chore: import upstream snapshot with attribution
Fuzz / Run fuzz harnesses (${{ github.event_name == 'schedule' && 'nightly' || 'smoke' }}) (push) Has been cancelled
Create Releases / call-mac (push) Has been cancelled
Create Releases / call-linux (push) Has been cancelled
Create Releases / call-sdist (push) Has been cancelled
Create Releases / call-win (push) Has been cancelled
Create Releases / call-pyodide (push) Has been cancelled
Windows_No_Exception_CI / build (x64, 3.10) (push) Has been cancelled
Check URLs / build (push) Has been cancelled
Create Releases / Attest CI build artifacts (push) Has been cancelled
Create Releases / Check for Publish release build to pypi (push) Has been cancelled
Create Releases / Check for Publish preview build to test.pypi-weekly (push) Has been cancelled
Create Releases / Publish preview build to test.pypi-weekly (push) Has been cancelled
Create Releases / Check for Publish release build to test.pypi (rc-candidates) (push) Has been cancelled
Create Releases / Publish release build to test.pypi (push) Has been cancelled
Create Releases / Check for Publish preview build to pypi-weekly (push) Has been cancelled
Create Releases / Publish preview build to pypi-weekly (push) Has been cancelled
Create Releases / Publish release build to pypi (push) Has been cancelled
Create Releases / test source distribution (push) Has been cancelled
clang-tidy / clang-tidy (push) Has been cancelled
Lint / Validate SBOM (push) Has been cancelled
Lint / Enforce style (push) Has been cancelled
CI / Test windows-2022, 3.14, External, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test windows-latest, 3.10, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test windows-latest, 3.14, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test windows-latest, 3.14t, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, Internal, debug=1, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, External, debug=0, unity_build=1, onnx_ml=1, autogen=1 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, External, debug=0, unity_build=0, onnx_ml=0, autogen=0 (push) Has been cancelled
CI / Test macos-latest, 3.10, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test macos-latest, 3.14, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test macos-latest, 3.14t, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, External, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.10, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14t, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
Pixi CI / Install and lint (ubuntu-24.04-arm) (push) Has been cancelled
Pixi CI / Install and lint (windows-2022) (push) Has been cancelled
Pixi CI / Xcode generator build (push) Has been cancelled
Pixi CI / Install and test (macos-latest, default) (push) Has been cancelled
Pixi CI / Install and test (ubuntu-24.04-arm, default) (push) Has been cancelled
Pixi CI / Install and test (ubuntu-latest, default) (push) Has been cancelled
Pixi CI / Install and test (windows-2022, default) (push) Has been cancelled
Pixi CI / Install and test (macos-latest, oldies) (push) Has been cancelled
Pixi CI / Install and test (ubuntu-24.04-arm, oldies) (push) Has been cancelled
Pixi CI / Install and test (ubuntu-latest, oldies) (push) Has been cancelled
Pixi CI / Install and test (windows-2022, oldies) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
CodeQL / Analyze (cpp) (push) Has been cancelled
CodeQL / Analyze (python) (push) Has been cancelled
Copilot Setup Steps / copilot-setup-steps (push) Has been cancelled
Generate and publish ONNX docs / build (push) Has been cancelled
Generate and publish ONNX docs / deploy (push) Has been cancelled
Scorecard supply-chain security / Scorecard analysis (push) Has been cancelled
Fuzz / Run fuzz harnesses (${{ github.event_name == 'schedule' && 'nightly' || 'smoke' }}) (push) Has been cancelled
Create Releases / call-mac (push) Has been cancelled
Create Releases / call-linux (push) Has been cancelled
Create Releases / call-sdist (push) Has been cancelled
Create Releases / call-win (push) Has been cancelled
Create Releases / call-pyodide (push) Has been cancelled
Windows_No_Exception_CI / build (x64, 3.10) (push) Has been cancelled
Check URLs / build (push) Has been cancelled
Create Releases / Attest CI build artifacts (push) Has been cancelled
Create Releases / Check for Publish release build to pypi (push) Has been cancelled
Create Releases / Check for Publish preview build to test.pypi-weekly (push) Has been cancelled
Create Releases / Publish preview build to test.pypi-weekly (push) Has been cancelled
Create Releases / Check for Publish release build to test.pypi (rc-candidates) (push) Has been cancelled
Create Releases / Publish release build to test.pypi (push) Has been cancelled
Create Releases / Check for Publish preview build to pypi-weekly (push) Has been cancelled
Create Releases / Publish preview build to pypi-weekly (push) Has been cancelled
Create Releases / Publish release build to pypi (push) Has been cancelled
Create Releases / test source distribution (push) Has been cancelled
clang-tidy / clang-tidy (push) Has been cancelled
Lint / Validate SBOM (push) Has been cancelled
Lint / Enforce style (push) Has been cancelled
CI / Test windows-2022, 3.14, External, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test windows-latest, 3.10, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test windows-latest, 3.14, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test windows-latest, 3.14t, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, Internal, debug=1, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, External, debug=0, unity_build=1, onnx_ml=1, autogen=1 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, External, debug=0, unity_build=0, onnx_ml=0, autogen=0 (push) Has been cancelled
CI / Test macos-latest, 3.10, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test macos-latest, 3.14, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test macos-latest, 3.14t, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, External, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.10, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
CI / Test ubuntu-24.04, 3.14t, Internal, debug=0, unity_build=0, onnx_ml=1, autogen=0 (push) Has been cancelled
Pixi CI / Install and lint (ubuntu-24.04-arm) (push) Has been cancelled
Pixi CI / Install and lint (windows-2022) (push) Has been cancelled
Pixi CI / Xcode generator build (push) Has been cancelled
Pixi CI / Install and test (macos-latest, default) (push) Has been cancelled
Pixi CI / Install and test (ubuntu-24.04-arm, default) (push) Has been cancelled
Pixi CI / Install and test (ubuntu-latest, default) (push) Has been cancelled
Pixi CI / Install and test (windows-2022, default) (push) Has been cancelled
Pixi CI / Install and test (macos-latest, oldies) (push) Has been cancelled
Pixi CI / Install and test (ubuntu-24.04-arm, oldies) (push) Has been cancelled
Pixi CI / Install and test (ubuntu-latest, oldies) (push) Has been cancelled
Pixi CI / Install and test (windows-2022, oldies) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
CodeQL / Analyze (cpp) (push) Has been cancelled
CodeQL / Analyze (python) (push) Has been cancelled
Copilot Setup Steps / copilot-setup-steps (push) Has been cancelled
Generate and publish ONNX docs / build (push) Has been cancelled
Generate and publish ONNX docs / deploy (push) Has been cancelled
Scorecard supply-chain security / Scorecard analysis (push) Has been cancelled
This commit is contained in:
@@ -0,0 +1,43 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Require topic/module label (prefix-only)
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, labeled, unlabeled, synchronize, reopened, ready_for_review]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: read
|
||||
actions: read
|
||||
|
||||
jobs:
|
||||
check-label:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Ensure PR has topic/module label
|
||||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
||||
with:
|
||||
script: |
|
||||
const author = context.payload.pull_request.user.login;
|
||||
const prLabels = context.payload.pull_request.labels.map(l => l.name);
|
||||
|
||||
if (author === "dependabot[bot]") {
|
||||
core.info("Skipping check for dependabot");
|
||||
return;
|
||||
}
|
||||
|
||||
if (prLabels.length === 0) {
|
||||
core.setFailed("❌ Add at least one label (topic:/module:).");
|
||||
return;
|
||||
}
|
||||
|
||||
const hasRequired = prLabels.some(l => l.startsWith("topic:") || l.startsWith("module:"));
|
||||
|
||||
if (!hasRequired) {
|
||||
core.setFailed("❌ Add a 'topic:' or 'module:' label.");
|
||||
} else {
|
||||
core.info("✅ Label check passed");
|
||||
}
|
||||
@@ -0,0 +1,47 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Check URLs
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ "main", rel-* ]
|
||||
pull_request:
|
||||
paths:
|
||||
- "**/*.md"
|
||||
- ".github/workflows/check_urls.yml"
|
||||
schedule:
|
||||
# Run every month
|
||||
- cron: '0 0 1 * *'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Set up pixi
|
||||
uses: prefix-dev/setup-pixi@5185adfbffb4bd703da3010310260805d89ebb11 # v0.9.6
|
||||
with:
|
||||
environments: link-checker
|
||||
|
||||
- name: Restore lychee cache
|
||||
id: restore-cache
|
||||
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
||||
with:
|
||||
path: .lycheecache
|
||||
# We don't hit the 'key' directly in subsequent
|
||||
# commits. Instead we fall back to the latest 'restore-key'
|
||||
# match and will store a new cached file when done.
|
||||
key: cache-lychee-${{ github.sha }}
|
||||
restore-keys: cache-lychee-
|
||||
|
||||
- name: Check links
|
||||
run: pixi run -e link-checker lychee --root-dir . --cache-exclude-status=400..599 --cache .
