| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
docs: add citation section and fix stale org references Add a Cite Us section to the README with BibTeX citation info, and align it with docs/citation.md (author/organization: Semantica, 2026). Update LICENSE and docs/project-license.md copyright holder to Semantica, and replace the stale Hawksight-AI GitHub org slug with semantica-agi across READMEs, plugin manifests, cookbook notebooks, and GitHub templates. | 1 个月前 | |
fix: require Python >=3.10 and commit uv.lock for reproducible dev (#1506) (#1702) * fix: require Python >=3.10 and commit uv.lock for reproducible dev (#1506) `uv sync` failed from a clean checkout because requires-python allowed 3.9 while several dependencies (pyarrow>=24, open-ontologies-lite, ...) need 3.10+, so uv's universal resolution had no solution. Per maintainer decision on #1506, drop Python 3.8/3.9 and align every place that declares or tests a Python range: - pyproject.toml: requires-python >=3.10; classifiers 3.10-3.13; remove the now-dead `python_version < '3.10'` dependency branches. - explorer: replace datetime.UTC (3.11+) with timezone.utc so the package actually imports on the declared 3.10 floor. - Commit uv.lock (generated with the CI-pinned uv 0.12.1) and add a `uv lock --check` step to CI; document `uv sync --extra dev`. - Install Matrix: 3.10-3.13 (adds 3.13, which the Docker image uses). - Docs/README/badges/plugin READMEs: Python 3.10+. - osv-scanner.toml: ignore advisories that reach uv.lock only through the opt-in crewai extra (chromadb, json-repair); the extra stays out of `all` and requirements-ci.txt. requirements-ci.txt is unchanged (re-resolved for 3.11/linux: identical). Closes #1506 * fix: address #1702 review - cap Python <3.14, dev dependency group, doctor/docs - pyproject.toml: requires-python is now ">=3.10,<3.14" so the declared range matches what the Install Matrix and Docker image actually cover. - Docker: pin the runtime image back to python:3.13-slim (digest-pinned). Dependabot had bumped it to 3.14 (#1547) while the comment still said 3.13; the comment now states the current reasons, and dependabot.yml ignores python minor/major bumps for the image. - Move contributor tooling from the `dev` extra to a PEP 735 `[dependency-groups] dev` group and drop `dev` from the `all` extra, so `pip install semantica[all]` no longer ships pytest/jupyter/etc. `uv sync` installs the group by default and it is locked in uv.lock; pip users run `pip install -e . --group dev` (pip 25.1+). - requirements-ci.txt: same 410 pins and hashes; only the compile command (now `--group dev`) and the `via` annotations for dev packages change. CI's staleness check and CONTRIBUTING use the same command. - doctor: validate against MIN_PYTHON/MAX_PYTHON_EXCLUSIVE (3.10..3.13) instead of 3.8; warn on newer interpreters. - Docs: explorer/README.md and integrations/openclaw still said 3.8+; replace the removed `.[dev]` extra in README/docs. - Add tests/test_python_support_policy.py, which fails when requires-python, classifiers, the Install Matrix, the Dockerfile, doctor's constants or the dev-group layout disagree. Refs #1506 | 13 天前 | |
ci: reusable install action, install-matrix, and release hardening (#1266) Distribution and trust-signal infrastructure to make pip install semantica frictionless in downstream CI, and to bring the release pipeline in line with mature OSS practice. - .github/actions/setup-semantica: reusable composite action other repos can call to install + verify semantica in one step - install-matrix.yml: verifies the published package installs and imports cleanly across Ubuntu/macOS/Windows x Python 3.9-3.12, weekly and on release; backs a new README badge - scorecard.yml: OpenSSF Scorecard analysis, weekly and on push to main, backing a new README badge - release.yml: twine check gate before publish, catching a broken PyPI long-description render before it ships - CITATION.cff: enables GitHub's native "Cite this repository" button - examples/ci/: copy-paste GitHub Actions, GitLab CI, and CircleCI templates for projects adopting semantica - GROWTH.md: tracked checklist of distribution channels, what's done vs outstanding, with guardrails against inflating metrics artificially Fixes folded in along the way: - Re-pinned softprops/action-gh-release to the immutable v3.0.3 tag instead of the floating v3, after verify-action-pins.sh caught the mutable tag had drifted to a newer commit - setup-semantica now passes extras/version through env vars instead of interpolating ${{ inputs.* }} directly into the bash script, closing a script-injection vector for callers deriving these from event data - install-matrix now triggers on the Release workflow's completion (workflow_run) instead of release: published, since the GitHub release is created before the PyPI upload runs and the old trigger could race the publish - The workflow_run path derives the expected version from the triggering tag and passes it into setup-semantica's version input, so pip installs and verifies the exact release instead of whatever's latest on PyPI at the time - setup-semantica's pip caching is now opt-in (default disabled), since actions/setup-python errors out with cache: 'pip' enabled when the caller repo has no requirements.txt/pyproject.toml to key on - examples/ci/github-actions.yml pins actions/checkout and actions/setup-python to verified commit SHAs instead of mutable tags - examples/ci templates guard the requirements.txt install step with -f requirements.txt and call out pyproject.toml/Poetry/Pipenv as alternatives, since not every project has a requirements.txt | 1 个月前 | |
