Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
114 changes: 109 additions & 5 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,30 @@
version: 2

# Grouping note
# ─────────────
# Every ecosystem below groups its minor+patch updates into ONE pull request.
# Before this, each bump arrived as its own PR: the 2026-09 batch produced six
# open PRs (#49 memmap2, #51 tokenizers, #52 mimalloc, #53 windows, #64
# System.Text.Json, #69 log) plus three more against /Deploy. They then sat
# long enough to fall 61 commits behind main, and each carried its own stale
# Cargo.lock. Replaying those lockfiles individually would have reverted the
# quinn-proto 0.11.17 fix for alert #28 that landed on main in the meantime.
#
# One grouped PR per ecosystem resolves a single lockfile against current main
# and is gated once. Major bumps stay ungrouped so they keep an individual,
# reviewable PR -- those are the ones that break APIs.

updates:
# Rust dependencies (pcai_core workspace)
# ── Rust: pcai_core workspace ────────────────────────────────
- package-ecosystem: "cargo"
directory: "/Native/pcai_core"
schedule:
interval: "weekly"
day: "tuesday"
open-pull-requests-limit: 5
groups:
cargo-pcai-core:
update-types: ["minor", "patch"]
labels:
- "dependencies"
- "rust"
Expand All @@ -15,13 +33,35 @@ updates:
commit-message:
prefix: "chore(deps):"

# Rust dependencies (FunctionGemma workspace)
# ── Rust: FunctionGemma workspace ────────────────────────────
# NOTE: no CI job builds this workspace. rust-guidelines.yml has it
# commented out ("FunctionGemma workspaces require CUDA bindgen"), so
# nothing here is gated. Bumps must be verified locally in a VS
# developer environment before merging.
- package-ecosystem: "cargo"
directory: "/Deploy"
schedule:
interval: "weekly"
day: "tuesday"
open-pull-requests-limit: 3
groups:
cargo-deploy:
update-types: ["minor", "patch"]
ignore:
# The candle stack is pinned to 0.9.2 to match the vendored CUDA
# kernels under Deploy/vendor/ (candle-kernels-0.9.2,
# candle-flash-attn-0.9.2), which the workspace [patch] table points
# at. Dependabot raised candle-transformers 0.9.2 -> 0.11.0 (#66) on
# its own, which would have left rust-functiongemma-core depending on
# candle-core 0.9.2 and candle-transformers 0.11.0 at the same time --
# two semver-incompatible copies of Tensor in one crate, a guaranteed
# compile error. Moving candle requires re-vendoring the kernels too,
# so it is a deliberate coordinated change, not a dependabot bump.
- dependency-name: "candle-core"
- dependency-name: "candle-nn"
- dependency-name: "candle-transformers"
- dependency-name: "candle-flash-attn"
- dependency-name: "candle-kernels"
labels:
- "dependencies"
- "rust"
Expand All @@ -30,13 +70,38 @@ updates:
commit-message:
prefix: "chore(deps):"

# .NET dependencies (PcaiNative)
# ── .NET ─────────────────────────────────────────────────────
# PcaiServiceHost and both test projects were previously absent from this
# file, so nothing ever raised a PR for them. PcaiServiceHost had drifted
# to System.Text.Json 10.0.7 while PcaiNative (which IS covered) sat at
# 10.0.9 -- two versions of one package in a single solution, invisible
# because only half the projects were watched.
- package-ecosystem: "nuget"
directory: "/Native/PcaiNative"
schedule:
interval: "weekly"
day: "tuesday"
open-pull-requests-limit: 3
groups:
nuget-pcainative:
update-types: ["minor", "patch"]
labels:
- "dependencies"
- "dotnet"
reviewers:
- "David-Martel"
commit-message:
prefix: "chore(deps):"

- package-ecosystem: "nuget"
directory: "/Native/PcaiServiceHost"
Comment thread
David-Martel marked this conversation as resolved.
schedule:
interval: "weekly"
day: "tuesday"
open-pull-requests-limit: 3
groups:
nuget-servicehost:
update-types: ["minor", "patch"]
labels:
- "dependencies"
- "dotnet"
Expand All @@ -45,13 +110,49 @@ updates:
commit-message:
prefix: "chore(deps):"

# .NET dependencies (PcaiChatTui)
- package-ecosystem: "nuget"
directory: "/Native/PcaiChatTui"
schedule:
interval: "weekly"
day: "tuesday"
open-pull-requests-limit: 2
groups:
nuget-chattui:
update-types: ["minor", "patch"]
labels:
- "dependencies"
- "dotnet"
reviewers:
- "David-Martel"
commit-message:
prefix: "chore(deps):"

- package-ecosystem: "nuget"
directory: "/Native/PcaiNative.Tests"
schedule:
interval: "weekly"
day: "tuesday"
open-pull-requests-limit: 2
groups:
nuget-pcainative-tests:
update-types: ["minor", "patch"]
labels:
- "dependencies"
- "dotnet"
reviewers:
- "David-Martel"
commit-message:
prefix: "chore(deps):"

