diff --git a/.dockerignore b/.dockerignore index ababbcda82..6d9a841184 100644 --- a/.dockerignore +++ b/.dockerignore @@ -86,9 +86,8 @@ apps/ # Test suite — not shipped in production images tests/ -# Documentation site (Docusaurus) and supplementary docs +# Documentation site (Docusaurus) website/ -docs/ # Keep the source artwork needed by web's icon-generation prebuild. assets/ diff --git a/.github/workflows/osv-scanner.yml b/.github/workflows/osv-scanner.yml index 671eecb947..2e61fcc92c 100644 --- a/.github/workflows/osv-scanner.yml +++ b/.github/workflows/osv-scanner.yml @@ -58,6 +58,11 @@ jobs: emit-status: name: Emit review status runs-on: ubuntu-latest + # Downloads one small SARIF artifact and runs two inline python snippets — + # minutes of work. Bound it so a wedged artifact download can't hold a + # runner for GitHub's 6-hour default (the only unbounded job left in + # .github/workflows; every other workflow already sets timeout-minutes). + timeout-minutes: 10 needs: scan if: always() outputs: diff --git a/.github/workflows/tests-os.yml b/.github/workflows/tests-os.yml index 0198b8c31c..8b9dd102a3 100644 --- a/.github/workflows/tests-os.yml +++ b/.github/workflows/tests-os.yml @@ -32,7 +32,7 @@ on: desktop_updater: description: >- Run the Windows desktop-update hand-off integration tests - (tests/test_desktop_update_windows_*.py). These spawn the real + (tests/scripts/desktop_update/test_desktop_update_windows_*.py). These spawn the real scripts/desktop-update/windows.ps1 and poll its loopback server, so they carry process-timing noise a shared runner amplifies; the caller gates them on the classifier's desktop_updater lane so a PR @@ -126,7 +126,7 @@ jobs: # an unbound-variable error, hence the ``${arr[@]+...}`` idiom.) EXTRA_ARGS=() if [ "${{ inputs.desktop_updater }}" != "true" ]; then - echo "desktop_updater lane off: skipping tests/test_desktop_update_windows_*.py" + echo "desktop_updater lane off: skipping tests/scripts/desktop_update/test_desktop_update_windows_*.py" EXTRA_ARGS+=(--ignore-glob='*test_desktop_update_windows_*.py') fi diff --git a/.gitignore b/.gitignore index 9c9e2c4d52..ab3936a137 100644 --- a/.gitignore +++ b/.gitignore @@ -325,6 +325,7 @@ install-stamp.json # regenerated by scripts/tool_search_livetest.py. Never an artifact of the repo. scripts/out/ +evals/tool_search/out*/ # Per-release changelog drafts. These exist only transiently during a release # cut (passed to `gh release create --notes-file`); the GitHub Release itself diff --git a/AGENTS.md b/AGENTS.md index 1f1ae045f2..16849686c5 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -257,7 +257,7 @@ families: `hermes_state.py` (21), `gateway/run.py` (15), `tools/mcp_tool.py` (15 (`_SLASH_DISPATCH` in `cli.py`, `_command_handler_table` in the gateway are the shape). - **No re-export shims for internal moves** ("keep the old name importable"). Internal paths are not API; external compat is handled ONCE by the compat layer, not per PR. -- **Moving a symbol means fixing its docs in the same PR:** grep `website/docs`, `docs/`, +- **Moving a symbol means fixing its docs in the same PR:** grep `website/docs`, `skills/`, and every `AGENTS.md` for the old `path.py` + symbol (23 doc files went stale after the refactor). `evals/codebase_navigability/static_metrics.py