverage run -m pytest -v -s + + - name: Generate Coverage Report + run: coverage report -m + + trusted-tests: + name: pytest with external API access + if: ${{ github.event_name != 'pull_request' || !github.event.pull_request.head.repo.fork }} + runs-on: ubuntu-latest + environment: causal-agent + strategy: + matrix: + python-version: ["3.10"] + steps: + - uses: actions/checkout@v4 - name: Set up Python ${{ matrix.python-version }} uses: actions/setup-python@v5 @@ -41,4 +68,4 @@ jobs: OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }} - name: Generate Coverage Report - run: coverage report -m \ No newline at end of file + run: coverage report -m