security: fix 12 vulnerabilities across CRITICAL→LOW severity Closes CodeQL alerts #12, #13, #14, #15, #16, #17, #18 CRITICAL - fix(media_parser): replace eval() with fractions.Fraction for fps parsing (CWE-95) - fix(agent_memory): replace pickle serialization with JSON to prevent RCE (CWE-502) HIGH - fix(snowflake_ingestor): parameterize LIMIT/OFFSET, validate ORDER BY with regex, reject semicolons in WHERE to prevent SQL injection (CWE-89) - fix(rdf_parser): add defusedxml XXE protection for RDF/XML format parsing (CWE-611) - fix(server): add CORSMiddleware, security response headers middleware (X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, HSTS), and global error handler (CWE-346, CWE-200) - fix(explorer/app): narrow CORS to specific methods/headers, redact exception messages in HTTP error handlers, enforce 64 KB WebSocket message size cap (CWE-346) MEDIUM - fix(graph): replace free-text algorithm param with _PathAlgorithm enum (CWE-20) - fix(vocabulary): validate uploaded file extensions against allowlist (CWE-434) - fix(llm_extraction): json.dumps() all user content in LLM prompts to block prompt-injection attacks (CWE-1336) - fix(pipeline_validator): replace __import__("collections") with proper import (CWE-95) LOW - fix(sparql): cap results at 5 000 rows and enforce 30-second query timeout (CWE-400) - fix(export_import): validate file extension + enforce 50 MB upload limit (CWE-434) CodeQL / scanning - feat(codeql): add .github/codeql/codeql-config.yml to exclude generated cookbook HTML bundles (Plotly + MapLibre) from JS scanning - feat(codeql): extend dismiss-fixed-alerts job with all new rule IDs (py/path-injection, py/polynomial-redos, js/incomplete-url-substring-sanitization, js/insecure-randomness, js/prototype-pollution-utility) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> | 5 个月前 | |
fix(deps): override semgrep's pyjwt pin and databricks' oauthlib cap (#1859) Clears the remaining Dependabot alerts, which were blocked by upstream pins with no patched parent release available. - pyjwt 2.13.0 -> 2.15.1 in security-scan-tools.txt: semgrep (latest 1.178.0) pins pyjwt~=2.13.0. Compile with a new security-scan-tools-overrides.txt (pyjwt[crypto]>=2.15.1) and install with --no-deps in security-scan.yml, since pip's resolver rejects the out-of-range version. Every transitive dep is already hash-pinned. - oauthlib 3.3.1 -> 4.0.0 in uv.lock: databricks-sql-connector (latest 4.6.0) caps oauthlib<4.0.0. Add [tool.uv] override-dependencies. The connector only uses WebApplicationClient methods, verified unchanged on 4.0.0. | 3 天前 | |
fix(ci): stop checkov's suppressed checks from reopening as new alerts (#1346) * fix(ci): drop unpinnable benchmarks/requirements.txt install Scorecard flagged this pip install as unpinned-by-hash (#6082). Can't hash-pin it - benchmarks/requirements.txt doesn't exist in this repo, so there's nothing to compile a lockfile from. Dropping it instead of leaving it unpinned: the job already fails on the next real step (benchmarks/benchmarks_runner.py, also missing), so this line wasn't doing anything useful to begin with. * fix(ci): hash-pin the spacy model download in benchmark.yml Qodo review on this PR: dropping the benchmarks/requirements.txt install (the previous failure point) let the job actually reach `python -m spacy download en_core_web_sm`, which fetches an unpinned, unhashed wheel from spacy-models' GitHub releases - undoing the point of this PR by exposing a real unpinned-install path instead of a dead one. Replaced with a hash-pinned direct-URL entry in benchmark-extra.in/.txt for en_core_web_sm-3.8.0 (matches the spacy==3.8.15 already pinned in base-deps.txt). uv independently computed the same sha256 I got via a manual curl+sha256 of the release asset, and a --require-hashes dry-run install verifies clean. * fix(ci): stop checkov's suppressed checks from reopening as new alerts Root cause found, not just worked around: checkov's SARIF exporter includes every evaluated check as an ordinary result, including ones it internally marked SKIPPED via the inline # checkov:skip= comments and checkov.io/skipN annotations already on the Helm chart. It never uses SARIF's own `suppressions` field and never drops them - so the exact same already-suppressed finding reopens as a brand-new code scanning alert number on every single run, forever (#6035/#6036, #6112-6115, #6128-6131 are all the same 4 findings, manually dismissed 3 times now). checkov's JSON output *does* correctly record which checks were skipped. Added .github/scripts/filter_checkov_skipped.py, which cross-references the JSON's skipped_checks against the SARIF's results (matched by check ID + the last two path segments, since the two outputs use different path roots) and drops anything checkov itself already decided to suppress, before upload. Verified locally against a real checkov+helm run: removed exactly the 4 known-suppressed helm chart results, left the 2 genuinely real findings (deploy/gcp/cloudrun-service.yaml, deploy/kubernetes/ deployment.yaml) untouched. | 1 个月前 | |
