Skip to content

ga evidence

ga evidence #70

Workflow file for this run

name: ga evidence
# Producer for the WAVE GA readiness gate — VER-001 and SUPPLY-001 — computed against what the
# PUBLIC PyPI registry and GitHub actually serve, never the checkout under test. See
# scripts/ga/ga_evidence.py for what each criterion verifies and what it leaves `unknown`.
#
# wave-av/sdks is the only other repo in the WAVE org that ships a GA-evidence producer today
# (its `registry clean-room acceptance` workflow). This mirrors that repo's fail-loud posture:
# every trigger reports its true state, no `|| true`, no continue-on-error, and the final
# Enforce step turns a non-zero producer exit into a red job.
#
# `pull_request` legitimately sees VER-001 as `unknown` on a release PR whose tag/version is
# ahead of what PyPI has published — the producer reports that as `unknown`, not `fail`; see the
# HEAD-ahead-of-published branch in scripts/ga/check_ver_001.py.
#
# PR CONTRACT: on `pull_request`, exit 1 (a live criterion failed) is a `::warning`, not a job
# failure — that is a property of the live registry, not of the PR's diff. Exit 2 (the producer
# could not run) always fails the job, and on schedule/workflow_dispatch/push exit 1 fails it too.
on:
pull_request:
workflow_dispatch:
inputs:
expect_version:
description: 'Assert PyPI now serves exactly this version (e.g. a release job verifying its own publish)'
type: string
required: false
schedule:
# 09:43 UTC — offset from a round hour so a registry rate-limit window shared across the org's
# scheduled jobs does not land on this one every day.
- cron: "43 9 * * *"
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
ga-evidence:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
persist-credentials: false
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: "3.12"
- name: Run GA evidence producer against the public registries
id: evidence
env:
GA_EXPECT_VERSION: ${{ inputs.expect_version }}
# Read-only, job-scoped default token — raises the GitHub REST API's
# unauthenticated 60/hour-per-IP cap (shared across CI runners' NAT'd
# pools, and easy to exhaust) to 1000/hour. No new secret: this is
# `github.token`, already governed by the `permissions:` block above
# (contents: read), expires with the job, and is never logged.
# scripts/ga/ga_common.py attaches it ONLY to api.github.com requests.
GITHUB_TOKEN: ${{ github.token }}
run: |
set -uo pipefail
args=(--out-dir "$GITHUB_WORKSPACE/ga-out")
[ -n "${GA_EXPECT_VERSION:-}" ] && args+=(--expect-version "$GA_EXPECT_VERSION")
set +e
python3 scripts/ga/ga_evidence.py "${args[@]}" 2>&1 | tee "$RUNNER_TEMP/ga-evidence.log"
code=${PIPESTATUS[0]}
set -e
echo "exit_code=$code" >> "$GITHUB_OUTPUT"
{
echo "## GA evidence — VER-001 / SUPPLY-001"
echo
echo "Exit code \`$code\` (0 = pass/unknown, 1 = a criterion failed, 2 = the producer could not run)."
echo
echo '```'
cat "$RUNNER_TEMP/ga-evidence.log"
echo '```'
} >> "$GITHUB_STEP_SUMMARY"
exit 0
- name: Upload GA evidence
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: ga-evidence-sdk-python
path: ga-out/
if-no-files-found: warn
retention-days: 90
- name: Enforce
# A gate that cannot fail is not a gate (wave-av/sdks#79 is the org's own cautionary
# tale — see registry-cleanroom.yml). This step fails loud on every trigger except one:
# see the PR CONTRACT note in the header — a live-criterion failure (exit 1) on
# `pull_request` logs a `::warning` and exits 0 instead of failing the job, because that
# failure is a property of the live registry, not of this PR's diff. Whether the job is a
# *required* branch-protection check is a separate branch-ruleset decision.
env:
CODE: ${{ steps.evidence.outputs.exit_code }}
EVENT: ${{ github.event_name }}
run: |
if [ "$CODE" = "0" ]; then
echo "ga-evidence: no criterion failed (pass or unknown only) — see the job summary for detail"
exit 0
fi
if [ "$CODE" = "1" ] && [ "$EVENT" = "pull_request" ]; then
echo "::warning title=ga-evidence::sdk-python GA evidence producer reports a failing live criterion (exit 1); evidence is in the job summary and artifact; this does not fail the PR because the criterion is a property of the live surface, not of this change"
exit 0
fi
if [ "$CODE" = "1" ]; then
echo "::error title=ga-evidence::a GA criterion failed verification (exit 1) — see the job summary"
exit 1
fi
echo "::error title=ga-evidence::the producer could not run (exit $CODE) — never read as a pass"
exit 1