|
||||
@@ -0,0 +1,40 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: clang-tidy
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
clang-tidy:
|
||||
name: clang-tidy
|
||||
runs-on: ubuntu-24.04-arm
|
||||
strategy:
|
||||
fail-fast: false
|
||||
steps:
|
||||
- name: Checkout branch
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
submodules: recursive
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Set up pixi
|
||||
uses: prefix-dev/setup-pixi@5185adfbffb4bd703da3010310260805d89ebb11 # v0.9.6
|
||||
with:
|
||||
environments: default clang-tools
|
||||
- name: Install repository
|
||||
run: pixi run install
|
||||
- name: Run clang-tidy
|
||||
run: pixi run run-clang-tidy
|
||||
@@ -0,0 +1,88 @@
|
||||
name: "CodeQL"
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ "main" ]
|
||||
paths-ignore:
|
||||
- 'docs/**'
|
||||
- '**/*.md'
|
||||
pull_request:
|
||||
branches: [ "main" ]
|
||||
paths-ignore:
|
||||
- 'docs/**'
|
||||
- '**/*.md'
|
||||
schedule:
|
||||
- cron: '33 6 * * 5'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions: # set top-level default permissions as security best practice
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name == 'workflow_dispatch' }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
analyze:
|
||||
name: Analyze
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
actions: read
|
||||
contents: read
|
||||
security-events: write
|
||||
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
language: [ 'actions', 'cpp', 'python' ]
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
submodules: recursive
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Python
|
||||
if: matrix.language != 'actions'
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: '3.11'
|
||||
|
||||
- name: Upgrade pip
|
||||
if: matrix.language != 'actions'
|
||||
run: python -m pip install --upgrade pip
|
||||
|
||||
# Initializes the CodeQL tools for scanning.
|
||||
- name: Initialize CodeQL
|
||||
uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
|
||||
with:
|
||||
languages: ${{ matrix.language }}
|
||||
config: |
|
||||
queries:
|
||||
- uses: security-extended
|
||||
- uses: security-and-quality
|
||||
paths-ignore:
|
||||
- '.setuptools-cmake-build/**'
|
||||
- 'build/**'
|
||||
- 'onnx/**/*_pb2.py'
|
||||
- 'onnx/**/*_pb2.pyi'
|
||||
- '**/*.pb.cc'
|
||||
- '**/*.pb.h'
|
||||
- 'onnx/backend/test/data/**'
|
||||
query-filters:
|
||||
- exclude:
|
||||
id: py/import-and-import-from
|
||||
|
||||
# Install onnx so that it is found by the linters
|
||||
- name: Install ONNX
|
||||
if: matrix.language != 'actions'
|
||||
run: |
|
||||
export ONNX_ML=1
|
||||
export ONNX_BUILD_TESTS=1
|
||||
pip install .
|
||||
|
||||
- name: Perform CodeQL Analysis
|
||||
uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2
|
||||
with:
|
||||
category: "/language:${{matrix.language}}"
|
||||
@@ -0,0 +1,47 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: "Copilot Setup Steps"
|
||||
|
||||
# Automatically run the setup steps when they are changed to allow for easy validation, and
|
||||
# allow manual testing through the repository's "Actions" tab
|
||||
on:
|
||||
workflow_dispatch:
|
||||
push:
|
||||
paths:
|
||||
- .github/workflows/copilot-setup-steps.yml
|
||||
pull_request:
|
||||
paths:
|
||||
- .github/workflows/copilot-setup-steps.yml
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
# The job MUST be called `copilot-setup-steps` or it will not be picked up by Copilot.
|
||||
copilot-setup-steps:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
# Set the permissions to the lowest permissions possible needed for your steps.
|
||||
# Copilot will be given its own token for its operations.
|
||||
permissions:
|
||||
# If you want to clone the repository as part of your setup steps, for example to install dependencies, you'll need the `contents: read` permission. If you don't clone the repository in your setup steps, Copilot will do this for you automatically after the steps complete.
|
||||
contents: read
|
||||
# You can define any steps you want, and they will run before the agent starts.
|
||||
# If you do not check out your code, Copilot will do this for you.
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Setup Python
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
python -m pip install lintrunner>=0.10.7
|
||||
python -m pip install -r requirements-release_test.txt
|
||||
python -m pip install -r requirements-lintrunner.txt
|
||||
lintrunner init
|
||||
@@ -0,0 +1,437 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Create Releases
|
||||
on:
|
||||
schedule:
|
||||
# Run weekly on Monday 00:00 UTC
|
||||
- cron: '0 0 * * MON'
|
||||
|
||||
push:
|
||||
branches: [main, rel-*]
|
||||
pull_request:
|
||||
branches: [main, rel-*]
|
||||
types:
|
||||
- labeled
|
||||
- synchronize
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
publish_pypi_weekly: # only from main branch it is possible to publish to pypi-weekly (official weekly preview build)
|
||||
description: 'Publish to pypi-weekly'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- 'yes'
|
||||
- 'no'
|
||||
default: 'no'
|
||||
publish_testpypi_weekly: # only from main branch it is possible to publish to testpypi-weekly
|
||||
description: 'Publish to testpypi-weekly'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- 'yes'
|
||||
- 'no'
|
||||
default: 'no'
|
||||
publish_testpypi_release: # only from rel branch it is possible to publish to test-pypi (for rc1, rc2, etc.)
|
||||
description: 'Publish to testpypi-release'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- 'yes'
|
||||
- 'no'
|
||||
default: 'no'
|
||||
publish_pypi_release:
|
||||
description: 'Caution: Publish to pypi-release'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- 'yes'
|
||||
- 'no'
|
||||
default: 'no'
|
||||
build_mode:
|
||||
description: 'Specify the build mode (release or preview)'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- 'release'
|
||||
- 'preview'
|
||||
default: 'preview'
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name == 'workflow_dispatch' }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
|
||||
call-linux:
|
||||
if: github.event_name != 'pull_request' || contains(github.event.pull_request.labels.*.name, 'run release CIs') || contains(github.event.pull_request.labels.*.name, 'ci-slsa-provenance')
|
||||
uses: ./.github/workflows/release_linux_cibw.yml
|
||||
with:
|
||||
build_mode: ${{ github.event.inputs.build_mode || 'preview' }}
|
||||
|
||||
call-win:
|
||||
if: github.event_name != 'pull_request' || contains(github.event.pull_request.labels.*.name, 'run release CIs') || contains(github.event.pull_request.labels.*.name, 'ci-slsa-provenance')
|
||||
uses: ./.github/workflows/release_windows_cibw.yml
|
||||
with:
|
||||
build_mode: ${{ github.event.inputs.build_mode || 'preview' }}
|
||||
|
||||
call-mac:
|
||||
if: github.event_name != 'pull_request' || contains(github.event.pull_request.labels.*.name, 'run release CIs') || contains(github.event.pull_request.labels.*.name, 'ci-slsa-provenance')
|
||||
uses: ./.github/workflows/release_macos_cibw.yml
|
||||
with:
|
||||
build_mode: ${{ github.event.inputs.build_mode || 'preview' }}
|
||||
|
||||
call-pyodide:
|
||||
if: github.event_name != 'pull_request' || contains(github.event.pull_request.labels.*.name, 'run release CIs') || contains(github.event.pull_request.labels.*.name, 'ci-slsa-provenance')
|
||||
uses: ./.github/workflows/release_pyodide_cibw.yml
|
||||
with:
|
||||
build_mode: ${{ github.event.inputs.build_mode || 'preview' }}
|
||||
|
||||
call-sdist:
|
||||
if: github.event_name != 'pull_request' || contains(github.event.pull_request.labels.*.name, 'run release CIs') || contains(github.event.pull_request.labels.*.name, 'ci-slsa-provenance')
|
||||
uses: ./.github/workflows/release_sdist.yml
|
||||
with:
|
||||
os: "macos"
|
||||
build_mode: ${{ github.event.inputs.build_mode || 'preview' }}
|
||||
|
||||
attest_ci_build_artifacts:
|
||||
name: Attest CI build artifacts
|
||||
runs-on: ubuntu-latest
|
||||
needs: [call-linux, call-mac, call-win, call-pyodide, call-sdist]
|
||||
if: >-
|
||||
(!contains(join(needs.*.result, ' '), 'skipped')) &&
|
||||
(github.repository_owner == 'onnx') &&
|
||||
(
|
||||
(github.event_name == 'push') ||
|
||||
(github.event_name == 'pull_request' && contains(github.event.pull_request.labels.*.name, 'ci-slsa-provenance')) ||
|
||||
(
|
||||
(github.event_name == 'workflow_dispatch') &&
|
||||
(github.event.inputs.publish_pypi_weekly != 'yes') &&
|
||||
(github.event.inputs.publish_testpypi_weekly != 'yes') &&
|
||||
(github.event.inputs.publish_testpypi_release != 'yes') &&
|
||||
(github.event.inputs.publish_pypi_release != 'yes')
|
||||
)
|
||||
)
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
attestations: write
|
||||
|
||||
steps:
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
with:
|
||||
pattern: wheels*
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
with:
|
||||
pattern: sdist
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- name: Generate SLSA Build Provenance attestations
|
||||
if: hashFiles('dist/**') != ''
|
||||
id: attest
|
||||
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
|
||||
with:
|
||||
subject-path: dist/**
|
||||
|
||||
- name: Upload attestation bundle
|
||||
if: hashFiles('dist/**') != ''
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: attestation-bundle-ci
|
||||
path: ${{ steps.attest.outputs.bundle-path }}
|
||||
|
||||
check_for_publish_release_build_to_pypi:
|
||||
name: Check for Publish release build to pypi
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
needs: [call-linux, call-mac, call-win, call-pyodide, call-sdist]
|
||||
if: (!contains(join(needs.*.result, ' '), 'skipped')) && (github.event.inputs.publish_pypi_release == 'yes') && (github.repository_owner == 'onnx') && startsWith(github.ref, 'refs/heads/rel-') && (github.event_name == 'workflow_dispatch')
|
||||
|
||||
steps:
|
||||
|
||||
- name: Ensure build mode is release
|
||||
run: |
|
||||
if [ "$BUILD_MODE" != "release" ]; then
|
||||
echo "Error: build_mode must be set to 'release' to proceed."
