Skip to content

docs: add public repository confidentiality rules for agents #6091

docs: add public repository confidentiality rules for agents

docs: add public repository confidentiality rules for agents #6091

Workflow file for this run

name: "Build and Test"
on:
push:
branches:
- main
pull_request:
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
pull-requests: read
checks: write
id-token: write
jobs:
# Code quality checks
trunk-check:
name: Trunk code check
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Trunk Check
uses: trunk-io/trunk-action@e1234e67a86010d61ddac8d8ebf4b783e2ffd2fa # v2.0.0
with:
check-mode: pull_request
instrumented-core:
uses: ./.github/workflows/instrumented-tests.yml
with:
display_name: Core
gradle_command: ":android-core:cAT -Pandroid.testInstrumentationRunnerArguments.androidx.benchmark.enabledRules=none --info --stacktrace"
artifact_name: instrumented-core-results
artifact_path: android-core/build/reports/androidTests/connected/**
instrumented-kit-base:
uses: ./.github/workflows/instrumented-tests.yml
strategy:
fail-fast: false
matrix:
shard: [0, 1, 2, 3]
with:
display_name: "Kit Base Shard ${{ matrix.shard }}/4"
gradle_command: ":android-kit-base:cAT -Pandroid.testInstrumentationRunnerArguments.androidx.benchmark.enabledRules=none -Pandroid.testInstrumentationRunnerArguments.numShards=4 -Pandroid.testInstrumentationRunnerArguments.shardIndex=${{ matrix.shard }}"
artifact_name: "instrumented-kit-base-results-shard-${{ matrix.shard }}"
artifact_path: android-kit-base/build/reports/androidTests/connected/**
instrumented-testutils:
uses: ./.github/workflows/instrumented-tests.yml
with:
display_name: Testutils
gradle_command: ":testutils:cAT -Pandroid.testInstrumentationRunnerArguments.androidx.benchmark.enabledRules=none --info --stacktrace"
artifact_name: instrumented-testutils-results
artifact_path: testutils/build/reports/androidTests/connected/**
instrumented-orchestrator:
uses: ./.github/workflows/instrumented-tests.yml
with:
display_name: Orchestrator
gradle_command: "-Porchestrator=true :android-core:cAT -Pandroid.testInstrumentationRunnerArguments.androidx.benchmark.enabledRules=none --stacktrace"
artifact_name: instrumented-orchestrator-results
artifact_path: android-core/build/orchestrator/**
# End-to-end payload baselines against a local WireMock; see integration-tests/README.md.
instrumented-integration:
uses: ./.github/workflows/instrumented-tests.yml
with:
display_name: Integration
gradle_command: "-Pintegration.tests=true :integration-tests:testDebugUnitTest :integration-tests:connectedDebugAndroidTest --stacktrace"
artifact_name: instrumented-integration-results
artifact_path: |
integration-tests/build/reports/androidTests/connected/**
integration-tests/build/wiremock/wiremock.log
timeout_minutes: 30
unit-tests:
name: "Unit Tests"
timeout-minutes: 15
runs-on: ubuntu-latest
steps:
- name: "Checkout Branch"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: "Install JDK 17"
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6
with:
distribution: "zulu"
java-version: "17"
- name: "Setup Gradle"
uses: gradle/actions/setup-gradle@3f5f9adaf7d9fecd50b5935e54106014257a94e6 # v6.4.0
- name: "Run Unit Tests"
run: ./gradlew test
- name: "Check the public API dumps"
run: ./gradlew apiCheck
- name: "Fetch the base branch"
if: github.event_name == 'pull_request'
env:
BASE_REF: ${{ github.base_ref }}
run: git fetch --no-tags --depth=1 origin "$BASE_REF"
- name: "Classify public API changes"
if: >
github.event_name == 'pull_request' &&
!contains(github.event.pull_request.labels.*.name, 'api-change-approved')
env:
BASE_REF: ${{ github.base_ref }}
run: python3 scripts/check_api_dump.py --base "origin/$BASE_REF"
- name: "Print Android Unit Tests Report"
uses: asadmansr/android-test-report-action@384cd31388782f4106dc4a1b37eea2ff02e0aad7 #v1.2.0
if: always()
- name: "Archive Unit Test Results"
uses: actions/upload-artifact@v7
if: always()
with:
name: "unit-tests-results"
