Peter Steinberger
60861b3823
ci: use api key auth for Codex CLI backend smoke
2026-04-28 23:24:45 +01:00
Peter Steinberger
cc7a209982
fix: normalize QA model refs for parity gates
2026-04-28 23:01:58 +01:00
Vincent Koc
e7947948b6
test(ci): add plugin prerelease suite to CI ( #73741 )
...
* test(ci): route plugin prerelease coverage to plugin shard
* test(ci): add plugin prerelease suite to CI
* fix(ci): preserve pnpm path in plugin prerelease shard
* fix(ci): avoid inheriting secrets for plugin prerelease suite
2026-04-28 14:52:03 -07:00
Peter Steinberger
69fb7455c6
fix(ci): harden full release validation monitors
2026-04-28 22:36:14 +01:00
Peter Steinberger
d9b46e0551
ci: start repo live release checks earlier
2026-04-28 22:18:41 +01:00
Peter Steinberger
969cb8b4c0
ci: use standard runner for release package preparation
2026-04-28 21:51:30 +01:00
Peter Steinberger
35059d1e3a
ci: use standard runner for cross-os preparation
2026-04-28 21:47:35 +01:00
Peter Steinberger
da1084caf2
ci: start release checks on standard runner
2026-04-28 21:14:37 +01:00
Vincent Koc
87172dc9fe
fix(ci): harden package acceptance refs
2026-04-28 12:53:05 -07:00
Vincent Koc
3ae69498e2
ci: shard channel codeql security
...
Add a narrow channel-runtime CodeQL critical-security shard and document it.
2026-04-28 12:46:44 -07:00
Peter Steinberger
230f8886c6
ci: keep full release validation children pinned
2026-04-28 20:43:39 +01:00
Peter Steinberger
4a24b23e3e
fix(ci): stabilize full release validation
2026-04-28 20:14:14 +01:00
Vincent Koc
bb0461b682
ci: shard channel codeql quality
...
Add a narrow channel-runtime CodeQL critical-quality shard and document it.
2026-04-28 11:52:54 -07:00
Vincent Koc
e476523082
ci: shard gateway codeql quality
...
Add a narrow gateway/runtime CodeQL critical-quality shard and document it.
2026-04-28 11:16:48 -07:00
Vincent Koc
e10f493160
ci: shard config codeql quality
...
Split config quality CodeQL results into a separate category while keeping the default quality bucket narrow.
2026-04-28 04:00:14 -07:00
Peter Steinberger
2a0af6754e
ci: narrow ClawSweeper dispatch cancellation
2026-04-28 11:53:06 +01:00
Peter Steinberger
94fc91e235
ci: harden clawsweeper dispatch workflow
2026-04-28 11:35:40 +01:00
Peter Steinberger
7150acba69
ci: debounce clawsweeper dispatch metadata
2026-04-28 11:31:49 +01:00
Vincent Koc
77192572f6
ci: split macos codeql shard
...
Split the slow macOS CodeQL job into its own weekly/manual workflow and keep the daily CodeQL default on the fast JS/Actions security path.
2026-04-28 03:14:07 -07:00
Vincent Koc
5820a48fca
ci: add plugin boundary codeql quality shard ( #73447 )
2026-04-28 02:30:33 -07:00
Vincent Koc
b6a21cde34
ci: schedule android codeql shard ( #73430 )
2026-04-28 01:54:57 -07:00
Vincent Koc
5ac6d7661c
fix(ci): harden workflow checkouts
2026-04-28 01:37:00 -07:00
Peter Steinberger
8ff0ea50b0
ci: stabilize full release validation
2026-04-28 09:26:50 +01:00
Vincent Koc
dbab162abd
ci: split codeql quality workflow ( #73404 )
2026-04-28 01:04:59 -07:00
Peter Steinberger
a811e164e3
ci: speed up full release validation
2026-04-28 09:02:57 +01:00
Peter Steinberger
c7af9c765c
ci: tolerate missing clawsweeper dispatch access
2026-04-28 09:02:28 +01:00
Peter Steinberger
bcf4628092
ci: use gpt-5.5 for live OpenAI defaults
2026-04-28 08:27:11 +01:00
Peter Steinberger
39cecd6428
ci: avoid unnecessary docker image pulls
2026-04-28 08:24:29 +01:00
Vincent Koc
1278f0bcc0
fix(codeql): tune Android pinning profile
...