- package-ecosystem: "nuget"
directory: "/Native/PcaiChatTui.Tests"
schedule:
interval: "weekly"
day: "tuesday"
open-pull-requests-limit: 2
groups:
nuget-chattui-tests:
update-types: ["minor", "patch"]
labels:
- "dependencies"
- "dotnet"
Expand All @@ -60,13 +161,16 @@ updates:
commit-message:
prefix: "chore(deps):"

# GitHub Actions versions
# ── GitHub Actions ───────────────────────────────────────────
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "tuesday"
open-pull-requests-limit: 5
groups:
github-actions:
update-types: ["minor", "patch"]
labels:
- "dependencies"
- "ci"
Expand Down
64 changes: 60 additions & 4 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: CI

on:
pull_request:
branches: [main, develop]
branches: [main]
push:
branches: [develop]
branches: [main]

concurrency:
group: ci-${{ github.ref }}
Expand Down Expand Up @@ -352,6 +352,60 @@ jobs:
}
}

# ──────────────────────────────────────────────────────────────
# .NET
# ──────────────────────────────────────────────────────────────
# No job built any .NET project before this one. dependabot watches all five
# csproj files (.github/dependabot.yml), so a bump to PcaiServiceHost or to
# either test project could satisfy every gate while leaving that project
# unable to restore or compile -- nothing compiled it. The only .NET build
# that ever ran was in portable-ci.yml, which built PcaiNative alone, on
# Linux, and turned failures into warnings.
dotnet-build:
name: .NET Build
runs-on: windows-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
# Both SDKs: four projects target net8.0, but PcaiChatTui.Tests targets
# net10.0 -- a test project on a newer TFM than the code it exercises.
# That builds locally where the 10.x SDK is installed and would fail on a
# runner given only 8.0.x, which is part of why this gap went unnoticed.
# Installing both makes the gate work today; aligning the TFMs is a
# separate decision.
- uses: actions/setup-dotnet@v4
with:
dotnet-version: |
8.0.x
10.0.x
- name: Build every .NET project
shell: pwsh
run: |
$projects = @(Get-ChildItem -Path Native -Recurse -Filter *.csproj |
Where-Object { $_.FullName -notmatch '[\\/](bin|obj)[\\/]' })
# Positive control: a discovery glob that silently matches nothing is
# not a gate. Fail loudly if the project set shrinks unexpectedly.
if ($projects.Count -lt 5) {
throw "Expected at least 5 .csproj files under Native/, found $($projects.Count)"
}
Write-Host "Building $($projects.Count) projects" -ForegroundColor Cyan
foreach ($p in $projects) {
Write-Host "== $($p.Name)" -ForegroundColor Cyan
dotnet build $p.FullName -c Release --nologo -v minimal
if ($LASTEXITCODE -ne 0) { throw "dotnet build failed: $($p.Name)" }
}
- name: Run .NET test projects
shell: pwsh
run: |
$tests = @(Get-ChildItem -Path Native -Recurse -Filter *.Tests.csproj |
Where-Object { $_.FullName -notmatch '[\\/](bin|obj)[\\/]' })
if ($tests.Count -lt 1) { throw "Expected at least 1 .NET test project, found 0" }
foreach ($t in $tests) {
Write-Host "== $($t.Name)" -ForegroundColor Cyan
dotnet test $t.FullName -c Release --nologo -v minimal
if ($LASTEXITCODE -ne 0) { throw "dotnet test failed: $($t.Name)" }
}

# ──────────────────────────────────────────────────────────────
# Gate (required status check for branch protection)
# ──────────────────────────────────────────────────────────────
Expand All @@ -370,6 +424,7 @@ jobs:
- powershell-test
- build-llamacpp
- integration-tests
- dotnet-build
steps:
- name: Evaluate Results
shell: pwsh
Expand All @@ -382,7 +437,8 @@ jobs:
'${{ needs.rust-test.result }}',
'${{ needs.powershell-test.result }}',
'${{ needs.build-llamacpp.result }}',
'${{ needs.integration-tests.result }}'
'${{ needs.integration-tests.result }}',
'${{ needs.dotnet-build.result }}'
)
# 'success' only. No job here carries an `if:`, so the only way a
# gated job skips is an upstream `needs` failing -- and that upstream
Expand All @@ -394,4 +450,4 @@ jobs:
Write-Host "Non-success results: $($failed -join ', ')" -ForegroundColor Red
exit 1
}
Write-Host "CI Gate PASSED - all 8 checks succeeded" -ForegroundColor Green
Write-Host "CI Gate PASSED - all 9 checks succeeded" -ForegroundColor Green
4 changes: 2 additions & 2 deletions .github/workflows/nvidia-validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ name: NVIDIA Stack Validation
# on every PR.
on:
pull_request:
branches: [main, develop]
branches: [main]
paths:
- 'Modules/PC-AI.Gpu/**'
- 'Config/nvidia-software-registry.json'
Expand All @@ -14,7 +14,7 @@ on:
- 'Tools/Sync-NvidiaDriverVersion.ps1'
- 'Tools/Initialize-CudaEnvironment.ps1'
push:
branches: [develop]
branches: [main]
paths:
- 'Modules/PC-AI.Gpu/**'
- 'Config/nvidia-software-registry.json'
Expand Down
Loading
Loading