path: ./**/build/reports/**
lint-checks:
name: "Lint Checks"
timeout-minutes: 20
runs-on: ubuntu-latest
steps:
- name: "Checkout Branch"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- run: echo "ORG_GRADLE_PROJECT_VERSION=$(head -n 1 VERSION)" >> $GITHUB_ENV
- run: echo "ORG_GRADLE_PROJECT_version=$(head -n 1 VERSION)" >> $GITHUB_ENV
- name: "Install JDK 17"
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6
with:
distribution: "zulu"
java-version: "17"
- name: "Setup Gradle"
uses: gradle/actions/setup-gradle@3f5f9adaf7d9fecd50b5935e54106014257a94e6 # v6.4.0
- name: "Run Android Core SDK Lint"
run: ./gradlew lint
- name: "Setup Android Kit Lint"
run: ./gradlew publishMavenPublicationToMavenLocal
- name: "Run Android Kit Lint"
run: ./gradlew -c settings-kits.gradle -Pmparticle.kit.mparticleFromMavenLocalOnly=true lint
- name: "Archive Lint Test Results"
uses: actions/upload-artifact@v7
if: always()
with:
name: "lint-results"
path: ./**/build/reports/**
kotlin-lint-checks:
name: "Kotlin Lint Checks"
timeout-minutes: 15
runs-on: ubuntu-latest
steps:
- name: "Checkout Branch"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- run: echo "ORG_GRADLE_PROJECT_VERSION=$(head -n 1 VERSION)" >> $GITHUB_ENV
- run: echo "ORG_GRADLE_PROJECT_version=$(head -n 1 VERSION)" >> $GITHUB_ENV
- name: "Install JDK 17"
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6
with:
distribution: "zulu"
java-version: "17"
- name: "Setup Gradle"
uses: gradle/actions/setup-gradle@3f5f9adaf7d9fecd50b5935e54106014257a94e6 # v6.4.0
- name: "Run Android Core SDK Kotlin Lint"
run: ./gradlew ktlintCheck
- name: "Setup Android Kit Kotlin Lint"
run: ./gradlew publishMavenPublicationToMavenLocal
- name: "Run Android Kit Kotlin Lint"
run: ./gradlew -c settings-kits.gradle -Pmparticle.kit.mparticleFromMavenLocalOnly=true ktlintCheck
- name: "Archive Kotlin Lint Test Results"
uses: actions/upload-artifact@v7
if: always()
with:
name: "kotlin-lint-results"
path: ./**/build/reports/**
security-checks:
name: "Security Lint Checks"
if: github.event_name == 'pull_request'
uses: mparticle/mparticle-workflows/.github/workflows/security-checks.yml@main
with:
base_branch: main
build-kits:
uses: ./.github/workflows/build-kits.yml
kit-compatibility-test:
name: "Kit Compatibility Test"
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: "Checkout Branch"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- run: echo "ORG_GRADLE_PROJECT_VERSION=$(head -n 1 VERSION)" >> $GITHUB_ENV
- run: echo "ORG_GRADLE_PROJECT_version=$(head -n 1 VERSION)" >> $GITHUB_ENV
- name: "Install JDK 17"
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6
with:
distribution: "zulu"
java-version: "17"
- name: "Setup Gradle"
uses: gradle/actions/setup-gradle@3f5f9adaf7d9fecd50b5935e54106014257a94e6 # v6.4.0
- name: "Generate Core Release Build"
run: ./gradlew publishMavenPublicationToMavenLocal
- name: "Run Kit-Base Release Tests and Build"
run: ./gradlew :android-kit-base:testRelease
- name: "Run Kit Release Tests and Build"
run: ./gradlew -p kits testRelease -c ../settings-kits.gradle -Pmparticle.kit.mparticleFromMavenLocalOnly=true
- name: "Build consumer compatibility fixtures"
run: ./gradlew -c settings-compat.gradle assembleDebug
- name: "Run Isolated Kit Compatibility Tests (urbanairship)"
run: ./gradlew -Pmparticle.kit.mparticleFromMavenLocalOnly=true -p kits/urbanairship/urbanairship-20 -PisRelease=true testRelease
- name: "Run Isolated Kit Compatibility Tests (braze-43)"
run: ./gradlew -Pmparticle.kit.mparticleFromMavenLocalOnly=true -p kits/braze/braze-43 -PisRelease=true testRelease
- name: "Run Isolated Kit Compatibility Tests (ga)"
run: ./gradlew -Pmparticle.kit.mparticleFromMavenLocalOnly=true -p kits/ga/ga-23 -PisRelease=true testRelease
- name: "Run Isolated Kit Compatibility Tests (ga4)"
run: ./gradlew -Pmparticle.kit.mparticleFromMavenLocalOnly=true -p kits/ga4/ga4-23 -PisRelease=true testRelease
binary-compatibility:
name: "Binary Compatibility"
