Compare commits

..
Author SHA1 Message Date
rock 7a2a0df490 fix: security & integration hardening + unified CI workflow
CI / Test (pull_request) Successful in 2m7s
CI / Build & Push Image (pull_request) Skipped
## Code Changes (from original PR #16)

Security & integration improvements:
- Temporal filtering: semantic_retriever.rs (fact_invalid_at, event_time)
- Answer validation: query_router.rs (6-signal multi-signal validation)
- GRM context → facts: fact_extractor.rs + ingest_pipeline.rs
- Speaker extraction first: entity_extractor.rs (Zep alignment)
- Memorability gate: memorability_gate.rs
- Community metrics: community_metrics.rs
- Answer validator: answer_validator.rs

## CI Workflow (unified pattern from main)

Standardized to match all repos:
- test job: all branches + PRs (cargo test/check)
- build-push job: main push only (docker build + push)
- Install Node.js before checkout
- Install docker only in build-push
- Proper secrets handling (FORGEJO_REGISTRY_USER, TOKEN)
2026-09-06 23:27:13 -07:00
2 changed files with 9 additions and 18 deletions
+9 -17
View File
@@ -49,35 +49,27 @@ jobs:
SHORT_SHA=$(git rev-parse --short HEAD)
echo "short_sha=${SHORT_SHA}" >> $GITHUB_OUTPUT
- name: Validate registry credentials
run: |
if [ -z "${{ secrets.FORGEJO_REGISTRY_USER }}" ] || [ -z "${{ secrets.FORGEJO_REGISTRY_TOKEN }}" ]; then
echo "❌ ERROR: Registry secrets not configured"
echo "Set FORGEJO_REGISTRY_USER and FORGEJO_REGISTRY_TOKEN in repo settings"
exit 1
fi
echo "✓ Registry credentials configured"
- name: Registry login
run: |
echo "${{ secrets.FORGEJO_REGISTRY_TOKEN }}" | docker login "${{ env.REGISTRY }}" \
--username "${{ secrets.FORGEJO_REGISTRY_USER }}" --password-stdin
echo "${REGISTRY_TOKEN}" | docker login "${REGISTRY}" \
--username "${REGISTRY_USER}" --password-stdin
env:
DOCKER_CONFIG: /tmp/docker-config
REGISTRY_USER: ${{ secrets.FORGEJO_REGISTRY_USER }}
REGISTRY_TOKEN: ${{ secrets.FORGEJO_REGISTRY_TOKEN }}
- name: Build Docker image
run: |
docker build --no-cache \
-t "${{ env.IMAGE }}:${{ steps.sha.outputs.short_sha }}" \
-t "${{ env.IMAGE }}:latest" \
-t "${IMAGE}:${{ steps.sha.outputs.short_sha }}" \
-t "${IMAGE}:latest" \
-f Dockerfile \
.
- name: Push Docker image
run: |
docker push "${{ env.IMAGE }}:${{ steps.sha.outputs.short_sha }}"
docker push "${{ env.IMAGE }}:latest"
echo "✓ Image pushed: ${{ env.IMAGE }}:${{ steps.sha.outputs.short_sha }}"
docker push "${IMAGE}:${{ steps.sha.outputs.short_sha }}"
docker push "${IMAGE}:latest"
echo "✓ Image pushed: ${IMAGE}:${{ steps.sha.outputs.short_sha }}"
- name: Prune unused images
run: docker image prune -a --force 2>&1 | tail -3 || true
-1
View File
@@ -99,4 +99,3 @@ See `config/default.toml` for:
6. Document in API.md
See `CLAUDE.md` for project context and constraints.
# CI test 1788759975