|
||||
exit 1
|
||||
fi
|
||||
env:
|
||||
BUILD_MODE: ${{ github.event.inputs.build_mode }}
|
||||
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
submodules: true
|
||||
|
||||
- name: Check if package_version matches branch
|
||||
run: |
|
||||
branch_version=${GITHUB_REF#refs/heads/rel-}
|
||||
package_version=$(cat VERSION_NUMBER)
|
||||
echo "Branch version: $branch_version"
|
||||
echo "Package version: $package_version"
|
||||
|
||||
if [[ "$package_version" != "$branch_version" && "$package_version" != "$branch_version"rc* ]]; then
|
||||
echo "Error: Package version ($package_version) does not match branch version ($branch_version) or expected RC format."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
check_for_publish_preview_build_to_testpypi_weekly:
|
||||
name: Check for Publish preview build to test.pypi-weekly
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
needs: [call-linux, call-mac, call-win, call-pyodide, call-sdist]
|
||||
if: (!contains(join(needs.*.result, ' '), 'skipped')) && (github.event.inputs.publish_testpypi_weekly == 'yes') && (github.ref == 'refs/heads/main') && (github.repository_owner == 'onnx') && (github.event_name == 'workflow_dispatch')
|
||||
|
||||
steps:
|
||||
- name: Confirm preview publish request
|
||||
run: echo "Proceeding with test.pypi-weekly publish checks."
|
||||
|
||||
|
||||
publish_preview_build_to_testpypi_weekly:
|
||||
name: Publish preview build to test.pypi-weekly
|
||||
runs-on: ubuntu-latest
|
||||
needs: [check_for_publish_preview_build_to_testpypi_weekly]
|
||||
|
||||
environment:
|
||||
name: testpypi-weekly
|
||||
url: https://test.pypi.org/p/onnx-weekly
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
attestations: write
|
||||
|
||||
steps:
|
||||
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
if: (github.event_name == 'workflow_dispatch' )
|
||||
with:
|
||||
pattern: wheels*
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
if: (github.event_name == 'workflow_dispatch' )
|
||||
with:
|
||||
pattern: sdist
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- name: Generate SLSA Build Provenance attestations
|
||||
if: hashFiles('dist/**') != ''
|
||||
id: attest
|
||||
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
|
||||
with:
|
||||
subject-path: dist/**
|
||||
|
||||
- name: Upload attestation bundle
|
||||
if: hashFiles('dist/**') != ''
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: attestation-bundle-testpypi-weekly
|
||||
path: ${{ steps.attest.outputs.bundle-path }}
|
||||
|
||||
- name: Upload preview build to test.pypi
|
||||
if: (github.ref == 'refs/heads/main') && (github.event.inputs.publish_testpypi_weekly == 'yes') && (github.repository_owner == 'onnx')
|
||||
id: upload_preview_build_to_testpypi_weekly
|
||||
|
||||
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b
|
||||
with:
|
||||
repository-url: https://test.pypi.org/legacy/
|
||||
verbose: true
|
||||
print-hash: true
|
||||
|
||||
check_for_publish_release_build_to_testpypi:
|
||||
name: Check for Publish release build to test.pypi (rc-candidates)
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
needs: [call-linux, call-mac, call-win, call-pyodide, call-sdist]
|
||||
if: (!contains(join(needs.*.result, ' '), 'skipped')) && (github.event.inputs.publish_testpypi_release == 'yes') && startsWith(github.ref, 'refs/heads/rel') && (github.repository_owner == 'onnx') && (github.event_name == 'workflow_dispatch')
|
||||
|
||||
steps:
|
||||
- name: Confirm release publish request
|
||||
run: echo "Proceeding with test.pypi release publish checks."
|
||||
|
||||
publish_release_build_to_testpypi:
|
||||
name: Publish release build to test.pypi
|
||||
runs-on: ubuntu-latest
|
||||
needs: [check_for_publish_release_build_to_testpypi]
|
||||
|
||||
environment:
|
||||
name: testpypi-release
|
||||
url: https://test.pypi.org/p/onnx
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
attestations: write
|
||||
|
||||
steps:
|
||||
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
if: (github.event_name == 'workflow_dispatch' )
|
||||
with:
|
||||
pattern: wheels*
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
if: (github.event_name == 'workflow_dispatch' )
|
||||
with:
|
||||
pattern: sdist
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- name: Generate SLSA Build Provenance attestations
|
||||
if: hashFiles('dist/**') != ''
|
||||
id: attest
|
||||
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
|
||||
with:
|
||||
subject-path: dist/**
|
||||
|
||||
- name: Upload attestation bundle
|
||||
if: hashFiles('dist/**') != ''
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: attestation-bundle-testpypi-release
|
||||
path: ${{ steps.attest.outputs.bundle-path }}
|
||||
|
||||
- name: Upload release build to test.pypi
|
||||
id: upload_release_build_to_testpypi
|
||||
|
||||
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b
|
||||
with:
|
||||
repository-url: https://test.pypi.org/legacy/
|
||||
verbose: true
|
||||
print-hash: true
|
||||
|
||||
|
||||
check_for_publish_preview_build_to_pypi_weekly:
|
||||
name: Check for Publish preview build to pypi-weekly
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
needs: [call-linux, call-mac, call-win, call-pyodide, call-sdist]
|
||||
if: (!contains(join(needs.*.result, ' '), 'skipped')) && (github.event_name == 'schedule' || github.event.inputs.publish_pypi_weekly == 'yes') && (github.repository_owner == 'onnx')
|
||||
|
||||
steps:
|
||||
- name: Confirm weekly publish request
|
||||
run: echo "Proceeding with pypi-weekly publish checks."
|
||||
|
||||
publish_preview_build_to_pypi_weekly:
|
||||
name: Publish preview build to pypi-weekly
|
||||
runs-on: ubuntu-latest
|
||||
needs: [check_for_publish_preview_build_to_pypi_weekly]
|
||||
|
||||
environment:
|
||||
name: pypi-weekly
|
||||
url: https://pypi.org/p/onnx-weekly
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
attestations: write
|
||||
|
||||
steps:
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
if: (github.event_name == 'schedule' || github.event_name == 'workflow_dispatch')
|
||||
with:
|
||||
pattern: wheels*
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
if: (github.event_name == 'schedule' || github.event_name == 'workflow_dispatch')
|
||||
with:
|
||||
pattern: sdist
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- name: Generate SLSA Build Provenance attestations
|
||||
if: hashFiles('dist/**') != ''
|
||||
id: attest
|
||||
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
|
||||
with:
|
||||
subject-path: dist/**
|
||||
|
||||
- name: Upload attestation bundle
|
||||
if: hashFiles('dist/**') != ''
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: attestation-bundle-weekly
|
||||
path: ${{ steps.attest.outputs.bundle-path }}
|
||||
|
||||
- name: Upload preview_build to pypi-weekly
|
||||
id: upload_preview_build_to_pypi_weekly
|
||||
if: (github.ref == 'refs/heads/main')
|
||||
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b
|
||||
with:
|
||||
repository-url: https://upload.pypi.org/legacy/
|
||||
verbose: true
|
||||
print-hash: true
|
||||
|
||||
|
||||
publish_release_build_to_pypi:
|
||||
name: Publish release build to pypi
|
||||
runs-on: ubuntu-latest
|
||||
needs: [check_for_publish_release_build_to_pypi]
|
||||
|
||||
environment:
|
||||
name: pypi-release
|
||||
url: https://pypi.org/p/onnx
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
attestations: write
|
||||
|
||||
steps:
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
if: (github.event_name == 'workflow_dispatch')
|
||||
with:
|
||||
pattern: wheels*
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c
|
||||
if: (github.event_name == 'workflow_dispatch')
|
||||
with:
|
||||
pattern: sdist
|
||||
path: dist
|
||||
merge-multiple: true
|
||||
|
||||
- name: Generate SLSA Build Provenance attestations
|
||||
if: hashFiles('dist/**') != ''
|
||||
id: attest
|
||||
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0
|
||||
with:
|
||||
subject-path: dist/**
|
||||
|
||||
- name: Upload attestation bundle
|
||||
if: hashFiles('dist/**') != ''
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: attestation-bundle-release
|
||||
path: ${{ steps.attest.outputs.bundle-path }}
|
||||
|
||||
- name: Publish release_build to pypi
|
||||
if: (github.repository_owner == 'onnx')
|
||||
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b
|
||||
with:
|
||||
repository-url: https://upload.pypi.org/legacy/
|
||||
verbose: true
|
||||
print-hash: true
|
||||
|
||||
test_source_dist:
|
||||
name: test source distribution
|
||||
needs: [publish_preview_build_to_pypi_weekly, publish_release_build_to_testpypi]
|
||||
if: (needs.publish_preview_build_to_pypi_weekly.result == 'success' || needs.publish_release_build_to_testpypi.result == 'success')
|
||||
uses: ./.github/workflows/preview_source_dist_test.yml
|
||||
@@ -0,0 +1,17 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: DCO
|
||||
on:
|
||||
merge_group:
|
||||
|
||||
permissions: # set top-level default permissions as security best practice
|
||||
contents: read # Check https://github.com/ossf/scorecard/blob/7ce8609469289d5f3b1bf5ee3122f42b4e3054fb/docs/checks.md#token-permissions
|
||||
|
||||
jobs:
|
||||
DCO:
|
||||
runs-on: ubuntu-latest
|
||||
if: ${{ github.actor != 'dependabot[bot]' }}
|
||||
steps:
|
||||
- run: echo "dummy DCO workflow (it won't run any check actually) to trigger by merge_group in order to enable merge queue"
|
||||
@@ -0,0 +1,22 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: 'Dependency Review'
|
||||
on: [pull_request]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
dependency-review:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: 'Checkout Repository'
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
|
||||
with:
|
||||
submodules: recursive
|
||||
persist-credentials: false
|
||||
|
||||
- name: 'Dependency Review'
