Files
NotoriousRebel ea5db87915 Merge master into dev to resolve PR #2607 conflicts
Preserve provider outcome release notes alongside the HTTP proxy wording. Keep the dev domain glossary and carry the master HTTP-only proxy policy into its relocated architecture guide. Retain RocketReach cancellation coverage while removing the obsolete global dependency stub.

Align provider lifecycle regressions with the master session-construction boundary: construction ValueError is normalized to transport-error, while cancellation, lifecycle RuntimeError, and teardown ValueError still propagate.
2026-09-09 21:41:46 -04:00

159 lines
5.3 KiB
YAML

name: Release validation
on:
workflow_dispatch:
inputs:
run_live:
description: Run bounded P0 provider checks against mozilla.org
required: true
default: false
type: boolean
permissions:
contents: read
jobs:
python-ci:
uses: ./.github/workflows/theHarvester.yml
harvestview-e2e:
uses: ./.github/workflows/harvestview-e2e.yml
container-smoke:
uses: ./.github/workflows/harvestview-container.yml
package-smoke:
needs: python-ci
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: '3.14'
enable-cache: true
cache-dependency-glob: uv.lock
- name: Build distributions
run: uv build --out-dir release-dist
- name: Verify installed distributions
run: |
wheel_path="$(find release-dist -maxdepth 1 -name '*.whl' -print -quit)"
sdist_path="$(find release-dist -maxdepth 1 -name '*.tar.gz' -print -quit)"
test -n "$wheel_path"
test -n "$sdist_path"
uv run --isolated --no-project --with "$wheel_path" theHarvester --help
uv run --isolated --no-project --with "$wheel_path" harvestview --help
uv run --isolated --no-project --with "$sdist_path" theHarvester --help
- name: Upload release distributions
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: release-distributions-${{ github.sha }}
path: release-dist/*
if-no-files-found: error
retention-days: 7
live-provider-tests:
if: ${{ inputs.run_live }}
needs: [python-ci, harvestview-e2e, container-smoke, package-smoke]
runs-on: ubuntu-latest
timeout-minutes: 10
env:
SMOKE_TEST_DOMAIN: mozilla.org
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: '3.14'
enable-cache: true
cache-dependency-glob: uv.lock
- name: Install dependencies
run: uv sync --all-groups --frozen
- name: Validate P0 provider test contract
run: |
uv run python -c \
'import sys; from theHarvester.lib.source_catalog import ActivityClass, get_source_spec; assert all(get_source_spec(name).activity is ActivityClass.PASSIVE for name in sys.argv[1:])' \
certspotter otx thc
- name: Run opt-in live provider tests
run: |
uv run pytest --run-live-network -m live_network -q \
tests/discovery/test_certspotter.py::TestCertspotterSearch::test_api \
tests/discovery/test_otx.py::TestOtx::test_api \
tests/discovery/test_thc.py::TestThcApi
live-cli-smoke:
if: ${{ inputs.run_live }}
needs: [python-ci, harvestview-e2e, container-smoke, package-smoke]
runs-on: ubuntu-latest
timeout-minutes: 10
strategy:
fail-fast: false
matrix:
source:
- certspotter
- crtsh
- duckduckgo
- hackertarget
- otx
- rapiddns
- urlscan
- yahoo
env:
SMOKE_TEST_DOMAIN: mozilla.org
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
with:
egress-policy: audit
- name: Install uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: '3.14'
enable-cache: true
- name: Download release distributions
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: release-distributions-${{ github.sha }}
path: release-dist
- name: Verify source is P0
run: |
wheel_path="$(find release-dist -maxdepth 1 -name '*.whl' -print -quit)"
test -n "$wheel_path"
uv run --isolated --no-project --with "$wheel_path" python -c \
'import sys; from theHarvester.lib.source_catalog import ActivityClass, get_source_spec; assert get_source_spec(sys.argv[1]).activity is ActivityClass.PASSIVE' \
'${{ matrix.source }}'
- name: Run installed-wheel P0 CLI smoke
run: |
wheel_path="$(find release-dist -maxdepth 1 -name '*.whl' -print -quit)"
uv run --isolated --no-project --with "$wheel_path" \
theHarvester -d "$SMOKE_TEST_DOMAIN" -b '${{ matrix.source }}' -l 10 -q