Skip to content

chore(deps): Bump langchain-core from 1.6.4 to 1.6.5 #3047

chore(deps): Bump langchain-core from 1.6.4 to 1.6.5

chore(deps): Bump langchain-core from 1.6.4 to 1.6.5 #3047

Workflow file for this run

# CI - Lint, test, and build for all modules
#
# Runs on PRs and pushes to main/release branches.
# Covers the AuthProxy Go module and Python tests.
#
name: CI
on:
pull_request:
branches:
- main
- "release-*"
push:
branches:
- main
permissions:
contents: read
jobs:
pre-commit:
name: Pre-commit Checks
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: core/go.mod
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: '3.12'
- name: Run pre-commit
uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd # v3.0.1
# TODO: Remove continue-on-error after fixing pre-existing style issues repo-wide
continue-on-error: true
env:
SKIP: ai-assisted-by-trailer
go-ci-core:
name: Go CI (core)
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: core
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: core/go.mod
cache-dependency-path: core/go.sum
- name: Lint
run: |
go fmt ./...
go vet ./...
- name: Build
run: go build -v ./...
- name: Test
run: go test -v -race -cover ./...
# The plugin-profile guards live in their own module, so no other job runs
# them. They have to run on every PR: plugins are all opt-in, and a plugin
# missing from every profile produces no build error — it just silently
# disappears from every image. TestEveryPluginIsAccountedFor is the only thing
# between that and a shipped artifact.
go-ci-profile-tags:
name: Go CI (plugin profiles)
runs-on: ubuntu-latest
timeout-minutes: 10
defaults:
run:
working-directory: scripts/profile-tags
env:
GOWORK: "off"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: scripts/profile-tags/go.mod
- name: Lint
run: |
go fmt ./...
go vet ./...
# The guards read sibling trees through relative paths (../../cmd, the repo
# root), so they need the full checkout, not just this module. -count=1 is
# required, not cosmetic: Go's test cache keys on this package's own inputs
# and knows nothing about those sibling files, so a cached PASS can outlive
# the change that should have broken it.
- name: Test
run: go test -count=1 -v -cover ./...
# Every profile must resolve to a non-empty tag list. A profile that
# silently yields nothing would flow into `go build -tags ""`.
- name: Every profile resolves
run: |
for profile in local full lite envoy cpex; do
tags=$(go run . "${profile}")
[ -n "${tags}" ] || { echo "profile ${profile} resolved to no tags"; exit 1; }
echo "${profile}: ${tags}"
done
go-ci-readme-demo:
name: Go CI (README demo)
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: scripts/readme-demo
env:
GOWORK: "off"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: scripts/readme-demo/go.mod
- name: Lint
run: |
go fmt ./...
go vet ./...
# The generator drives the real abctl TUI and compares its output against the
# committed docs/assets/cortex-demo.svg, so it reads sibling trees through
# relative paths and needs the full checkout. -count=1 is required, not
# cosmetic: Go's test cache keys on this package's own inputs and knows
# nothing about abctl's sources or the committed asset, so a cached PASS can
# outlive exactly the UI change this job exists to catch.
- name: Test (includes the asset staleness check)
run: go test -count=1 -v ./...
go-ci-authbridge-cmd:
name: Go CI (authbridge ${{ matrix.binary }})
runs-on: ubuntu-latest
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
binary:
- authbridge-proxy
- authbridge-envoy
# abctl is published by release-binaries.yaml, so it has to build
# under GOWORK=off here too. Omitting it let a missing go.sum entry
# for a core transitive dep reach main: the workspace build used
# everywhere else resolved it, and the per-module release build did
# not — surfacing only when a tag was cut.
- abctl
# authbridge-praxis was in no workflow at all, which is how it ended
# up broken under GOWORK=off by the same missing go.sum entry. Any
# cmd/* module absent from every workflow will drift this way — the
# workspace hides exactly this class of breakage. (authbridge-cpex is
# deliberately not here: it needs CGO and libcpex_ffi.a from a pinned
# release, so build.yaml covers it via its image build instead.)
- authbridge-praxis
defaults:
run:
working-directory: cmd/${{ matrix.binary }}
env:
# Disable go.work so each cmd/* module resolves core via its own
# `replace` directive in go.mod (the workspace would otherwise pull
# all sibling modules in and slow down CI).
GOWORK: "off"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: cmd/${{ matrix.binary }}/go.mod
cache-dependency-path: cmd/${{ matrix.binary }}/go.sum
- name: Lint
run: |
go fmt ./...
go vet ./...
- name: Build
run: go build -v ./...
