Merge pull request #172 from boshu2/codex/ag-y7w-eval-advisory

fix(ci): install eval advisory dependencies
This commit is contained in:
Bo
2026-04-28 14:03:58 -04:00
committed by GitHub
9 changed files with 45 additions and 9 deletions
+23 -3
View File
@@ -152,6 +152,23 @@ jobs:
go-version: '1.26'
cache-dependency-path: cli/go.sum
- name: Install AgentOps eval dependencies
run: |
sudo apt-get install -y jq ripgrep
sudo npm install -g bats
GOBIN="$HOME/go/bin" go install github.com/fzipp/gocyclo/cmd/gocyclo@latest
echo "$HOME/go/bin" >> "$GITHUB_PATH"
bash scripts/install-bd.sh --version v1.0.3
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
bd_eval_root="$RUNNER_TEMP/agentops-bd"
mkdir -p "$bd_eval_root"
git -C "$bd_eval_root" init --quiet
(
cd "$bd_eval_root"
"$HOME/.local/bin/bd" init --non-interactive --skip-agents --skip-hooks --quiet
)
echo "BEADS_DIR=$bd_eval_root/.beads" >> "$GITHUB_ENV"
- name: Run AgentOps public eval canaries
run: |
chmod +x scripts/eval-agentops.sh
@@ -650,12 +667,15 @@ jobs:
echo "✅ Embedded hooks are in sync"
- name: Enforce Go complexity budget on changed files
env:
EVENT_NAME: ${{ github.event_name }}
BASE_REF_NAME: ${{ github.base_ref }}
run: |
echo "=== Enforcing Go complexity budget ==="
GOBIN=/usr/local/bin go install github.com/fzipp/gocyclo/cmd/gocyclo@latest
if [[ "${{ github.event_name }}" == "pull_request" ]]; then
git fetch --no-tags --depth=1 origin "${{ github.base_ref }}"
BASE_REF="origin/${{ github.base_ref }}"
if [[ "$EVENT_NAME" == "pull_request" ]]; then
git fetch --no-tags --depth=1 origin "$BASE_REF_NAME"
BASE_REF="origin/$BASE_REF_NAME"
else
BASE_REF="HEAD~1"
fi
+4
View File
@@ -11,6 +11,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- **`security` domain in eval-suite manifests** — `$defs/domain` enum in `schemas/eval-suite.v1.schema.json` now accepts `security` alongside the existing eight domains. Paired updates land in `cli/internal/eval/coverage.go` (`DefaultCoverageDomains`) and `cli/cmd/ao/cobra_commands_test.go` (`evalCoverageDomains`) so schema, production default, and test fixture stay in lock-step. `ao eval coverage` will report `security` as a missing required domain until a security-domain manifest is authored.
### Fixed
- **GitHub eval advisory setup** — the `agentops-eval-advisory` job now installs the deterministic canary toolchain (`jq`, `ripgrep`, `bats`, `bd`, and `gocyclo`) and initializes a disposable bd database before running `scripts/eval-agentops.sh --fast`, matching the local environment expected by the public canaries.
## [2.38.0] - 2026-04-22
### Added
+1 -1
View File
@@ -897,7 +897,7 @@ ao eval coverage [suite.json ...] [flags]
```
-h, --help help for coverage
--require-dimension stringArray required score dimension for missing-dimension reporting (default [correctness,process_adherence,artifact_quality,runtime_compatibility,efficiency,safety,learning_closure])
--require-domain stringArray required product domain for missing-domain reporting (default [cli,hook,skill,rpi,runtime,retrieval,scenario,mixed])
--require-domain stringArray required product domain for missing-domain reporting (default [cli,hook,skill,rpi,runtime,retrieval,scenario,mixed,security])
--require-runtime stringArray required deterministic runtime for missing-runtime reporting (default [static,shell,mock])
--root string suite root to scan when no suite paths are provided (default "evals/agentops-core")
```
+2 -1
View File
@@ -243,7 +243,8 @@ func AggregateFindingGeneratorSidecars(cwd, outputDir string) (FindingGeneratorA
}
sort.Slice(entries, func(i, j int) bool { return entries[i].Name() < entries[j].Name() })
selected := map[string]FindingGeneratorCandidate{}
// selected is populated through applyGeneratorSidecarCandidates before use.
selected := map[string]FindingGeneratorCandidate{} // nosemgrep: trailofbits.go.iterate-over-empty-map.iterate-over-empty-map
for _, entry := range entries {
if entry.IsDir() || filepath.Ext(entry.Name()) != ".json" {
continue
+4
View File
@@ -11,6 +11,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- **`security` domain in eval-suite manifests** — `$defs/domain` enum in `schemas/eval-suite.v1.schema.json` now accepts `security` alongside the existing eight domains. Paired updates land in `cli/internal/eval/coverage.go` (`DefaultCoverageDomains`) and `cli/cmd/ao/cobra_commands_test.go` (`evalCoverageDomains`) so schema, production default, and test fixture stay in lock-step. `ao eval coverage` will report `security` as a missing required domain until a security-domain manifest is authored.
