Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 0 additions & 20 deletions .github/CI_README.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,26 +50,6 @@ reusable actions, and supporting docs.

- `semantic-pull-requests.yaml`
Pull request title validation.

- `request-nvskills-ci.yml`
Dispatches the internal NVSkills validation workflow when a maintainer or
admin comments `/nvskills-ci` on a pull request with changes under `skills/`.
It also handles the trusted signature push from the NVSkills signing bot.

- `require-nvskills-ci.yml`
Merge-blocking PR check for `skills/` changes. It passes immediately when a
PR does not touch `skills/`. When `skills/` files changed, it requires the PR
head commit to be the trusted NVSkills signature commit from
`NVSKILLS_SIGNATURE_PUSH_ACTOR` (default `svc-nvskills-signing`) with commit
title prefix `NVSKILLS_SIGNATURE_COMMIT_TITLE` (default
`Attach NVSkills validation signatures`). If new `skills/` content is pushed
after signing, a maintainer or admin must rerun `/nvskills-ci`. Repository
admins must make `Require NVSkills CI for skill changes / require-nvskills-ci`
a required check in branch protection or rulesets for this workflow to block
merges. Internal pipeline/log lookup is documented in the NVIDIA onboarding
doc section:
<https://nvidia.atlassian.net/wiki/spaces/GAIT/pages/3483240468/Github+First+-+Outbound+Repos+Onboarding+doc+-+NVCARPS#Review-Internal-Pipeline-Logs>.

- `dco-war.yaml`
Merge queue compatibility shim for the DCO check. Normal DCO validation comes
from the installed DCO app.
Expand Down
51 changes: 0 additions & 51 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2028,56 +2028,6 @@ jobs:
command: |
opa test services/core/auth/src/nmp/core/auth/app/policies services/core/auth/src/nmp/core/auth/app/policy_tests services/core/auth/src/nmp/core/auth/assets/static-authz.yaml -v

require-nvskills:
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Require trusted NVSkills signature for skills changes
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
SIGNATURE_ACTOR: ${{ vars.NVSKILLS_SIGNATURE_PUSH_ACTOR || 'svc-nvskills-signing' }}
SIGNATURE_TITLE: ${{ vars.NVSKILLS_SIGNATURE_COMMIT_TITLE || 'Attach NVSkills validation signatures' }}
ONBOARDING_DOC: https://nvidia.atlassian.net/wiki/spaces/GAIT/pages/3483240468/Github+First+-+Outbound+Repos+Onboarding+doc+-+NVCARPS#Review-Internal-Pipeline-Logs
with:
script: |
const pr = context.payload.pull_request;
const owner = context.repo.owner;
const repo = context.repo.repo;

const files = await github.paginate(github.rest.pulls.listFiles, {
owner,
repo,
pull_number: pr.number,
per_page: 100,
});

const touchedSkills = files.some((file) => file.filename.startsWith('skills/'));
if (!touchedSkills) {
core.info('No files under skills/ changed.');
return;
}

const commit = await github.rest.repos.getCommit({
owner,
repo,
ref: pr.head.sha,
});

const actor = commit.data.author?.login || '';
const title = commit.data.commit.message.split('\n')[0];

const okActor = actor === process.env.SIGNATURE_ACTOR;
const okTitle = title.startsWith(process.env.SIGNATURE_TITLE);

if (!okActor || !okTitle) {
core.setFailed(
'Files under skills/ changed in this PR, but HEAD is not the trusted NVSkills signature commit. ' +
'Ask a maintainer/admin to comment /nvskills-ci. If new skills/ content was pushed after signing, rerun /nvskills-ci. ' +
`Expected HEAD GitHub author "${process.env.SIGNATURE_ACTOR}" and commit title prefix "${process.env.SIGNATURE_TITLE}". ` +
`See ${process.env.ONBOARDING_DOC}.`
);
}

# Required-check pin: branch protection should require this final aggregate.
# Skipped jobs count as pass so conditional jobs can remain optional.
ci-status:
Expand All @@ -2101,7 +2051,6 @@ jobs:
- evaluator-sdk-closure-smoke
# Enable if you want this required
# - python-integration-test
- require-nvskills
- wheel-build
- wheel-test
- python-e2e-test
Expand Down
26 changes: 0 additions & 26 deletions .github/workflows/request-nvskills-ci.yml

This file was deleted.

Loading