mirror of
https://github.com/langchain-ai/langgraph.git
synced 2026-08-20 22:52:29 +02:00
## Summary - SHA-pins 7 distinct third-party actions across 10 workflow files to full commit SHAs - Prevents supply chain attacks via tag hijacking (mutable tags can be force-pushed by a compromised maintainer account) - Tag retained as an inline comment for readability | Action | Before | After | |--------|--------|-------| | `dorny/paths-filter` | `@v4` | `@fbd0ab8...` | | `Ana06/get-changed-files` | `@v2.3.0` | `@25f79e6...` | | `docker/login-action` | `@v4` | `@b45d80f...` | | `pypa/gh-action-pypi-publish` | `@release/v1` | `@ed0c539...` | | `ncipollo/release-action` | `@v1` | `@339a818...` | | `amannn/action-semantic-pull-request` | `@v6` | `@48f2562...` | | `peter-evans/create-pull-request` | `@v8` | `@c0f553f...` | ## Test plan - [x] CI passes on this PR - [x] Verify each pinned action still functions (no behaviour change, only ref format) 🤖 Generated with [Claude Code](https://claude.com/claude-code)
72 lines
2.0 KiB
YAML
72 lines
2.0 KiB
YAML
name: bench
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- "libs/**"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
benchmark:
|
|
runs-on: ubuntu-latest
|
|
defaults:
|
|
run:
|
|
working-directory: libs/langgraph
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- id: files
|
|
name: Get changed files
|
|
uses: Ana06/get-changed-files@25f79e676e7ea1868813e21465014798211fad8c # v2.3.0
|
|
with:
|
|
format: json
|
|
- name: Set up Python 3.11
|
|
uses: ./.github/actions/uv_setup
|
|
with:
|
|
python-version: "3.11"
|
|
cache-suffix: "bench"
|
|
working-directory: libs/langgraph
|
|
- name: Install dependencies
|
|
run: uv sync --group test
|
|
- name: Download baseline
|
|
uses: actions/cache/restore@v5
|
|
with:
|
|
key: ${{ runner.os }}-benchmark-baseline
|
|
restore-keys: |
|
|
${{ runner.os }}-benchmark-baseline-
|
|
fail-on-cache-miss: true
|
|
path: |
|
|
libs/langgraph/out/benchmark-baseline.json
|
|
- name: Run benchmarks
|
|
id: benchmark
|
|
run: |
|
|
{
|
|
echo 'OUTPUT<<EOF'
|
|
make -s benchmark-fast
|
|
echo EOF
|
|
} >> "$GITHUB_OUTPUT"
|
|
- name: Compare benchmarks
|
|
id: compare
|
|
run: |
|
|
{
|
|
echo 'OUTPUT<<EOF'
|
|
mv out/benchmark-baseline.json out/main.json
|
|
mv out/benchmark.json out/changes.json
|
|
uv run pyperf compare_to out/main.json out/changes.json --table --group-by-speed
|
|
echo EOF
|
|
} >> "$GITHUB_OUTPUT"
|
|
- name: Annotation
|
|
uses: actions/github-script@v8
|
|
with:
|
|
script: |
|
|
const file = JSON.parse(`${{ steps.files.outputs.added_modified_renamed }}`)[0]
|
|
core.notice(`${{ steps.benchmark.outputs.OUTPUT }}`, {
|
|
title: 'Benchmark results',
|
|
file,
|
|
})
|
|
core.notice(`${{ steps.compare.outputs.OUTPUT }}`, {
|
|
title: 'Comparison against main',
|
|
file,
|
|
})
|