mirror of
https://github.com/langchain-ai/langgraph.git
synced 2026-08-23 08:02:23 +02:00
Every third-party GitHub Action in the workflows is now pinned to a full
commit SHA instead of a floating major tag, closing a supply-chain gap
where a mutable tag like `@v6` could be force-pushed to point at
malicious code. Seven actions were already SHA-pinned; this brings the
remaining first-party `actions/*` and `astral-sh/setup-uv` references in
line.
## Changes
- Pinned all previously tag-referenced actions to their current commit
SHA with the exact release as a trailing comment (the format Dependabot
reads and updates): `actions/checkout` → `v6.0.3`,
`actions/setup-python` → `v6.2.0`, `actions/github-script` → `v9.0.0`,
`actions/upload-artifact` → `v7.0.1`, `actions/download-artifact` →
`v8.0.1`, `actions/cache/{restore,save}` → `v5.0.5`,
`actions/configure-pages` → `v6.0.0`, `actions/deploy-pages` → `v5.0.0`,
`actions/upload-pages-artifact` → `v5.0.0`,
`actions/create-github-app-token` → `v3.2.0`, and `astral-sh/setup-uv` →
`v7.6.0`.
- Applied across all workflow files plus the `uv_setup` composite
action; local same-repo references (`./.github/workflows/_*.yml`,
`./.github/actions/uv_setup`) left as path refs since they resolve from
the same commit.
76 lines
2.3 KiB
YAML
76 lines
2.3 KiB
YAML
name: bench
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- "libs/**"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
benchmark:
|
|
runs-on: ubuntu-latest
|
|
defaults:
|
|
run:
|
|
working-directory: libs/langgraph
|
|
steps:
|
|
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
|
- id: files
|
|
name: Get changed files
|
|
uses: Ana06/get-changed-files@25f79e676e7ea1868813e21465014798211fad8c # v2.3.0
|
|
with:
|
|
format: json
|
|
- name: Set up Python 3.11
|
|
uses: ./.github/actions/uv_setup
|
|
with:
|
|
python-version: "3.11"
|
|
cache-suffix: "bench"
|
|
working-directory: libs/langgraph
|
|
- name: Install dependencies
|
|
run: uv sync --group test
|
|
- name: Download baseline
|
|
uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
|
|
with:
|
|
key: ${{ runner.os }}-benchmark-baseline
|
|
restore-keys: |
|
|
${{ runner.os }}-benchmark-baseline-
|
|
fail-on-cache-miss: true
|
|
path: |
|
|
libs/langgraph/out/benchmark-baseline.json
|
|
- name: Run benchmarks
|
|
id: benchmark
|
|
run: |
|
|
{
|
|
echo 'OUTPUT<<EOF'
|
|
make -s benchmark-fast
|
|
echo EOF
|
|
} >> "$GITHUB_OUTPUT"
|
|
- name: Compare benchmarks
|
|
id: compare
|
|
run: |
|
|
{
|
|
echo 'OUTPUT<<EOF'
|
|
mv out/benchmark-baseline.json out/main.json
|
|
mv out/benchmark.json out/changes.json
|
|
uv run pyperf compare_to out/main.json out/changes.json --table --group-by-speed
|
|
echo EOF
|
|
} >> "$GITHUB_OUTPUT"
|
|
- name: Annotation
|
|
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
|
env:
|
|
CHANGED_FILES: ${{ steps.files.outputs.added_modified_renamed }}
|
|
BENCHMARK_OUTPUT: ${{ steps.benchmark.outputs.OUTPUT }}
|
|
COMPARE_OUTPUT: ${{ steps.compare.outputs.OUTPUT }}
|
|
with:
|
|
script: |
|
|
const file = JSON.parse(process.env.CHANGED_FILES || "[]")[0]
|
|
core.notice(process.env.BENCHMARK_OUTPUT || "", {
|
|
title: 'Benchmark results',
|
|
file,
|
|
})
|
|
core.notice(process.env.COMPARE_OUTPUT || "", {
|
|
title: 'Comparison against main',
|
|
file,
|
|
})
|