diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d1ded0ff54..3441d7bb6d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -115,6 +115,11 @@ jobs: needs: detect uses: ./.github/workflows/uv-lockfile-check.yml + infographic-check: + name: Check no committed infographics + needs: detect + uses: ./.github/workflows/infographic-check.yml + lockfile-diff: name: package-lock.json diff needs: detect diff --git a/.github/workflows/infographic-check.yml b/.github/workflows/infographic-check.yml new file mode 100644 index 0000000000..288f6f493a --- /dev/null +++ b/.github/workflows/infographic-check.yml @@ -0,0 +1,78 @@ +name: Infographic Check + +# Rejects PRs that commit PR-infographic images into the repo. +# +# PR infographics are rendered to an image-provider URL (fal.media) and +# embedded in the PR *description*. The PR body is the archive; the binary +# never belongs in git history. +# +# This has now leaked twice. PR #48261 removed the first batch, PR #54564 +# removed a second batch and added `infographic/` to `.gitignore` — but +# `.gitignore` only stops *accidental* `git add`. It does nothing against +# `git add -f`, and it does nothing for a path that does not literally match +# the ignore pattern. Nine more PNGs (~14MB) were committed in the four +# weeks AFTER that rule landed, plus PR #70552 caught an `infograficos/` +# spelling that sidestepped the pattern entirely. +# +# A passive ignore rule cannot enforce a policy. This check can. + +on: + workflow_call: + outputs: + review_status: + description: "JSON array of review_status objects for the synthesizer." + value: ${{ jobs.check-no-committed-infographics.outputs.review_status }} + +permissions: + contents: read + +jobs: + check-no-committed-infographics: + runs-on: ubuntu-latest + timeout-minutes: 10 + outputs: + review_status: ${{ steps.infographic-check.outputs.review_status }} + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + + - id: infographic-check + name: Reject committed PR-infographic images + run: | + # Match on the IMAGE, not on a directory name. Keying this to + # `infographic/` is what let `infograficos/` through in #70552 — + # any localized or typo'd directory would sidestep it again. + # Instead: find tracked raster images whose path contains an + # infographic-ish segment, in any spelling, at any depth. + # + # `docs/assets` and `website/` legitimately hold product imagery + # and are excluded; those are referenced from shipped docs pages. + OFFENDERS=$(git ls-files -z \ + | tr '\0' '\n' \ + | grep -iE '(^|/)(infograph|infograf)[^/]*/' \ + | grep -iE '\.(png|jpe?g|webp|gif)$' \ + || true) + + if [ -n "$OFFENDERS" ]; then + COUNT=$(printf '%s\n' "$OFFENDERS" | wc -l | tr -d ' ') + STATUS='[{"source":"committed infographics","results":[{"kind":"action_required","title":"PR infographic committed to the repo","summary":"Infographic images belong in the PR description, never in git.","detail":"","how_to_fix":"Untrack the image and reference the provider URL from the PR body instead:\n```\ngit rm --cached \n```\nThen put it in the PR description:\n```\n## Infographic\n\n![slug](https://)\n```\n"}]}]' + echo "review_status=${STATUS}" >> "$GITHUB_OUTPUT" + echo "" + echo "::error::${COUNT} PR-infographic image(s) are tracked in git." + echo "" + printf '%s\n' "$OFFENDERS" | sed 's/^/ /' + echo "" + echo "PR infographics are rendered to an image-provider URL and" + echo "embedded in the PR DESCRIPTION. The PR body is the archive —" + echo "the binary never enters git history." + echo "" + echo "This rule has been re-established twice already (#48261," + echo "#54564) and leaked both times, because .gitignore cannot stop" + echo "'git add -f' or a differently-spelled directory (#70552)." + echo "" + echo "To fix:" + echo " git rm --cached # keeps your local copy" + echo " # then embed the provider URL in the PR description" + exit 1 + fi + echo "::notice::No committed PR-infographic images." + echo "review_status=[]" >> "$GITHUB_OUTPUT" diff --git a/.gitignore b/.gitignore index 8c0ce9c23d..a72536f007 100644 --- a/.gitignore +++ b/.gitignore @@ -175,5 +175,13 @@ apps/desktop/demo/ # image-provider (fal.media) URL — they are NEVER committed to the repo. The # PR body is the archive. See the hermes-agent-dev skill's # pr-infographic-workflow reference (storage rule + lapse #8 / #COMMIT-1). +# +# Spelling variants are listed because a single `infographic/` pattern was +# sidestepped by an `infograficos/` directory (#70552). .gitignore is only +# the first line of defence and cannot stop `git add -f` at all — the +# infographic-check CI job is what actually enforces this. infographic/ +infographics/ +infograficos/ +infografico/ native/fts5_cjk/*.so diff --git a/infograficos/bedrock_converse_cache_demoniaco_flow.png b/infograficos/bedrock_converse_cache_demoniaco_flow.png deleted file mode 100644 index 37eb271441..0000000000 Binary files a/infograficos/bedrock_converse_cache_demoniaco_flow.png and /dev/null differ diff --git a/infographic/approval-mode-validation/infographic.png b/infographic/approval-mode-validation/infographic.png deleted file mode 100644 index 4091ca78a7..0000000000 Binary files a/infographic/approval-mode-validation/infographic.png and /dev/null differ diff --git a/infographic/checkpoint-prune-startup-safety/infographic.png b/infographic/checkpoint-prune-startup-safety/infographic.png deleted file mode 100644 index 87d1bcc5d5..0000000000 Binary files a/infographic/checkpoint-prune-startup-safety/infographic.png and /dev/null differ diff --git a/infographic/dead-delivery-targets/infographic.png b/infographic/dead-delivery-targets/infographic.png deleted file mode 100644 index 9dbf3431ee..0000000000 Binary files a/infographic/dead-delivery-targets/infographic.png and /dev/null differ diff --git a/infographic/feishu-group-events/infographic.png b/infographic/feishu-group-events/infographic.png deleted file mode 100644 index 4936e34427..0000000000 Binary files a/infographic/feishu-group-events/infographic.png and /dev/null differ diff --git a/infographic/fireworks-provider/infographic.png b/infographic/fireworks-provider/infographic.png deleted file mode 100644 index 23534ceb2e..0000000000 Binary files a/infographic/fireworks-provider/infographic.png and /dev/null differ diff --git a/infographic/friendly-tool-labels/infographic.png b/infographic/friendly-tool-labels/infographic.png deleted file mode 100644 index 843bf4bfe4..0000000000 Binary files a/infographic/friendly-tool-labels/infographic.png and /dev/null differ diff --git a/infographic/gateway-reconnect-contract/infographic.png b/infographic/gateway-reconnect-contract/infographic.png deleted file mode 100644 index 11d36ab235..0000000000 Binary files a/infographic/gateway-reconnect-contract/infographic.png and /dev/null differ diff --git a/infographic/list-profiles-perf-54751/infographic.png b/infographic/list-profiles-perf-54751/infographic.png deleted file mode 100644 index b5ba45fde6..0000000000 Binary files a/infographic/list-profiles-perf-54751/infographic.png and /dev/null differ diff --git a/infographic/reasoning-max-ultra/infographic.png b/infographic/reasoning-max-ultra/infographic.png deleted file mode 100644 index 3856b5f971..0000000000 Binary files a/infographic/reasoning-max-ultra/infographic.png and /dev/null differ diff --git a/infographic/win-clh-lock-traceback/infographic.png b/infographic/win-clh-lock-traceback/infographic.png deleted file mode 100644 index caeb4eaec4..0000000000 Binary files a/infographic/win-clh-lock-traceback/infographic.png and /dev/null differ