ci: run the full test suite (#1858) * ci: run the full test suite The job gated one slice of tests/: the reasoning suite, google_adk and open_ontologies. Everything else under tests/ had no CI coverage, so a regression there was only found by hand. This adds a step that runs the whole suite against the pinned tree. Tests that already fail on an unmodified checkout are deselected. .github/full-suite-known-failures.txt records them by group with the reason for each. Baseline, measured on 4f4a0031 with requirements-ci.txt installed: 49 failed, 8950 passed, 239 skipped. The list is an upper bound: it was captured on Windows and the Windows-only entries are expected to pass on Linux, so they should be deleted once a CI run confirms it. No defect behind the list is fixed here. * ci: gate the integration tests outside the dedicated dirs, deselect Windows-only entries on Windows only Two fixes to the full-suite step after review. `-m "not integration"` left the integration tests outside tests/integrations/google_adk/ and tests/integrations/open_ontologies/ with no gate at all: 186 tests across 21 files. They need neither a service nor the network, so they belong in this step and the marker is dropped. The seven that fail on a clean checkout join the deselect list; the two dedicated directories stay ignored because their own steps install their own extras. The five Windows-only entries were deselected unconditionally, but CI runs on ubuntu-latest, so that turned off the symlink-rejection check in tests/semantic_extract/test_cache_backends.py on the one platform where it passes. Those entries now carry a `# windows-only` marker, and the step skips a marked line only when RUNNER_OS is Windows. On Linux the step deselects 51 entries rather than 56. * ci: deselect the suite failures the Linux runner hits too The baseline file above was measured on Windows with a two-invocation run, so it never saw the 34 ids the single-process run this step uses surfaces on ubuntu-latest. Add them under a dated banner with a comment per group, and reclassify the network-pin group: those four fail on Linux as well (the connection times out instead of being refused), so they are no longer windows-only. * ci: note the deselection set is a union, and why each network stub misses --------- Co-authored-by: Kaif <98801504+KaifAhmad1@users.noreply.github.com> | 1 天前 | |
docs: add citation section and fix stale org references Add a Cite Us section to the README with BibTeX citation info, and align it with docs/citation.md (author/organization: Semantica, 2026). Update LICENSE and docs/project-license.md copyright holder to Semantica, and replace the stale Hawksight-AI GitHub org slug with semantica-agi across READMEs, plugin manifests, cookbook notebooks, and GitHub templates. | 1 个月前 | |
docs: add citation section and fix stale org references Add a Cite Us section to the README with BibTeX citation info, and align it with docs/citation.md (author/organization: Semantica, 2026). Update LICENSE and docs/project-license.md copyright holder to Semantica, and replace the stale Hawksight-AI GitHub org slug with semantica-agi across READMEs, plugin manifests, cookbook notebooks, and GitHub templates. | 1 个月前 | |
fix: require Python >=3.10 and commit uv.lock for reproducible dev (#1506) (#1702) * fix: require Python >=3.10 and commit uv.lock for reproducible dev (#1506) `uv sync` failed from a clean checkout because requires-python allowed 3.9 while several dependencies (pyarrow>=24, open-ontologies-lite, ...) need 3.10+, so uv's universal resolution had no solution. Per maintainer decision on #1506, drop Python 3.8/3.9 and align every place that declares or tests a Python range: - pyproject.toml: requires-python >=3.10; classifiers 3.10-3.13; remove the now-dead `python_version < '3.10'` dependency branches. - explorer: replace datetime.UTC (3.11+) with timezone.utc so the package actually imports on the declared 3.10 floor. - Commit uv.lock (generated with the CI-pinned uv 0.12.1) and add a `uv lock --check` step to CI; document `uv sync --extra dev`. - Install Matrix: 3.10-3.13 (adds 3.13, which the Docker image uses). - Docs/README/badges/plugin READMEs: Python 3.10+. - osv-scanner.toml: ignore advisories that reach uv.lock only through the opt-in crewai extra (chromadb, json-repair); the extra stays out of `all` and requirements-ci.txt. requirements-ci.txt is unchanged (re-resolved for 3.11/linux: identical). Closes #1506 * fix: address #1702 review - cap Python <3.14, dev dependency group, doctor/docs - pyproject.toml: requires-python is now ">=3.10,<3.14" so the declared range matches what the Install Matrix and Docker image actually cover. - Docker: pin the runtime image back to python:3.13-slim (digest-pinned). Dependabot had bumped it to 3.14 (#1547) while the comment still said 3.13; the comment now states the current reasons, and dependabot.yml ignores python minor/major bumps for the image. - Move contributor tooling from the `dev` extra to a PEP 735 `[dependency-groups] dev` group and drop `dev` from the `all` extra, so `pip install semantica[all]` no longer ships pytest/jupyter/etc. `uv sync` installs the group by default and it is locked in uv.lock; pip users run `pip install -e . --group dev` (pip 25.1+). - requirements-ci.txt: same 410 pins and hashes; only the compile command (now `--group dev`) and the `via` annotations for dev packages change. CI's staleness check and CONTRIBUTING use the same command. - doctor: validate against MIN_PYTHON/MAX_PYTHON_EXCLUSIVE (3.10..3.13) instead of 3.8; warn on newer interpreters. - Docs: explorer/README.md and integrations/openclaw still said 3.8+; replace the removed `.[dev]` extra in README/docs. - Add tests/test_python_support_policy.py, which fails when requires-python, classifiers, the Install Matrix, the Dockerfile, doctor's constants or the dev-group layout disagree. Refs #1506 | 13 天前 | |
ci: run the full test suite (#1858) * ci: run the full test suite The job gated one slice of tests/: the reasoning suite, google_adk and open_ontologies. Everything else under tests/ had no CI coverage, so a regression there was only found by hand. This adds a step that runs the whole suite against the pinned tree. Tests that already fail on an unmodified checkout are deselected. .github/full-suite-known-failures.txt records them by group with the reason for each. Baseline, measured on 4f4a0031 with requirements-ci.txt installed: 49 failed, 8950 passed, 239 skipped. The list is an upper bound: it was captured on Windows and the Windows-only entries are expected to pass on Linux, so they should be deleted once a CI run confirms it. No defect behind the list is fixed here. * ci: gate the integration tests outside the dedicated dirs, deselect Windows-only entries on Windows only Two fixes to the full-suite step after review. `-m "not integration"` left the integration tests outside tests/integrations/google_adk/ and tests/integrations/open_ontologies/ with no gate at all: 186 tests across 21 files. They need neither a service nor the network, so they belong in this step and the marker is dropped. The seven that fail on a clean checkout join the deselect list; the two dedicated directories stay ignored because their own steps install their own extras. The five Windows-only entries were deselected unconditionally, but CI runs on ubuntu-latest, so that turned off the symlink-rejection check in tests/semantic_extract/test_cache_backends.py on the one platform where it passes. Those entries now carry a `# windows-only` marker, and the step skips a marked line only when RUNNER_OS is Windows. On Linux the step deselects 51 entries rather than 56. * ci: deselect the suite failures the Linux runner hits too The baseline file above was measured on Windows with a two-invocation run, so it never saw the 34 ids the single-process run this step uses surfaces on ubuntu-latest. Add them under a dated banner with a comment per group, and reclassify the network-pin group: those four fail on Linux as well (the connection times out instead of being refused), so they are no longer windows-only. * ci: note the deselection set is a union, and why each network stub misses --------- Co-authored-by: Kaif <98801504+KaifAhmad1@users.noreply.github.com> | 1 天前 | |
docs: formalize issue assignment and duplicate-PR triage workflow (#1030) * docs(contributing): formalize issue assignment and duplicate-PR triage workflow Comments are no longer required before an issue can be assigned - maintainers may assign directly based on recent activity. Also documents the duplicate-PR priority order for triage (contributor PR, claimed issue, activity tiebreak, late duplicates, overlapping scope). * docs(contributing): clarify assignment precedence and define activity tiebreak Addresses Qodo review feedback on PR #1030: the duplicate-PR priority list now states these rules apply on top of the assignment workflow (opening a PR pre-assignment doesn't grant priority), and the "most active" tiebreak now specifies a concrete 60-day window and signals instead of being subjective. | 1 个月前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 1 个月前 | ||
| 13 天前 | ||
| 1 个月前 | ||
| 5 个月前 | ||
| 3 天前 | ||
| 1 个月前 | ||
| 1 天前 | ||
| 1 个月前 | ||
| 1 个月前 | ||
| 13 天前 | ||
| 1 天前 | ||
| 1 个月前 |