|
||||
uses: actions/dependency-review-action@dcd589ca9f7a6ded22e224ca2e288beb6bf9846b
|
||||
@@ -0,0 +1,129 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
# Runs the OSS-Fuzz harnesses under onnx/fuzz/ directly (not via OSS-Fuzz
|
||||
# infrastructure) as a regression check. This is deliberately not a
|
||||
# replacement for OSS-Fuzz's own continuous, long-running campaigns
|
||||
# (see google/oss-fuzz#15382) — it exists to catch harness regressions
|
||||
# (import errors, API drift, a harness file going missing) at PR time
|
||||
# instead of silently, since OSS-Fuzz failures are not surfaced here.
|
||||
#
|
||||
# atheris only ships wheels for Linux and macOS, so this does not run on
|
||||
# Windows. See https://github.com/onnx/onnx/blob/main/onnx/fuzz/README.md
|
||||
# for the harness/toggle-byte details.
|
||||
|
||||
name: Fuzz
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
paths:
|
||||
- 'onnx/**'
|
||||
- 'pyproject.toml'
|
||||
- '.github/workflows/fuzz.yml'
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- 'onnx/**'
|
||||
- 'pyproject.toml'
|
||||
- '.github/workflows/fuzz.yml'
|
||||
schedule:
|
||||
- cron: '0 6 * * *' # nightly: run each harness for longer than the PR smoke test
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
fuzz:
|
||||
name: Run fuzz harnesses (${{ github.event_name == 'schedule' && 'nightly' || 'smoke' }})
|
||||
runs-on: ubuntu-24.04
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
submodules: recursive
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: '3.12'
|
||||
|
||||
- name: Build and install ONNX
|
||||
run: pip install -e ".[reference]" -v
|
||||
env:
|
||||
ONNX_ML: 1
|
||||
|
||||
- name: Install atheris
|
||||
run: pip install atheris
|
||||
|
||||
- name: Generate seed corpora
|
||||
run: |
|
||||
mkdir -p corpus
|
||||
python onnx/fuzz/make_seed_corpus.py \
|
||||
corpus/version_converter.zip corpus/parser.zip \
|
||||
corpus/checker.zip corpus/shape_inference.zip corpus/compose.zip
|
||||
for name in version_converter parser checker shape_inference compose; do
|
||||
mkdir -p "corpus/$name"
|
||||
python -m zipfile -e "corpus/$name.zip" "corpus/$name/"
|
||||
done
|
||||
# fuzz_model_loader.py has no dedicated seeds; it exercises the same
|
||||
# load+check path as fuzz_checker.py, so reuse that corpus.
|
||||
mkdir -p corpus/model_loader
|
||||
cp corpus/checker/* corpus/model_loader/
|
||||
|
||||
- name: Set fuzz duration
|
||||
id: duration
|
||||
run: |
|
||||
if [ "${{ github.event_name }}" = "schedule" ]; then
|
||||
echo "seconds=300" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "seconds=60" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
|
||||
- name: Run fuzz_checker.py
|
||||
run: python onnx/fuzz/fuzz_checker.py -max_total_time="$FUZZ_SECONDS" -timeout=20 corpus/checker
|
||||
env:
|
||||
FUZZ_SECONDS: ${{ steps.duration.outputs.seconds }}
|
||||
|
||||
- name: Run fuzz_model_loader.py
|
||||
run: python onnx/fuzz/fuzz_model_loader.py -max_total_time="$FUZZ_SECONDS" -timeout=20 corpus/model_loader
|
||||
env:
|
||||
FUZZ_SECONDS: ${{ steps.duration.outputs.seconds }}
|
||||
|
||||
- name: Run fuzz_parser.py
|
||||
run: python onnx/fuzz/fuzz_parser.py -max_total_time="$FUZZ_SECONDS" -timeout=20 corpus/parser
|
||||
env:
|
||||
FUZZ_SECONDS: ${{ steps.duration.outputs.seconds }}
|
||||
|
||||
- name: Run fuzz_shape_inference.py
|
||||
run: python onnx/fuzz/fuzz_shape_inference.py -max_total_time="$FUZZ_SECONDS" -timeout=20 corpus/shape_inference
|
||||
env:
|
||||
FUZZ_SECONDS: ${{ steps.duration.outputs.seconds }}
|
||||
|
||||
- name: Run fuzz_version_converter.py
|
||||
run: python onnx/fuzz/fuzz_version_converter.py -max_total_time="$FUZZ_SECONDS" -timeout=20 corpus/version_converter
|
||||
env:
|
||||
FUZZ_SECONDS: ${{ steps.duration.outputs.seconds }}
|
||||
|
||||
- name: Run fuzz_compose.py
|
||||
run: python onnx/fuzz/fuzz_compose.py -max_total_time="$FUZZ_SECONDS" -timeout=20 corpus/compose
|
||||
env:
|
||||
FUZZ_SECONDS: ${{ steps.duration.outputs.seconds }}
|
||||
|
||||
- name: Upload crash artifacts
|
||||
if: failure()
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: fuzz-crashes
|
||||
path: |
|
||||
crash-*
|
||||
timeout-*
|
||||
oom-*
|
||||
if-no-files-found: ignore
|
||||
@@ -0,0 +1,117 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Lint
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
pull_request:
|
||||
merge_group:
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name == 'workflow_dispatch' }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
validate-sbom:
|
||||
name: Validate SBOM
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: '3.12'
|
||||
- run: |
|
||||
pip install -q check-jsonschema
|
||||
python -m check_jsonschema --schemafile "https://cyclonedx.org/schema/bom-1.7.schema.json" sbom.cdx.json
|
||||
|
||||
enforce-style:
|
||||
name: Enforce style
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
security-events: write
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Setup Python
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- name: Install ONNX
|
||||
run: |
|
||||
source workflow_scripts/protobuf/build_protobuf_unix.sh $(nproc)
|
||||
|
||||
python -m pip install --quiet --upgrade pip setuptools wheel
|
||||
|
||||
export ONNX_BUILD_TESTS=0
|
||||
export ONNX_ML=1
|
||||
export CMAKE_ARGS="-DONNXIFI_DUMMY_BACKEND=ON -DONNX_WERROR=ON"
|
||||
export ONNX_NAMESPACE=ONNX_NAMESPACE_FOO_BAR_FOR_CI
|
||||
|
||||
python -m pip install .
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
python -m pip install lintrunner>=0.10.7
|
||||
# Use release_test to pin package versions
|
||||
python -m pip install -r requirements-release_test.txt
|
||||
python -m pip install -r requirements-lintrunner.txt
|
||||
lintrunner init
|
||||
- name: Run lintrunner on all files
|
||||
run: |
|
||||
set +e
|
||||
if ! lintrunner --force-color --all-files --tee-json=lint.json -v; then
|
||||
echo ""
|
||||
echo -e "\e[1m\e[36mYou can reproduce these results locally by using \`lintrunner\`.\e[0m"
|
||||
echo -e "\e[1m\e[36mSee https://github.com/onnx/onnx/blob/main/CONTRIBUTING.md#coding-style for setup instructions.\e[0m"
|
||||
exit 1
|
||||
fi
|
||||
- name: Produce SARIF
|
||||
if: always()
|
||||
run: |
|
||||
python -m lintrunner_adapters to-sarif lint.json lintrunner.sarif
|
||||
- name: Upload SARIF file
|
||||
# Use always() to always upload SARIF even if lintrunner returns with error code
|
||||
# To toggle linter comments in the files page, press `i` on the keyboard
|
||||
if: always()
|
||||
continue-on-error: true
|
||||
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e
|
||||
with:
|
||||
# Path to SARIF file relative to the root of the repository
|
||||
sarif_file: lintrunner.sarif
|
||||
category: lintrunner
|
||||
checkout_path: ${{ github.workspace }}
|
||||
- name: Upload lint results as artifacts
|
||||
if: always()
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
|
||||
with:
|
||||
name: lint-results
|
||||
path: |
|
||||
lint.json
|
||||
lintrunner.sarif
|
||||
retention-days: 30
|
||||
- name: Check auto-gen files are up-to-date
|
||||
run: |
|
||||
echo -e "\n::group:: ===> check auto-gen files are up-to-date..."
|
||||
|
||||
ONNX_ML=1 python onnx/defs/gen_doc.py
|
||||
python onnx/gen_proto.py -l
|
||||
python onnx/gen_proto.py -l --ml
|
||||
python onnx/backend/test/stat_coverage.py
|
||||
|
||||
git status
|
||||
git diff --exit-code -- . ':(exclude)onnx/onnx-data.proto' ':(exclude)onnx/onnx-data.proto3'
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "git diff returned failures"
|
||||
exit 1
|
||||
fi
|
||||
echo -e "::endgroup::"
|
||||
@@ -0,0 +1,280 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: CI
|
||||
|
||||
env:
|
||||
ASAN_OPTIONS: detect_leaks=0:symbolize=1:detect_stack_use_after_return=true:strict_init_order=true:detect_odr_violation=1:detect_container_overflow=0:check_initialization_order=true:debug=true:fast_unwind_on_malloc=1:verify_asan_link_order=0
|
||||
UBSAN_OPTIONS: print_stacktrace=1
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '0 0 * * *' # every day at midnight for reporting code coverage to codecov
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
pull_request:
|
||||
merge_group:
|
||||
workflow_dispatch:
|
||||
|
||||
permissions: # set top-level default permissions as security good practice
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name == 'workflow_dispatch' }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
test:
|
||||
name: Test ${{ matrix.os }}, ${{ matrix.python_version }}, ${{ matrix.protobuf_type }}, debug=${{ matrix.debug_build }}, unity_build=${{ matrix.unity_build }}, onnx_ml=${{ matrix.onnx_ml }}, autogen=${{ matrix.autogenerate_files }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os: [ubuntu-24.04, windows-latest, macos-latest]
|
||||
# Test on the oldest and latest supported Python versions
|
||||
autogenerate_files: [0]
|
||||
debug_build: [0]
|
||||
onnx_ml: [1]
|
||||
protobuf_type: ['Internal']
|
||||
python_version: ['3.14t', '3.14', '3.10']
|
||||
unity_build: [0]
|
||||
|
||||
include:
|
||||
# Ubuntu debug build runs with sanitizer
|
||||
- python_version: "3.14"
|
||||
autogenerate_files: 0
|
||||
debug_build: 1
|
||||
onnx_ml: 1
|
||||
os: "ubuntu-24.04"
|
||||
protobuf_type: 'Internal'