Remove noisy missing-certificate-pinning query from the critical Android CodeQL profile; gateway TLS uses custom certificate fingerprint pinning.
2026-04-27 23:04:16 -07:00
Peter Steinberger
ee75a8ec2c
ci: document clawsweeper dispatch trigger
2026-04-28 06:50:33 +01:00
Peter Steinberger
6f3674c8d0
ci: harden ClawSweeper dispatcher credentials
2026-04-28 06:48:38 +01:00
Peter Steinberger
ba17db96a4
ci: skip clawsweeper without app credentials
2026-04-28 06:48:29 +01:00
Peter Steinberger
0fc1cdec45
ci: fix ClawSweeper dispatcher payload
2026-04-28 06:44:26 +01:00
Peter Steinberger
23818600bb
ci: add ClawSweeper event dispatcher
2026-04-28 06:43:38 +01:00
Peter Steinberger
017b8db616
ci: speed up release validation shards
2026-04-28 06:14:23 +01:00
Vincent Koc
2bce63cb65
fix(android): harden canvas webview bridge ( #73240 )
...
* fix(android): harden canvas webview bridge
* fix(android): make canvas content access hardening explicit
* fix(android): keep webview hardening inline for CodeQL
* fix(android): avoid webview getter false positive
2026-04-27 21:41:01 -07:00
Peter Steinberger
000d52be37
ci: pin Google live gateway profile models
2026-04-28 05:19:33 +01:00
Peter Steinberger
d9a6dd0c36
ci: pin OpenAI live gateway profile model
2026-04-28 04:57:48 +01:00
Vincent Koc
42de56cc22
fix(ci): trust live docker harness scripts
2026-04-27 20:52:37 -07:00
Peter Steinberger
0bdc1d0375
ci: hydrate provider env for testbox commands
2026-04-28 04:34:21 +01:00
Peter Steinberger
68561a8c94
ci: use trusted codex live harness
2026-04-28 04:29:35 +01:00
Peter Steinberger
e7495e2d92
ci: pass provider secrets to testbox
2026-04-28 04:24:15 +01:00
Peter Steinberger
4db4d8976d
ci: run release validation with trusted harness
2026-04-28 04:14:09 +01:00
Peter Steinberger
e5452a9c57
ci: speed up release validation
2026-04-28 03:52:05 +01:00
Peter Steinberger
fdd2ff02c6
ci: stabilize release validation lanes
2026-04-28 01:31:00 +01:00
Peter Steinberger
0294aebe6f
feat(providers): add DeepInfra provider plugin ( #73038 )
...
* feat(providers): add DeepInfra provider plugin
* feat(deepinfra): add media provider surfaces
* fix(deepinfra): satisfy provider boundary checks
* docs: add gitcrawl maintainer skill
* test: include deepinfra in live media sweeps
* fix: remove stale tts contract import
2026-04-28 01:12:54 +01:00
Peter Steinberger
47f40788cf
ci: install ffmpeg for live audio media shard
2026-04-28 00:57:43 +01:00
Peter Steinberger
b90f29d313
ci: split native live release shards
2026-04-28 00:49:10 +01:00
Peter Steinberger
f1edd601bc
ci: split release qa parity lanes
2026-04-28 00:05:33 +01:00
Vincent Koc
cc80a40d86
fix(ci): preserve mixed macOS CodeQL SARIF findings
...
Conservatively filter macOS CodeQL SARIF by dropping only findings where every location is SwiftPM build output. Verified with workflow sanity, local jq filtering, PR CI, and a failed-job rerun for an unrelated stalled Vitest shard.
2026-04-27 15:43:53 -07:00