ci: backport stable release hardening from develop - #34
Merged
Conversation
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
mainso the next stable cut ships exported*.intoto.jsonlprovenance bundles, better Scorecard visibility, and tighter workflow defaults without another noisydevelopmerge.mainwith a lean multi-arch API image, an opt-in NVIDIA image, and ClusterFuzzLite coverage so stable releases inherit the same container and fuzzing guardrails already proven elsewhere.Verification
uv sync --frozen --all-extrasuv run pytestPYTHONWARNINGS=error uv run pytestuv run pytest --cov=src/newsdom_api --cov-branch --cov-report=term-missing --cov-fail-under=100uv run mkdocs build --strict./.venv/bin/python fuzzers/dom_builder_fuzzer.py --smoke tests/fixtures/mineru_sample.jsonpodman build -t newsdom-api-local-smoke .podman run -d --name newsdom-api-local-smoke -p 18080:8000 newsdom-api-local-smoke+http://127.0.0.1:18080/healthpython3 \"$HOME/.config/opencode/scripts/lint_by_filetype.py\" --jsonSummary by CodeRabbit
새 기능
문서
테스트
기타