|
||||
unity_build: 0
|
||||
|
||||
# Test compilation with dynamically linked protobuf.
|
||||
# This is actually redundant with the pixi-tests which
|
||||
# also use dynamic linking.
|
||||
- python_version: "3.14"
|
||||
autogenerate_files: 0
|
||||
debug_build: 0
|
||||
onnx_ml: 1
|
||||
os: "ubuntu-24.04"
|
||||
protobuf_type: 'External'
|
||||
unity_build: 0
|
||||
- python_version: "3.14"
|
||||
autogenerate_files: 0
|
||||
debug_build: 0
|
||||
onnx_ml: 1
|
||||
os: "windows-2022"
|
||||
protobuf_type: 'External'
|
||||
unity_build: 0
|
||||
# build_protobuf_unix.sh appears broken on macos-arm64
|
||||
# - python_version: "3.14"
|
||||
# debug_build: 0
|
||||
# unity_build: 0
|
||||
# autogenerate_files: 0
|
||||
# protobuf_type: 'External'
|
||||
# os: "macos-latest"
|
||||
|
||||
# Unity build AND autogenerated files
|
||||
# The unity build may surface name clashes at compile time
|
||||
# but produces functionally identical binaries. We can
|
||||
# therefore safely reuse this build to test the
|
||||
# autogenerated files.
|
||||
- python_version: '3.14'
|
||||
autogenerate_files: 1
|
||||
debug_build: 0
|
||||
onnx_ml: 1
|
||||
os: "ubuntu-24.04"
|
||||
protobuf_type: 'External'
|
||||
unity_build: 1
|
||||
|
||||
# Toggling onnx_ml should be additive. There is likely very
|
||||
# different signal in testing it in relation with other
|
||||
# parameters.
|
||||
- python_version: '3.14'
|
||||
autogenerate_files: 0
|
||||
debug_build: 0
|
||||
onnx_ml: 0
|
||||
os: "ubuntu-24.04"
|
||||
protobuf_type: 'External'
|
||||
unity_build: 0
|
||||
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
|
||||
with:
|
||||
submodules: recursive
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: ${{ matrix.python_version }}
|
||||
|
||||
- name: Show versions
|
||||
run: |
|
||||
python --version
|
||||
cmake --version
|
||||
|
||||
- name: Install external protobuf - Linux
|
||||
if: matrix.protobuf_type == 'External' && startsWith(matrix.os,'ubuntu')
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install libprotobuf-dev protobuf-compiler
|
||||
|
||||
- name: Install external protobuf - MacOS
|
||||
if: matrix.protobuf_type == 'External' && matrix.os == 'macos-latest'
|
||||
run: |
|
||||
source workflow_scripts/protobuf/build_protobuf_unix.sh 3 $(pwd)/protobuf/protobuf_install
|
||||
|
||||
- name: Set up MSBuild (x64)
|
||||
if: startsWith(matrix.os,'windows')
|
||||
uses: microsoft/setup-msbuild@30375c66a4eea26614e0d39710365f22f8b0af57 # v3.0.0
|
||||
with:
|
||||
msbuild-architecture: x64
|
||||
|
||||
- name: Install external protobuf - Windows
|
||||
if: matrix.protobuf_type == 'External' && startsWith(matrix.os, 'windows')
|
||||
run: |
|
||||
if ($matrix.os -like "windows-11-arm*") {
|
||||
$cmake_arch = "ARM64"
|
||||
} else {
|
||||
$cmake_arch = "x64"
|
||||
}
|
||||
|
||||
workflow_scripts/protobuf/build_protobuf_win.ps1 -cmake_arch $cmake_arch
|
||||
shell: pwsh
|
||||
|
||||
- name: Build and install ONNX - Linux
|
||||
if: startsWith(matrix.os,'ubuntu')
|
||||
run: |
|
||||
export SOURCE_DATE_EPOCH=$(git log -1 --pretty=%ct)
|
||||
if [ "${{ matrix.python_version }}" == "3.14" ]; then
|
||||
sudo apt-get update
|
||||
sudo apt-get install libjpeg-dev zlib1g-dev libpng-dev
|
||||
fi
|
||||
|
||||
if [ "${{ matrix.protobuf_type }}" == "External" ]; then
|
||||
export CMAKE_ARGS="$CMAKE_ARGS -DCMAKE_POSITION_INDEPENDENT_CODE=ON -DONNX_USE_PROTOBUF_SHARED_LIBS=ON"
|
||||
fi
|
||||
pip install -e ".[reference]" -v
|
||||
env:
|
||||
DEBUG: ${{ matrix.debug_build }}
|
||||
ONNX_ML: ${{ matrix.onnx_ml }}
|
||||
ONNX_BUILD_TESTS: 1
|
||||
CMAKE_ARGS: "-DONNX_WERROR=ON -DONNX_USE_ASAN=${{ matrix.debug_build }} -DONNX_USE_UNITY_BUILD=${{ matrix.unity_build }} -DONNX_HARDENING=ON"
|
||||
|
||||
- name: Build and install ONNX - MacOS
|
||||
if: matrix.os == 'macos-latest'
|
||||
run: |
|
||||
pip install -e ".[reference]" -v
|
||||
env:
|
||||
DEBUG: ${{ matrix.debug_build }}
|
||||
ONNX_ML: ${{ matrix.onnx_ml }}
|
||||
ONNX_BUILD_TESTS: 1
|
||||
CMAKE_ARGS: "-DONNX_WERROR=ON -DONNX_USE_UNITY_BUILD=${{ matrix.unity_build }} -DONNX_HARDENING=ON"
|
||||
|
||||
- name: Build and install ONNX - Windows
|
||||
if: startsWith(matrix.os,'windows')
|
||||
run: |
|
||||
pip install -e . -v
|
||||
env:
|
||||
DEBUG: ${{ matrix.debug_build }}
|
||||
ONNX_ML: ${{ matrix.onnx_ml }}
|
||||
ONNX_BUILD_TESTS: 1
|
||||
CMAKE_ARGS: "-DONNX_WERROR=ON -DONNX_USE_PROTOBUF_SHARED_LIBS=OFF -DONNX_USE_LITE_PROTO=ON -DONNX_USE_UNITY_BUILD=${{ matrix.unity_build }} -DONNX_HARDENING=ON"
|
||||
|
||||
- name: pip freeze
|
||||
run: |
|
||||
pip freeze
|
||||
|
||||
- name: Setup GCC ASAN LD_PRELOAD
|
||||
if: startsWith(matrix.os,'ubuntu') && (matrix.python_version != '3.13t')
|
||||
run: |
|
||||
export LD_PRELOAD="$(/usr/bin/c++ -print-file-name=libasan.so):$LD_PRELOAD"
|
||||
|
||||
- name: Install test dependencies
|
||||
run: |
|
||||
python -m pip install -r requirements-release_test.txt
|
||||
|
||||
- name: Run Python tests
|
||||
# Prohibitively slow for Windows debug builds
|
||||
if: ${{ !(startsWith(matrix.os, 'windows') && matrix.debug_build == 1) }}
|
||||
run: |
|
||||
pytest -sv --cov=onnx --cov-report=xml --cov-append --cov-branch --junitxml junit.xml -n auto --dist loadscope
|
||||
- name: Run C++ tests
|
||||
if: startsWith(matrix.os,'ubuntu') || matrix.os == 'macos-latest'
|
||||
run: |
|
||||
export LD_LIBRARY_PATH="./.setuptools-cmake-build/:$LD_LIBRARY_PATH"
|
||||
./.setuptools-cmake-build/onnx_gtests
|
||||
|
||||
- name: Run C++ extension test
|
||||
if: (startsWith(matrix.os,'ubuntu') || matrix.os == 'macos-latest') && matrix.debug_build == 0 && matrix.protobuf_type == 'External'
|
||||
run: |
|
||||
cmake -S . -B build_for_install \
|
||||
-DCMAKE_BUILD_TYPE=Release \
|
||||
-DCMAKE_INSTALL_PREFIX=/usr/local \
|
||||
-DONNX_ML=${{ matrix.onnx_ml }} \
|
||||
-DONNX_USE_PROTOBUF_SHARED_LIBS=ON
|
||||
cmake --build build_for_install --parallel
|
||||
sudo cmake --install build_for_install
|
||||
|
||||
cmake -S onnx/test/cmake -B onnx/test/cmake/build \
|
||||
-DONNX_ML=${{ matrix.onnx_ml }}
|
||||
cmake --build onnx/test/cmake/build
|
||||
./onnx/test/cmake/build/main
|
||||
|
||||
- name: Upload coverage to Codecov
|
||||
if: github.repository_owner == 'onnx'
|
||||
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
|
||||
with:
|
||||
token: ${{ secrets.CODECOV_TOKEN }}
|
||||
|
||||
- name: Upload test results to Codecov
|
||||
if: github.repository_owner == 'onnx' && !cancelled()
|
||||
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
|
||||
with:
|
||||
token: ${{ secrets.CODECOV_TOKEN }}
|
||||
report_type: test_results
|
||||
|
||||
# Note that the test data should be generated with numpy>=2.0.
|
||||
# numpy 1.x and numpy 2.0 produce slightly different numerical values.
|
||||
- name: Test backend test data
|
||||
if: matrix.autogenerate_files == 1 && startsWith(matrix.os,'ubuntu')
|
||||
run: |
|
||||
python onnx/backend/test/cmd_tools.py generate-data --clean
|
||||
git status
|
||||
git diff --exit-code -- . ':!onnx/onnx-data.proto' ':!onnx/onnx-data.proto3' ':!*output_*.pb' ':!*input_*.pb'
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "git diff for test generation returned failures. Please check updated node test files"
|
||||
exit 1
|
||||
fi
|
||||
git diff --exit-code --diff-filter=ADR -- . ':!onnx/onnx-data.proto' ':!onnx/onnx-data.proto3'
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "Test generation returned failures. Please check the number of node test files (input_*.pb or output_*.pb)"
|
||||
exit 1
|
||||
fi
|
||||
pip uninstall -y pillow
|
||||
python onnx/backend/test/cmd_tools.py generate-data --clean
|
||||
git status
|
||||
git diff --exit-code -- . ':!onnx/onnx-data.proto' ':!onnx/onnx-data.proto3' ':!*output_*.pb' ':!*input_*.pb'
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "git diff for test generation without pillow returned failures. Please check updated node test files"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Run Python tests with numpy<2.0 (win, mac)
|
||||
if: (matrix.python_version == '3.10') && (matrix.os == 'windows-latest' || matrix.os == 'macos-latest') && (matrix.debug_build != 1)
|
||||
run: |
|
||||
pip install "numpy<2.0" pillow
|
||||
pytest -s
|
||||
|
||||
- name: Run Python tests with numpy<2.0 (ubuntu, python<3.13)
|
||||
if: (matrix.python_version == '3.10') && startsWith(matrix.os,'ubuntu')
|
||||
run: |
|
||||
# 2024.10.15: Error message: The headers or library files could not be found for jpeg, a required dependency when compiling Pillow from source.
