mirror of
https://github.com/alphaXiv/OpenResearch.git
synced 2026-10-02 01:34:34 +08:00
* Sign and notarize the macOS CLI binaries in releases The install.sh archives for macOS shipped unsigned, so device-management policies on work Macs blocked them. A release-signing-gated job now signs and notarizes each darwin archive between dist's local and global builds, rewriting its checksums so the installers and sha256.sum match. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Harden CLI signing from review Keep the called workflow from reporting skipped on dry runs, narrow its token to read, pin the Developer ID requirement the updater checks, keep notarization logs on failure, and correct the allow-dirty docs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2.7 KiB
2.7 KiB
Repository Guide
What this repository is
openresearch-cli is the open-source Rust implementation of the orx command-line tool. It owns the local CLI, dashboard and API, SQLite store, coding-agent integrations, experiment orchestration, and execution backends.
openresearch.sh is the companion service. It owns the website and documentation, accounts and organizations, sandbox provisioning, and managed-compute catalogs. Research projects, experiments, runs, logs, and artifacts remain local to orx.
When changing authentication, organization, sandbox, or managed-compute APIs, inspect the corresponding openresearch.sh implementation and keep both sides compatible. Do not edit the companion repository unless it is explicitly in scope.
Development guidelines
- Rust code lives in
src/; the dashboard lives inui/src/. Keep local-only behavior local and use the production API client only for capabilities owned byopenresearch.sh. - Run local app instances through
scripts/dev-slot.mjsso development data, ports, and processes stay isolated. ui/distis committed and embedded in release builds. After UI changes, runpnpm buildinui/and include the regenerated assets.- Prefer canonical Tailwind utilities (
flex flex-col h-full min-h-0) and project theme aliases (bg-background,text-subtext,border-border). Use arbitrary values only when no project utility exists, and preserve semantic marker classes when selectors or runtime behavior depend on them. - Before shipping, follow the checks in
.github/workflows/ci.yml.
CI and release gates
- GitHub protection for
mainmust require thefmt, clippy, test,version sanity, andlinked issuechecks from GitHub Actions, including for administrators. Do not require a merge queue or require branches to be up to date. These settings are managed in GitHub, not by this file. linked issuefails PRs from forks unless the description links an issue in this repository (e.g.Closes #N). PRs from branches in this repository are exempt, since only people with write access can push them. It runs onpull_request_target, so it must never check out or run PR code.- PR CI must test GitHub's simulated merge (
refs/pull/<number>/merge), whichactions/checkoutselects by default forpull_requestevents, rather than checking out the PR head alone. Each run tests its merge candidate; subsequent changes tomaindo not automatically rerun open PRs. - CI also runs on
main. Releases call the same CI workflow on the commit being packaged; publishing requires that run to succeed. Keep./ciin cargo-dist'sglobal-artifacts-jobswhen regenerating the release workflow;allow-dirtymakesdist generateskip it, so follow the steps inmacos/DISTRIBUTION.md("CLI binaries").