### Fixed
- **GitHub eval advisory setup** — the `agentops-eval-advisory` job now installs the deterministic canary toolchain (`jq`, `ripgrep`, `bats`, `bd`, and `gocyclo`) and initializes a disposable bd database before running `scripts/eval-agentops.sh --fast`, matching the local environment expected by the public canaries.
## [2.38.0] - 2026-04-22
### Added
@@ -86,12 +86,12 @@
"id": "bd-runtime-version-health",
"title": "installed bd exposes current JSON health probes",
"kind": "command",
"objective": "Protect the latest-version check path with commands that currently emit JSON, while allowing migration inspect to remain human-readable.",
"objective": "Protect the latest-version and database health paths with commands that emit JSON, while allowing migration inspect and embedded-mode doctor output to remain human-readable.",
"runtime": "shell",
"timeout_seconds": 120,
"inputs": {
"cwd": "../..",
"shell": "bd version && bd upgrade status --json | jq -e '.current_version and (.schema_version == 1)' >/dev/null && bd status --json | jq -e '.schema_version == 1 and (.summary.total_issues >= 0)' >/dev/null && bd doctor --json | jq -e '.overall_ok == true and (.cli_version | length > 0)' >/dev/null && bd migrate --inspect >/tmp/agentops-bd-migrate-inspect.txt && rg -q 'Schema Version:' /tmp/agentops-bd-migrate-inspect.txt"
"shell": "bd version && bd upgrade status --json | jq -e '.current_version and (.schema_version == 1)' >/dev/null && bd status --json | jq -e '.schema_version == 1 and (.summary.total_issues >= 0)' >/dev/null && if bd doctor --json >/tmp/agentops-bd-doctor.json 2>/tmp/agentops-bd-doctor.err && jq -e '.overall_ok == true and (.cli_version | length > 0)' /tmp/agentops-bd-doctor.json >/dev/null; then :; else rg -q 'not yet supported in embedded mode' /tmp/agentops-bd-doctor.err; fi && bd migrate --inspect >/tmp/agentops-bd-migrate-inspect.txt && rg -q 'Schema Version:' /tmp/agentops-bd-migrate-inspect.txt"
},
"expectations": [
{"type": "exit_code", "value": 0},
@@ -105,6 +105,13 @@
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "security-scan"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "security-toolchain-gate"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "agentops-eval-advisory"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "Install AgentOps eval dependencies"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "sudo apt-get install -y jq ripgrep"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "sudo npm install -g bats"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "go install github.com/fzipp/gocyclo/cmd/gocyclo@latest"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "scripts/install-bd.sh --version v1.0.3"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "init --non-interactive --skip-agents --skip-hooks --quiet"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "BEADS_DIR=$bd_eval_root/.beads"},
{"type": "artifact_contains", "target": "../../.github/workflows/validate.yml", "value": "Run release smoke test"},
{"type": "artifact_contains", "target": "../../.github/workflows/release.yml", "value": "Generate SBOM and security report assets"},
{"type": "artifact_contains", "target": "../../.github/workflows/release.yml", "value": "security-gate-summary.json"},
+1 -1
View File
@@ -626,7 +626,7 @@
"name": "compile",
"source_skill": "skills/compile",
"source_hash": "16201db71f7c545f6169815d66606938bd8af90cc7b2d880cd53139e85a57fe5",
"generated_hash": "9318d8da6992b1983a8f61abb4e5755fa89976ef8ddcf95cde0435363c60d9cf"
"generated_hash": "d724ce9260f613e6ddfafd49c8b9b2a86085e203df47be0bf1d9ce3292c14b57"
},
{
"name": "llm-wiki",
@@ -3,5 +3,5 @@
"source_skill": "skills/compile",
"layout": "modular",
"source_hash": "16201db71f7c545f6169815d66606938bd8af90cc7b2d880cd53139e85a57fe5",
"generated_hash": "9318d8da6992b1983a8f61abb4e5755fa89976ef8ddcf95cde0435363c60d9cf"
"generated_hash": "d724ce9260f613e6ddfafd49c8b9b2a86085e203df47be0bf1d9ce3292c14b57"
}