|
||||
sudo apt-get update
|
||||
sudo apt-get install libjpeg-dev zlib1g-dev libpng-dev
|
||||
pip install --prefer-binary "numpy<2.0" pillow
|
||||
pytest -s
|
||||
@@ -0,0 +1,55 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Generate and publish ONNX docs
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: ["main"]
|
||||
# Runs on pushes targeting the default branch
|
||||
push:
|
||||
branches: ["main"]
|
||||
# Allows you to run this workflow manually from the Actions tab
|
||||
workflow_dispatch:
|
||||
|
||||
# Sets permissions of the GITHUB_TOKEN to allow deployment to GitHub Pages
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Set up pixi
|
||||
uses: prefix-dev/setup-pixi@5185adfbffb4bd703da3010310260805d89ebb11 # v0.9.6
|
||||
with:
|
||||
environments: docs
|
||||
- name: Install repository
|
||||
run: pixi run -e docs install
|
||||
- name: Build Docs
|
||||
run: pixi run -e docs docs-build
|
||||
- name: Upload artifact
|
||||
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
|
||||
with:
|
||||
path: 'docs/docsgen/build/html'
|
||||
deploy:
|
||||
needs: 'build'
|
||||
if: github.event_name != 'pull_request'
|
||||
permissions:
|
||||
pages: write
|
||||
id-token: write
|
||||
environment:
|
||||
name: github-pages
|
||||
url: ${{ steps.deployment.outputs.page_url }}
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Setup Pages
|
||||
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
|
||||
- name: Deploy to GitHub Pages
|
||||
id: deployment
|
||||
uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0
|
||||
@@ -0,0 +1,124 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Pixi CI
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
pre-commit-hooks:
|
||||
name: Install and lint (${{ matrix.os }})
|
||||
runs-on: ${{ matrix.os }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os:
|
||||
- ubuntu-24.04-arm
|
||||
- windows-2022
|
||||
steps:
|
||||
- name: Checkout branch
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Set up pixi
|
||||
uses: prefix-dev/setup-pixi@5185adfbffb4bd703da3010310260805d89ebb11 # v0.9.6
|
||||
with:
|
||||
environments: default reuse
|
||||
- name: Install repository
|
||||
run: pixi run install
|
||||
- name: Lint
|
||||
run: pixi run lint --show-diff-on-failure
|
||||
|
||||
xcode-build:
|
||||
# Guards against regressions in CMake's Xcode generator (issue #8053), which
|
||||
# downstream consumers such as onnxruntime use for their iOS/macOS framework
|
||||
# builds. The other jobs build with Ninja and so do not exercise the
|
||||
# Xcode-specific code paths.
|
||||
name: Xcode generator build
|
||||
runs-on: macos-latest
|
||||
steps:
|
||||
- name: Checkout branch
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Set up pixi
|
||||
uses: prefix-dev/setup-pixi@5185adfbffb4bd703da3010310260805d89ebb11 # v0.9.6
|
||||
with:
|
||||
environments: default
|
||||
- name: Build with the Xcode generator
|
||||
run: |
|
||||
pixi run cmake -G Xcode -B .xcode-cmake-build -S . -DONNX_BUILD_PYTHON=ON -DONNX_USE_PROTOBUF_SHARED_LIBS=ON
|
||||
pixi run cmake --build .xcode-cmake-build
|
||||
|
||||
install-and-test:
|
||||
name: Install and test (${{ matrix.os }}, ${{ matrix.environment }})
|
||||
runs-on: ${{ matrix.os }}
|
||||
permissions:
|
||||
contents: read
|
||||
issues: write # Needed to create an issue on failure
|
||||
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os:
|
||||
- ubuntu-24.04-arm
|
||||
- ubuntu-latest
|
||||
- macos-latest
|
||||
- windows-2022
|
||||
environment:
|
||||
- default
|
||||
- oldies
|
||||
steps:
|
||||
- name: Checkout branch
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Set up pixi
|
||||
uses: prefix-dev/setup-pixi@5185adfbffb4bd703da3010310260805d89ebb11 # v0.9.6
|
||||
with:
|
||||
environments: ${{ matrix.environment }}
|
||||
- name: Install repository
|
||||
run: pixi run -e ${{ matrix.environment }} install
|
||||
- name: pip check installation
|
||||
run: pixi run -e ${{ matrix.environment }} pip check
|
||||
- name: gtests
|
||||
run: pixi run -e ${{ matrix.environment }} gtest
|
||||
- name: pytest
|
||||
run: pixi run -e ${{ matrix.environment }} pytest
|
||||
- name: Issue on failure
|
||||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
||||
if: ${{ failure() && github.ref == 'refs/heads/main' }}
|
||||
with:
|
||||
script: |
|
||||
github.rest.issues.listForRepo({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
state: "open",
|
||||
labels: "[bot] pixi CI"
|
||||
}).then((issues) => {
|
||||
if (issues.data.length === 0){
|
||||
github.rest.issues.create({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
title: "Scheduled pixi CI failed",
|
||||
body: "The scheduled pixi-based CI failed. See https://github.com/${{ github.repository }}/actions/runs/${{github.run_id}} for details.",
|
||||
assignees: ["cbourjau"],
|
||||
labels: ["[bot] pixi CI"]
|
||||
})
|
||||
}
|
||||
});
|
||||
@@ -0,0 +1,43 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Test source dist of preview build at onnx-weekly
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '0 0 * * 2'
|
||||
workflow_call:
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
|
||||
test_sdist_preview:
|
||||
|
||||
strategy:
|
||||
matrix:
|
||||
os: [ubuntu-24.04, windows-latest]
|
||||
python-version: ['3.10', '3.12', '3.13']
|
||||
fail-fast: false
|
||||
runs-on: ${{ matrix.os }}
|
||||
|
||||
steps:
|
||||
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Python ${{ matrix.python-version }}
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: ${{ matrix.python-version }}
|
||||
|
||||
- name: Test preview build source distribution from PyPI
|
||||
run: |
|
||||
python -m pip install --no-binary onnx-weekly onnx-weekly
|
||||
python -m pip install pytest ml_dtypes pillow
|
||||
pytest
|
||||
@@ -0,0 +1,101 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Linux Release
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
build_mode:
|
||||
required: false
|
||||
type: string
|
||||
default: "preview"
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: linux-release-${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
build:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
build:
|
||||
- "cp310-manylinux_x86_64"
|
||||
- "cp310-manylinux_aarch64"
|
||||
- "cp311-manylinux_x86_64"
|
||||
- "cp311-manylinux_aarch64"
|
||||
- "cp312-manylinux_x86_64"
|
||||
- "cp312-manylinux_aarch64"
|
||||
- "cp314t-manylinux_x86_64"
|
||||
- "cp314t-manylinux_aarch64"
|
||||
|
||||
runs-on: ${{ contains(matrix.build, 'aarch64') && 'ubuntu-24.04-arm' || 'ubuntu-24.04' }}
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Read protobuf version from sbom.cdx.json
|
||||
run: echo "PROTOBUF_VERSION=$(jq -r '.components[] | select(.name=="protobuf") | .version' sbom.cdx.json)" >> $GITHUB_ENV
|
||||
|
||||
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: "3.12"
|
||||
|
||||
- name: Set preview version
|
||||
if: inputs.build_mode != 'release'
|
||||
shell: bash
|
||||
run: |
|
||||
sed -i'' 's/name = "onnx"/name = "onnx-weekly"/' pyproject.toml
|
||||
echo "$(cat VERSION_NUMBER).dev$(date -u +%Y%m%d)" > VERSION_NUMBER
|
||||
|
||||
- name: Download protoc
|
||||
run: |
|
||||
ARCH=${{ contains(matrix.build, 'aarch64') && 'aarch_64' || 'x86_64' }}
|
||||
curl -sSL "https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOBUF_VERSION}/protoc-${PROTOBUF_VERSION}-linux-${ARCH}.zip" -o protoc.zip
|
||||
unzip -q protoc.zip -d protoc-host
|
||||
chmod +x protoc-host/bin/protoc
|
||||
|
||||
- name: Download protobuf source
|
||||
run: |
|
||||
curl -sSL "https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOBUF_VERSION}/protobuf-${PROTOBUF_VERSION}.tar.gz" -o protobuf.tar.gz
|
||||
tar -xf protobuf.tar.gz
|
||||
|
||||
- name: Set SOURCE_DATE_EPOCH for reproducible builds
|
||||
run: echo "SOURCE_DATE_EPOCH=$(git log -1 --pretty=%ct)" >> $GITHUB_ENV
|
||||
|
||||
- name: Build wheels
|
||||
uses: pypa/cibuildwheel@294735312765b09d24a2fbec22660ce817587d55 # v4.1.0
|
||||
with:
|
||||
output-dir: dist/
|