# Not in the required-check set today; treat a red result as blocking. Posts a sticky PR
# comment with the result, the same pattern the SDK Size Impact job below uses, so an
# incompatibility is visible in the conversation without opening the job log.
timeout-minutes: 30
runs-on: ubuntu-latest
permissions:
contents: read
# Replaces the workflow-level `pull-requests: read` for this job only.
pull-requests: write
env:
COMMENT_IDENTIFIER: "<!-- binary-compatibility-report -->"
steps:
- name: "Checkout Branch"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: "Install JDK 17"
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6
with:
distribution: "zulu"
java-version: "17"
- name: "Setup Gradle"
uses: gradle/actions/setup-gradle@3f5f9adaf7d9fecd50b5935e54106014257a94e6 # v6.4.0
- name: "Test the comparison script"
run: python3 -m unittest scripts/test_api_compat_report.py
- name: "Compare release artifacts with the last published release"
# continue-on-error so the comment below posts even when this finds an incompatible
# change; the explicit failure step at the end of this job still turns it red.
id: compare
continue-on-error: true
run: |
python3 scripts/api_compat_report.py \
--output-dir build/api-compat \
--comment-file "${RUNNER_TEMP}/binary-compat-comment.md"
- name: "Archive compatibility reports"
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: "api-compat-reports"
path: build/api-compat/**
# A pull_request from a fork gets a read-only token regardless of the permissions above,
# so commenting would 403. The job summary and the artifact still carry the result.
- name: "Find existing comment"
id: existing
if: always() && github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository
uses: peter-evans/find-comment@b30e6a3c0ed37e7c023ccd3f1db5c6c0b0c23aad # v4
with:
issue-number: ${{ github.event.pull_request.number }}
comment-author: "github-actions[bot]"
body-includes: ${{ env.COMMENT_IDENTIFIER }}
- name: "Create or update PR comment"
if: always() && github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository
uses: peter-evans/create-or-update-comment@e8674b075228eee787fea43ef493e45ece1004c9 # v5
with:
comment-id: ${{ steps.existing.outputs.comment-id }}
issue-number: ${{ github.event.pull_request.number }}
edit-mode: replace
body-path: ${{ runner.temp }}/binary-compat-comment.md
- name: "Fail the job if the comparison found an incompatible change"
if: steps.compare.outcome == 'failure'
run: exit 1
kotlin-migration-progress:
name: "Kotlin Migration Progress"
# Posts the Java-to-Kotlin conversion numbers on every pull request. The last step fails
# when a pull request adds Java to the published modules without the allow-new-java label.
if: github.event_name == 'pull_request'
timeout-minutes: 10
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
env:
COMMENT_IDENTIFIER: "<!-- kotlin-migration-progress -->"
steps:
# The default pull_request ref is the merge result; see the size-report job below for why
# that is the right side to measure and what happens on a conflicted pull request.
- name: "Checkout PR head"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: "Checkout base branch"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: ${{ github.event.pull_request.base.sha }}
path: base
- name: "Test the progress script"
run: python3 -m unittest scripts/test_kotlin_migration_progress.py
- name: "Measure head and base"
id: measure
run: |
set -euo pipefail
read_metric() { grep "^$2=" "$1" | cut -d= -f2; }
python3 scripts/kotlin_migration_progress.py --format env > "${RUNNER_TEMP}/head.env"
python3 scripts/kotlin_migration_progress.py > "${RUNNER_TEMP}/head.md"
# The base is measured with the head's facade list, so editing the list cannot masquerade as progress.
python3 scripts/kotlin_migration_progress.py --root base --facades scripts/kotlin-migration-facades.txt --format env > "${RUNNER_TEMP}/base.env"
head_left=$(read_metric "${RUNNER_TEMP}/head.env" JAVA_LEFT_LOC)
base_left=$(read_metric "${RUNNER_TEMP}/base.env" JAVA_LEFT_LOC)
head_java=$(read_metric "${RUNNER_TEMP}/head.env" JAVA_LOC)
base_java=$(read_metric "${RUNNER_TEMP}/base.env" JAVA_LOC)
delta_left=$((head_left - base_left))
delta_java=$((head_java - base_java))
headline=$(python3 scripts/kotlin_migration_progress.py --headline "${delta_left}" "${delta_java}")
{
echo "${COMMENT_IDENTIFIER}"
echo "### Kotlin migration progress"
echo
echo "${headline}"
echo
cat "${RUNNER_TEMP}/head.md"
} > "${RUNNER_TEMP}/comment.md"
cat "${RUNNER_TEMP}/comment.md" >> "${GITHUB_STEP_SUMMARY}"
echo "delta_java=${delta_java}" >> "${GITHUB_OUTPUT}"