# Every plugin is opt-in, so the Build and Test steps above exercise a
# binary with NO plugins linked. That is worth compiling on its own — it is
# what a caller who forgets -tags gets — but the shipped artifacts are the
# profiles, so build AND test each one here. build.yaml only exercises them
# on tag/main pushes; this catches a profile-only regression on the PR.
- name: Build + test each shipped profile
if: matrix.binary == 'authbridge-proxy' || matrix.binary == 'authbridge-envoy'
run: |
case "${{ matrix.binary }}" in
authbridge-proxy) profiles="local full lite" ;;
authbridge-envoy) profiles="envoy" ;;
esac
for profile in ${profiles}; do
echo "::group::profile ${profile}"
TAGS=$(go -C ../../scripts/profile-tags run . "${profile}")
go build -v -tags "${TAGS}" ./...
go test -race -cover -tags "${TAGS}" ./...
echo "::endgroup::"
done
# Gives the abctl leg a real systemd --user session for
# cmd_service_systemd_integration_test.go. The runner has no interactive login, so
# nothing has started one yet; enable-linger asks logind to start and keep one
# running. Either way a real problem here is loud, not silent: a hard failure (e.g.
# enable-linger itself failing) fails this step outright under bash -e, so Test
# never runs; a soft one (session unreachable after enable-linger) only warns here,
# and ABCTL_SYSTEMD_TESTS=required (below) is what turns THAT case into a failed
# test instead of a silent skip.
- name: Enable a systemd --user session (abctl leg only)
if: matrix.binary == 'abctl'
run: |
sudo loginctl enable-linger "$(whoami)"
rt="/run/user/$(id -u)"
for i in $(seq 1 30); do
[ -S "${rt}/bus" ] && break
sleep 1
done
echo "XDG_RUNTIME_DIR=${rt}" >> "$GITHUB_ENV"
XDG_RUNTIME_DIR="${rt}" systemctl --user show-environment || \
echo "::warning::systemd --user session not reachable after enable-linger; the real-systemd tests will report why"
- name: Test
env:
ABCTL_SYSTEMD_TESTS: ${{ matrix.binary == 'abctl' && 'required' || '' }}
run: go test -v -race -cover ./...
proxy-init-iptables:
name: proxy-init iptables rules
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# This job runs a repo script as root via `sudo -E` and needs no git
# access afterwards, so don't leave the job token in .git/config.
persist-credentials: false
# The harness builds its rules inside `unshare --net`, so it never touches
# the runner's own networking. It needs root for unshare + iptables, the
# dummy module to generate a routable external packet, and both iptables
# backends so the legacy-detection case is exercised rather than skipped.
- name: Install iptables backends
run: |
sudo apt-get update -qq
sudo apt-get install -y -qq iptables iproute2 kmod
sudo modprobe dummy || echo "dummy module unavailable; capture packet may not be generated"
# Gates the interception rules themselves: chain placement and ordering,
# the DNS carve-out, the non-TCP drop, the fail-closed guards, and — for
# transparent inbound — that the ambient DNAT precedes AB_REDIRECT's
# ztunnel-mark RETURN. That ordering decides whether mesh-delivered traffic
# is validated or waved through, and nothing else in CI covers it.
- name: Test enforce-redirect + transparent inbound rules
run: sudo -E deploy/proxy-init/test-enforce-redirect.sh
python-test:
name: Python Tests
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: '3.12'
- name: Install dependencies
run: |
pip install pytest==8.* python-keycloak==5.3.1 pyjwt==2.10.1 pyyaml==6.*
- name: Run tests
run: pytest tests/ -v -x --ignore=tests/e2e
# install.sh is a curl|sh entry point, so a regression there is a
# stranger's first experience of Cortex. shellcheck in
# security-scans.yaml catches syntax, not behaviour — the tag parser
# returning the OLDEST release shipped past it.
install-script:
name: install.sh tests
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Run install.sh tests
run: sh scripts/install_test.sh
# `go mod tidy -diff` on every module in the repo. GOWORK=off so
# replace directives resolve as they do in build.yaml and
# release-binaries.yaml.
go-tidy-check:
name: Verify module graph is tidy
runs-on: ubuntu-latest
timeout-minutes: 5
env:
GOWORK: "off"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: core/go.mod
- name: Run go mod tidy -diff in every module
run: |
set -euo pipefail
# Percent-encode %, CR, LF for use in workflow commands
# (both metadata and message halves — CR/LF in the message
# would end the command and let the next line be interpreted
# as a new one).
esc() { printf '%s' "$1" | sed -e 's/%/%25/g' -e 's/\r/%0D/g' -e ':a' -e '$!N' -e 's/\n/%0A/g' -e 'ta'; }
fail=0
found=0
while IFS= read -r -d '' go_mod; do
found=$((found + 1))
mod=$(dirname "$go_mod")
mod_esc=$(esc "$mod")
go_mod_esc=$(esc "$go_mod")
echo "::group::${mod_esc}"
if ! (cd "$mod" && go mod tidy -diff); then
echo "::error file=${go_mod_esc}::go mod tidy would change ${go_mod_esc}; run 'go mod tidy' in ${mod_esc} and commit"
fail=1
fi
echo "::endgroup::"
done < <(find . -name go.mod -print0 | sort -z)
if [ "$found" -eq 0 ]; then
echo "::error::no go.mod found in the repository"
exit 1
fi
exit $fail