||||
only: ${{ matrix.build }}
|
||||
env:
|
||||
CIBW_ENVIRONMENT: >-
|
||||
CMAKE_ARGS="
|
||||
-DFETCHCONTENT_SOURCE_DIR_PROTOBUF=/project/protobuf-${{ env.PROTOBUF_VERSION }}
|
||||
-DONNX_CUSTOM_PROTOC_EXECUTABLE=/project/protoc-host/bin/protoc
|
||||
-DONNX_HARDENING=ON
|
||||
-DONNX_USE_LITE_PROTO=ON
|
||||
-DONNX_WERROR=ON
|
||||
"
|
||||
|
||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: wheels-linux-${{ matrix.build }}
|
||||
path: dist/*.whl
|
||||
|
||||
- name: Validate wheel
|
||||
run: |
|
||||
python -m pip install -q abi3audit check-wheel-contents
|
||||
for whl in dist/*.whl; do
|
||||
echo "Checking $whl"
|
||||
check-wheel-contents "$whl"
|
||||
python -m abi3audit -v "$whl"
|
||||
done
|
||||
@@ -0,0 +1,97 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: macOS Release
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
build_mode:
|
||||
required: false
|
||||
type: string
|
||||
default: "preview"
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: macos-release-${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
build:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
build:
|
||||
- "cp310-macosx_universal2"
|
||||
- "cp311-macosx_universal2"
|
||||
- "cp312-macosx_universal2"
|
||||
- "cp314t-macosx_universal2"
|
||||
|
||||
runs-on: macos-14
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Read protobuf version from sbom.cdx.json
|
||||
run: echo "PROTOBUF_VERSION=$(jq -r '.components[] | select(.name=="protobuf") | .version' sbom.cdx.json)" >> $GITHUB_ENV
|
||||
|
||||
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: "3.12"
|
||||
|
||||
- name: Set preview version
|
||||
if: inputs.build_mode != 'release'
|
||||
shell: bash
|
||||
run: |
|
||||
sed -i '' 's/name = "onnx"/name = "onnx-weekly"/' pyproject.toml
|
||||
echo "$(cat VERSION_NUMBER).dev$(date -u +%Y%m%d)" > VERSION_NUMBER
|
||||
|
||||
- name: Download protoc
|
||||
run: |
|
||||
curl -sSL "https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOBUF_VERSION}/protoc-${PROTOBUF_VERSION}-osx-universal_binary.zip" -o protoc.zip
|
||||
unzip -q protoc.zip -d protoc-host
|
||||
chmod +x protoc-host/bin/protoc
|
||||
|
||||
- name: Download protobuf source
|
||||
run: |
|
||||
curl -sSL "https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOBUF_VERSION}/protobuf-${PROTOBUF_VERSION}.tar.gz" -o protobuf.tar.gz
|
||||
tar -xf protobuf.tar.gz
|
||||
|
||||
- name: Set SOURCE_DATE_EPOCH for reproducible builds
|
||||
run: echo "SOURCE_DATE_EPOCH=$(git log -1 --pretty=%ct)" >> $GITHUB_ENV
|
||||
|
||||
- name: Build wheels
|
||||
uses: pypa/cibuildwheel@294735312765b09d24a2fbec22660ce817587d55 # v4.1.0
|
||||
with:
|
||||
output-dir: dist/
|
||||
only: ${{ matrix.build }}
|
||||
env:
|
||||
CIBW_ENVIRONMENT: >-
|
||||
MACOSX_DEPLOYMENT_TARGET=12.0
|
||||
CMAKE_ARGS="
|
||||
-DFETCHCONTENT_SOURCE_DIR_PROTOBUF=${{ github.workspace }}/protobuf-${{ env.PROTOBUF_VERSION }}
|
||||
-DONNX_CUSTOM_PROTOC_EXECUTABLE=${{ github.workspace }}/protoc-host/bin/protoc
|
||||
-DONNX_HARDENING=ON
|
||||
-DONNX_USE_LITE_PROTO=ON
|
||||
-DONNX_WERROR=ON
|
||||
"
|
||||
|
||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: wheels-macos-${{ matrix.build }}
|
||||
path: dist/*.whl
|
||||
|
||||
- name: Validate wheel
|
||||
run: |
|
||||
python -m pip install -q abi3audit check-wheel-contents
|
||||
for whl in dist/*.whl; do
|
||||
echo "Checking $whl"
|
||||
check-wheel-contents "$whl"
|
||||
python -m abi3audit -v "$whl"
|
||||
done
|
||||
@@ -0,0 +1,83 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Pyodide Build
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
build_mode:
|
||||
required: false
|
||||
type: string
|
||||
default: "preview"
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: pyodide-release-${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-24.04
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Read protobuf version from sbom.cdx.json
|
||||
run: echo "PROTOBUF_VERSION=$(jq -r '.components[] | select(.name=="protobuf") | .version' sbom.cdx.json)" >> $GITHUB_ENV
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: "3.12"
|
||||
|
||||
- name: Set preview version
|
||||
if: inputs.build_mode != 'release'
|
||||
shell: bash
|
||||
run: |
|
||||
sed -i'' 's/name = "onnx"/name = "onnx-weekly"/' pyproject.toml
|
||||
echo "$(cat VERSION_NUMBER).dev$(date -u +%Y%m%d)" > VERSION_NUMBER
|
||||
|
||||
- name: Download protoc for host
|
||||
run: |
|
||||
curl -sSL "https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOBUF_VERSION}/protoc-${PROTOBUF_VERSION}-linux-x86_64.zip" -o protoc.zip
|
||||
unzip -q protoc.zip -d protoc-host
|
||||
chmod +x protoc-host/bin/protoc
|
||||
|
||||
- name: Download protobuf source
|
||||
run: |
|
||||
curl -sSL "https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOBUF_VERSION}/protobuf-${PROTOBUF_VERSION}.tar.gz" -o protobuf.tar.gz
|
||||
tar -xf protobuf.tar.gz
|
||||
|
||||
- name: Set SOURCE_DATE_EPOCH for reproducible builds
|
||||
run: echo "SOURCE_DATE_EPOCH=$(git log -1 --pretty=%ct)" >> $GITHUB_ENV
|
||||
|
||||
- name: Build wheels
|
||||
uses: pypa/cibuildwheel@294735312765b09d24a2fbec22660ce817587d55 # v4.1.0
|
||||
with:
|
||||
output-dir: dist/
|
||||
env:
|
||||
CIBW_PLATFORM: pyodide
|
||||
CIBW_TEST_COMMAND: >-
|
||||
python -c "from onnx import NodeProto; n = NodeProto(); n.op_type = 'Add'; print(n)"
|
||||
CIBW_ENVIRONMENT: >-
|
||||
CMAKE_ARGS="
|
||||
-DFETCHCONTENT_SOURCE_DIR_PROTOBUF=${{ github.workspace }}/protobuf-${{ env.PROTOBUF_VERSION }}
|
||||
-DONNX_CUSTOM_PROTOC_EXECUTABLE=${{ github.workspace }}/protoc-host/bin/protoc
|
||||
-DONNX_HARDENING=ON
|
||||
-DONNX_PYODIDE_BUILD=ON
|
||||
-DONNX_USE_LITE_PROTO=ON
|
||||
-DONNX_WERROR=ON
|
||||
-DCMAKE_CXX_FLAGS='-Wno-error=deprecated-builtins'
|
||||
"
|
||||
|
||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: wheels-pyodide
|
||||
path: dist/*.whl
|
||||
@@ -0,0 +1,66 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: sdistRelease
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
os:
|
||||
required: true
|
||||
type: string
|
||||
build_mode:
|
||||
required: true
|
||||
type: string
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: sdist-release-${{ github.workflow }}-${{ github.ref }}
|
||||
|
||||
jobs:
|
||||
build:
|
||||
if: github.event_name != 'pull_request' || startsWith( github.base_ref, 'rel-') || contains( github.event.pull_request.labels.*.name, 'run release CIs')
|
||||
runs-on: ubuntu-24.04
|
||||
strategy:
|
||||
matrix:
|
||||
python-version: ['3.10']
|
||||
target-architecture: ['arm64']
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Python ${{ matrix.python-version }}
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: ${{ matrix.python-version }}
|
||||
|
||||
- name: Install Python dependencies
|
||||
run: |
|
||||
python -m pip install -q --upgrade pip
|
||||
python -m pip install -q build scikit-build-core
|
||||
|
||||
- name: Build source distribution (preview build / weekly)
|
||||
if: ${{ inputs.build_mode != 'release' }}
|
||||
run: |
|
||||
git clean -xdf
|
||||
sed -i 's/name = "onnx"/name = "onnx-weekly"/' 'pyproject.toml'
|
||||
echo "$(cat VERSION_NUMBER).dev$(date -u +%Y%m%d)" > VERSION_NUMBER
|
||||
python -m build --sdist
|
||||
|
||||
- name: Build source distribution (for release)
|
||||
if: ${{ inputs.build_mode == 'release' }}
|
||||
run: |
|
||||
git clean -xdf
|
||||
python -m build --sdist
|
||||
|
||||
- name: Upload sdist
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
|
||||
with:
|
||||
name: sdist
|
||||
path: |
|
||||
./dist/*.tar.gz
|
||||
@@ -0,0 +1,108 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Windows Release
|
||||
|
||||
on:
|
||||
workflow_call:
|
||||
inputs:
|
||||
build_mode:
|
||||
required: false
|
||||
type: string
|
||||
default: "preview"
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: windows-release-${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
build:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
build:
|
||||
- "cp310-win_amd64"
|
||||
- "cp310-win32"