# A pull_request from a fork gets a read-only token, so commenting would 403.
- name: "Find existing comment"
id: existing
if: github.event.pull_request.head.repo.full_name == github.repository
uses: peter-evans/find-comment@b30e6a3c0ed37e7c023ccd3f1db5c6c0b0c23aad # v4
with:
issue-number: ${{ github.event.pull_request.number }}
comment-author: "github-actions[bot]"
body-includes: ${{ env.COMMENT_IDENTIFIER }}
- name: "Create or update PR comment"
if: github.event.pull_request.head.repo.full_name == github.repository
uses: peter-evans/create-or-update-comment@e8674b075228eee787fea43ef493e45ece1004c9 # v5
with:
comment-id: ${{ steps.existing.outputs.comment-id }}
issue-number: ${{ github.event.pull_request.number }}
edit-mode: replace
body-path: ${{ runner.temp }}/comment.md
- name: "Ratchet: no new Java in the published modules"
if: >
steps.measure.outputs.delta_java > 0 &&
!contains(github.event.pull_request.labels.*.name, 'allow-new-java')
env:
DELTA_JAVA: ${{ steps.measure.outputs.delta_java }}
run: |
echo "This pull request adds ${DELTA_JAVA} lines of Java to android-core or android-kit-base." >&2
echo "New code in these modules is written in Kotlin. If the Java is unavoidable, add the" >&2
echo "allow-new-java label and explain why in the description." >&2
exit 1
automerge-dependabot:
name: "Save PR Number for Dependabot Automerge"
if: github.event_name == 'pull_request'
needs:
[
instrumented-core,
instrumented-kit-base,
instrumented-testutils,
instrumented-orchestrator,
instrumented-integration,
unit-tests,
lint-checks,
kotlin-lint-checks,
kit-compatibility-test,
build-kits,
]
uses: mParticle/mparticle-workflows/.github/workflows/dependabot-save-pr-number.yml@main
pr-notify:
if: >
github.event_name == 'pull_request' &&
github.event.pull_request.draft == false &&
github.actor != 'dependabot[bot]'
needs:
- instrumented-core
- instrumented-kit-base
- instrumented-testutils
- instrumented-orchestrator
- instrumented-integration
- unit-tests
- lint-checks
- kotlin-lint-checks
- security-checks
name: Notify GChat
uses: ROKT/rokt-workflows/.github/workflows/oss_pr_opened_notification.yml@main
secrets:
gchat_webhook: ${{ secrets.GCHAT_PRS_WEBHOOK }}
size-report:
name: "SDK Size Impact"
# Advisory. Measures what the Core SDK, and the Core SDK with the Rokt kit, add to a minified
# release APK and compares the PR against its base. Reports via a sticky PR comment and the
# job summary; deliberately absent from every other job's `needs` so it can never block a
# merge.
if: github.event_name == 'pull_request'
timeout-minutes: 60
runs-on: ubuntu-latest
continue-on-error: true
permissions:
contents: read
# Replaces the workflow-level `pull-requests: read` for this job only.
pull-requests: write
env:
COMMENT_IDENTIFIER: "<!-- sdk-size-report -->"
steps:
- name: "Checkout PR head"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# The merge ref, not head.sha. `base.sha` is the base branch's current tip, so
