refactor(tooling): consolidate build and verification workflows - #1868
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Performance BenchmarksCompared
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1868 +/- ##
=======================================
Coverage 76.53% 76.53%
=======================================
Files 218 218
Lines 119936 119936
Branches 28392 28392
=======================================
+ Hits 91790 91791 +1
Misses 20452 20452
+ Partials 7694 7693 -1 🚀 New features to boost your workflow:
|
|
@codex review |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Broad release, CI, and Docker workflow changes still depend on hosted matrix and full-image validation.
Review effort: Balanced
Findings: None
What changed in this PR
Consolidates duplicated CI, release, Docker, and QA tooling while preserving existing contracts and runtime behavior.
Changes:
- Reuses workflow steps and test accessors through shared helpers and YAML anchors.
- Centralizes Docker Rust installation and QA report generation.
- Simplifies equivalent scripts and configuration.
| File | Description |
|---|---|
tests/test_release_workflow.py |
Uses shared workflow helpers and validates package-specific PyPI settings. |
tests/test_perf_workflow.py |
Uses shared workflow accessors. |
tests/test_docker_workflow.py |
Tests the shared Rust installer contract. |
tests/helpers/workflows.py |
Adds shared workflow test accessors. |
tests/__init__.py |
Enables assertion rewriting for test helpers. |
scripts/large_pickle_corpus_qa.py |
Consolidates QA output generation and removes trivial wrappers. |
scripts/compile_tensorflow_protos.sh |
Combines equivalent protobuf compilation loops. |
scripts/benchmark_report.py |
Inlines percentage formatting. |
pyproject.toml |
Removes an obsolete mypy override. |
Dockerfile.tensorflow |
Uses the shared Rust installer. |
Dockerfile.full |
Uses the shared Rust installer. |
Dockerfile |
Uses the shared Rust installer. |
docker-install-rust.sh |
Provides verified, architecture-aware Rust installation. |
docker-entrypoint.sh |
Simplifies equivalent ModelAudit routing. |
docker-compose.yml |
Shares the model volume configuration. |
.github/workflows/test.yml |
Reuses common CI steps and paths. |
.github/workflows/release-please.yml |
Consolidates release steps, permissions, and PyPI verification. |
.github/workflows/perf.yml |
Shares benchmark trigger paths. |
.github/workflows/nightly.yml |
Reuses common setup steps. |
.github/workflows/docker-publish.yml |
Shares validation outputs, permissions, and checkout configuration. |
.github/workflows/docker-image-test.yml |
Shares Docker setup and tracks the installer. |
.github/workflows/codeql.yml |
Shares main-branch trigger configuration. |
.editorconfig |
Consolidates common file settings. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
ModelAudit repeats build steps, Docker Rust installation, workflow test accessors, and QA report generation. Share those implementations while preserving workflow jobs and permissions, verified Rust downloads, command ordering, report contents, and package boundaries.
This is PR 1 of the six-part simplification series. It changes tooling and its contract tests only; scan runtime behavior is unchanged. Net reduction: 403 maintained physical lines (386 tooling, 17 tests), including the new installer/helper and assertion-rewrite registration. Generated files and dependency versions are unchanged by this PR.
Validation:
tests/scanners/test_weight_distribution_scanner.py; the upstream-required mypy 2.4 environment could not be installed from this devbox's package index. The upstream pin and CI command are preserved.Full Docker image builds and the hosted platform matrix are left to CI; local BuildKit checks do not claim those builds ran. No merge is requested as part of preparing this series.
Review order: 1: tooling → 2: tests → 3: raw evidence → 4: picklescan → 5: scanning/results → 6: acquisition/cache/progress. Each PR targets the previous branch; PR1 targets
main.