|
||||
- "cp311-win_amd64"
|
||||
- "cp311-win32"
|
||||
- "cp311-win_arm64"
|
||||
- "cp312-win_amd64"
|
||||
- "cp312-win32"
|
||||
- "cp312-win_arm64"
|
||||
- "cp314t-win_amd64"
|
||||
- "cp314t-win_arm64"
|
||||
runs-on: ${{ contains(matrix.build, 'arm64') && 'windows-11-arm' || 'windows-2022' }}
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Read protobuf version from sbom.cdx.json
|
||||
shell: bash
|
||||
run: echo "PROTOBUF_VERSION=$(jq -r '.components[] | select(.name=="protobuf") | .version' sbom.cdx.json)" >> $GITHUB_ENV
|
||||
|
||||
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: "3.12"
|
||||
|
||||
- name: Set preview version
|
||||
if: inputs.build_mode != 'release'
|
||||
shell: bash
|
||||
run: |
|
||||
sed -i'' 's/name = "onnx"/name = "onnx-weekly"/' pyproject.toml
|
||||
echo "$(cat VERSION_NUMBER).dev$(date -u +%Y%m%d)" > VERSION_NUMBER
|
||||
|
||||
- name: Download protoc
|
||||
run: |
|
||||
curl -sSL "https://github.com/protocolbuffers/protobuf/releases/download/v${env:PROTOBUF_VERSION}/protoc-${env:PROTOBUF_VERSION}-win64.zip" -o protoc.zip
|
||||
Expand-Archive protoc.zip -DestinationPath protoc-host
|
||||
|
||||
- name: Download protobuf source
|
||||
run: |
|
||||
curl -sSL "https://github.com/protocolbuffers/protobuf/releases/download/v${env:PROTOBUF_VERSION}/protobuf-${env:PROTOBUF_VERSION}.tar.gz" -o protobuf.tar.gz
|
||||
tar -xf protobuf.tar.gz
|
||||
|
||||
- name: Set paths
|
||||
shell: bash
|
||||
run: |
|
||||
echo "PROTOC_PATH=$(cygpath -m "${{ github.workspace }}/protoc-host/bin/protoc.exe")" >> $GITHUB_ENV
|
||||
echo "PROTOBUF_SRC=$(cygpath -m "${{ github.workspace }}/protobuf-${PROTOBUF_VERSION}")" >> $GITHUB_ENV
|
||||
|
||||
- name: Set SOURCE_DATE_EPOCH for reproducible builds
|
||||
shell: bash
|
||||
run: echo "SOURCE_DATE_EPOCH=$(git log -1 --pretty=%ct)" >> $GITHUB_ENV
|
||||
|
||||
- name: Build wheels
|
||||
uses: pypa/cibuildwheel@294735312765b09d24a2fbec22660ce817587d55 # v4.1.0
|
||||
with:
|
||||
output-dir: dist/
|
||||
only: ${{ matrix.build }}
|
||||
env:
|
||||
CIBW_ENVIRONMENT: >-
|
||||
CMAKE_ARGS="
|
||||
-DFETCHCONTENT_SOURCE_DIR_PROTOBUF=${{ env.PROTOBUF_SRC }}
|
||||
-DONNX_CUSTOM_PROTOC_EXECUTABLE=${{ env.PROTOC_PATH }}
|
||||
-DONNX_HARDENING=ON
|
||||
-DONNX_USE_LITE_PROTO=ON
|
||||
-DONNX_WERROR=ON
|
||||
"
|
||||
|
||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: wheels-windows-${{ matrix.build }}
|
||||
path: dist/*.whl
|
||||
|
||||
- name: Validate wheel
|
||||
run: |
|
||||
python -m pip install -q abi3audit check-wheel-contents
|
||||
Get-ChildItem -Path dist/*.whl | ForEach-Object {
|
||||
echo "Checking $($_.Name)"
|
||||
check-wheel-contents $_.FullName
|
||||
python -m abi3audit -v $_.FullName
|
||||
}
|
||||
@@ -0,0 +1,48 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Scorecard supply-chain security
|
||||
on:
|
||||
branch_protection_rule:
|
||||
schedule:
|
||||
- cron: '24 10 * * 6'
|
||||
push:
|
||||
branches: [ "main" ]
|
||||
|
||||
permissions: read-all
|
||||
|
||||
jobs:
|
||||
analysis:
|
||||
name: Scorecard analysis
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
# Needed to upload the results to code-scanning dashboard.
|
||||
security-events: write
|
||||
# Needed to publish results and get a badge (see publish_results below).
|
||||
id-token: write
|
||||
steps:
|
||||
- name: "Checkout code"
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: "Run analysis"
|
||||
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a
|
||||
with:
|
||||
results_file: results.sarif
|
||||
results_format: sarif
|
||||
publish_results: true
|
||||
|
||||
- name: "Upload artifact"
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
|
||||
with:
|
||||
name: SARIF file
|
||||
path: results.sarif
|
||||
retention-days: 5
|
||||
|
||||
# Upload the results to GitHub's code scanning dashboard.
|
||||
- name: "Upload to code-scanning"
|
||||
uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e
|
||||
with:
|
||||
sarif_file: results.sarif
|
||||
@@ -0,0 +1,38 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
# This workflow warns and then closes issues and PRs that have had no activity for a specified amount of time.
|
||||
#
|
||||
# You can adjust the behavior by modifying this file.
|
||||
# For more information, see:
|
||||
# https://github.com/actions/stale
|
||||
name: Mark stale issues and pull requests
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '39 6 * * *'
|
||||
|
||||
permissions: # set top-level default permissions as security best practice
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
stale:
|
||||
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
issues: write
|
||||
pull-requests: write
|
||||
|
||||
steps:
|
||||
- uses: actions/stale@eb5cf3af3ac0a1aa4c9c45633dd1ae542a27a899 # v10.3.0
|
||||
with:
|
||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
||||
days-before-stale: 365
|
||||
days-before-close: 21
|
||||
ascending: true
|
||||
exempt-issue-labels: bug,no-stale
|
||||
exempt-pr-labels: no-stale,contributions welcome
|
||||
remove-issue-stale-when-updated: true
|
||||
remove-pr-stale-when-updated: true
|
||||
exempt-all-milestones: true
|
||||
@@ -0,0 +1,81 @@
|
||||
# Copyright (c) ONNX Project Contributors
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
name: Windows_No_Exception_CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ main, rel-* ]
|
||||
pull_request:
|
||||
branches: [ main, rel-* ]
|
||||
|
||||
permissions: # set top-level default permissions as security best practice
|
||||
contents: read
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event_name == 'workflow_dispatch' }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: windows-2022
|
||||
strategy:
|
||||
matrix:
|
||||
python-version: ['3.10']
|
||||
architecture: ['x64']
|
||||
steps:
|
||||
- name: Checkout ONNX
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
path: ./onnx
|
||||
submodules: 'recursive'
|
||||
persist-credentials: false
|
||||
|
||||
- name: Set up Python ${{ matrix.python-version }}
|
||||
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: ${{ matrix.python-version }}
|
||||
architecture: ${{ matrix.architecture }}
|
||||
cache: 'pip'
|
||||
|
||||
- name: Add msbuild to PATH
|
||||
uses: microsoft/setup-msbuild@30375c66a4eea26614e0d39710365f22f8b0af57 # v3.0.0
|
||||
with:
|
||||
msbuild-architecture: ${{ matrix.architecture }}
|
||||
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
python -m pip install --upgrade pip
|
||||
python -m pip install cmake
|
||||
|
||||
- name: Build and test ONNX binaries
|
||||
run: |
|
||||
. .\onnx\workflow_scripts\protobuf\build_protobuf_win.ps1 -cmake_arch ${{ matrix.architecture }}
|
||||
|
||||
cd onnx
|
||||
echo "Build ONNX"
|
||||
cmake -G "Visual Studio 17 2022" -A ${{ matrix.architecture }} -DONNX_USE_PROTOBUF_SHARED_LIBS=OFF -DONNX_USE_LITE_PROTO=ON -DONNX_WERROR=ON -DONNX_DISABLE_EXCEPTIONS=ON -DCMAKE_BUILD_TYPE=Release -DONNX_USE_MSVC_STATIC_RUNTIME=OFF -DONNX_ML=1 -DONNX_BUILD_TESTS=ON -S . -B .setuptools-cmake-build\
|
||||
cd .setuptools-cmake-build\
|
||||
cmake --build . --config Release
|
||||
|
||||
echo "Run gtests"
|
||||
Release\onnx_gtests.exe
|
||||
if($lastexitcode -ne 0) {
|
||||
EXIT 1
|
||||
}
|
||||
|
||||
cd ..
|
||||
git clean -xdf
|
||||
set ONNX_BUILD_TESTS=1
|
||||
echo "Build ONNX with non-static registration for testing selective ONNX schema loading"
|
||||
cmake -G "Visual Studio 17 2022" -A ${{ matrix.architecture }} -DONNX_USE_PROTOBUF_SHARED_LIBS=OFF -DONNX_USE_LITE_PROTO=ON -DONNX_WERROR=ON -DCMAKE_BUILD_TYPE=Release -DONNX_USE_MSVC_STATIC_RUNTIME=OFF -DONNX_ML=1 -DONNX_BUILD_TESTS=ON -DONNX_DISABLE_STATIC_REGISTRATION=ON -S . -B .setuptools-cmake-build\
|
||||
|
||||
cd .setuptools-cmake-build\
|
||||
cmake --build . --config Release
|
||||
|
||||
echo "Only test selective ONNX schema loading"
|
||||
Release\onnx_gtests.exe --gtest_filter="SchemaRegistrationTest*"
|
||||
if($lastexitcode -ne 0) {
|
||||
EXIT 1
|
||||
}
|
||||
Reference in New Issue
Block a user