name: CI on: push: branches: [main] pull_request: branches: [main] concurrency: group: ci-${{ github.ref }} cancel-in-progress: true permissions: contents: read jobs: lite: runs-on: ubuntu-latest env: UV_PYTHON_DOWNLOADS: never steps: - uses: actions/checkout@524e936cd9e579adf00e308bfdf971aebc7de09e with: persist-credentials: false - name: Gitea 合规校验 run: | if git ls-tree -r HEAD | awk '$1==160000' | grep -q .; then echo "HEAD 含 gitlink"; exit 1; fi if git ls-files .DS_Store | grep -q .; then echo "跟踪 .DS_Store"; exit 1; fi if git grep -n -I -E 'sk-[A-Za-z0-9]{20,}|AKIA[0-9A-Z]{16}|ghp_[A-Za-z0-9]{36}|xox[baprs]-[A-Za-z0-9-]{10,}' HEAD | grep -q .; then echo "检出疑似凭证"; exit 1; fi echo "Gitea 合规校验通过" - name: 验证并同步共享运行时 run: | test "$(python3 --version)" = "Python 3.13.15" test "$(uv --version | cut -d' ' -f1-2)" = "uv 0.12.3" uv sync --locked --extra dev uv run --locked --no-sync python -c 'import sys; assert sys.version_info[:2] == (3, 13)' - name: 架构模块契约测试 run: | uv run --locked --no-sync python tests/governance/test_module_spec.py uv run --locked --no-sync python tests/governance/test_ci_contract.py - name: Syntax check run: git ls-files -z '*.py' | xargs -0 uv run --locked --no-sync python -m py_compile