# measuring a stale head against it attributes everything merged into the base since
# the branch diverged to this pull request -- an unrelated increase on the base branch
# would render as this pull request shrinking the SDK. Measuring the merge result
# against the base compares like with like.
# A pull request with conflicts has no merge ref, so this step fails and the job
# stops here. The job is advisory so nothing is blocked, but note that an existing
# comment is then left untouched rather than rewritten to "not measured" -- the
# footnote naming the measured commit is what marks it stale. A conflicted pull
# request cannot merge anyway, so resolving the conflict is the fix.
ref: refs/pull/${{ github.event.pull_request.number }}/merge
path: head
- name: "Checkout target branch"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: ${{ github.event.pull_request.base.sha }}
path: base
- name: "Pin the head fixtures into the target checkout"
# Both sides must be measured with the same fixtures: the base may predate them entirely,
# and otherwise a change to a fixture would show up as an SDK size change.
run: |
set -euo pipefail
rm -rf base/size-report base/size-report-rokt
cp -R head/size-report base/size-report
cp -R head/size-report-rokt base/size-report-rokt
if ! grep -q 'size\.report' base/settings.gradle; then
printf "\n%s\n%s\n%s\n" \
"if (settings.startParameter.projectProperties['size.report'] == 'true') {" \
" include ':size-report'" \
"}" >> base/settings.gradle
fi
- name: "Install JDK 17"
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6
with:
distribution: "zulu"
java-version: "17"
- name: "Setup Gradle"
uses: gradle/actions/setup-gradle@3f5f9adaf7d9fecd50b5935e54106014257a94e6 # v6.4.0
- name: "Measure target branch: Core SDK"
continue-on-error: true
run: head/scripts/sdk-size-report.sh base > "${RUNNER_TEMP}/core-base.json"
- name: "Measure PR head: Core SDK"
continue-on-error: true
run: head/scripts/sdk-size-report.sh head > "${RUNNER_TEMP}/core-head.json"
# The Core SDK fixture alone understates a core change: R8 strips the core code only the
# Rokt kit calls, so that code's cost shows up only when the kit is linked in.
- name: "Measure target branch: Rokt kit"
continue-on-error: true
run: head/scripts/rokt-size-report.sh base > "${RUNNER_TEMP}/rokt-base.json"
- name: "Measure PR head: Rokt kit"
continue-on-error: true
run: head/scripts/rokt-size-report.sh head > "${RUNNER_TEMP}/rokt-head.json"
- name: "Render report"
env:
# Names what was measured. A comment left behind by a later push then reads as stale
# rather than passing as the current result.
FOOTNOTE: >-
Measured ${{ github.event_name == 'pull_request'
&& format('{0} merged into {1}', github.event.pull_request.head.sha, github.event.pull_request.base.sha)
|| github.sha }}
run: |
set -euo pipefail
cd "${RUNNER_TEMP}"
touch core-base.json core-head.json rokt-base.json rokt-head.json
"${GITHUB_WORKSPACE}/head/.github/scripts/render_size_report.py" \
--marker "${COMMENT_IDENTIFIER}" \
--footnote "${FOOTNOTE}" \
--fixture core core-base.json core-head.json \
--baseline-note "Measured against an empty baseline app. Unlike the Rokt kit, android-core ships no Compose and no resources, so there is nothing here that a host app would already provide." \
--stack 'core:mParticle Core SDK' \
--fixture rokt rokt-base.json rokt-head.json \
--baseline-note "Measured against a Compose + Material3 reference app, so these are the costs on top of an app that already ships Compose. The reference app's dependencies are a documented convention, not a measured average: see \`size-report-rokt/README.md\`." \
--stack 'kit:mParticle Core + Rokt kit' \
--stack 'sdkplus:Rokt SDK+ umbrella (adds the payment extension):kit' \
> size-report.md
cat size-report.md >> "${GITHUB_STEP_SUMMARY}"
- name: "Upload size report"
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: sdk-size-report
path: |
${{ runner.temp }}/size-report.md
${{ runner.temp }}/core-base.json
${{ runner.temp }}/core-head.json
${{ runner.temp }}/rokt-base.json
${{ runner.temp }}/rokt-head.json
retention-days: 14
# A pull_request from a fork gets a read-only token regardless of the permissions above,
# so commenting would 403. The job summary and the artifact still carry the result.
- name: "Find existing comment"
id: existing
if: github.event.pull_request.head.repo.full_name == github.repository
uses: peter-evans/find-comment@b30e6a3c0ed37e7c023ccd3f1db5c6c0b0c23aad # v4
with:
issue-number: ${{ github.event.pull_request.number }}
comment-author: "github-actions[bot]"
body-includes: ${{ env.COMMENT_IDENTIFIER }}
- name: "Create or update PR comment"
if: github.event.pull_request.head.repo.full_name == github.repository
uses: peter-evans/create-or-update-comment@e8674b075228eee787fea43ef493e45ece1004c9 # v5
with:
comment-id: ${{ steps.existing.outputs.comment-id }}
issue-number: ${{ github.event.pull_request.number }}
edit-mode: replace
body-path: ${{ runner.temp }}/size-report.md