Skip to content

ci: add isolated exact-pin dependency contract check - #372

Merged
Pigbibi merged 1 commit into
mainfrom
codex/binance-exact-pin-ci
Oct 11, 2026
Merged

Pigbibi merged 1 commit into
mainfrom
codex/binance-exact-pin-ci

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Oct 11, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Add a separate GitHub-hosted exact-pin job that only performs a frozen install. Keep candidate integration and same-branch editable overrides unchanged.
  • Verify real installed QPK/CryptoStrategies PEP 610 Git provenance against pyproject.toml and uv.lock, and reject source-shadowed imports.
  • Reuse existing real catalog/runtime member-risk gate tests with sibling source paths disabled in exact-pin mode; document the boundary.

Scope

CI, tests and documentation only. No dependency pin, trading logic, risk rule, production trigger, deployment, approval, or credential changes. Uses synthetic data only. Independent of #371: observation reporting is not included, and this does not claim legacy 20% full-cost loss enforcement under member-risk APPROVE.

Verification

  • Frozen install succeeded, exact-pin/runtime subset: 16 passed, 6 subtests.
  • Full pytest: 1506 passed, 1 deliberate opt-in skip, 208 subtests.
  • unittest discovery: 488 tests, OK (1 skip).
  • ruff, py_compile, git diff --check and uv lock --check passed.
  • Real-install negative probes rejected wrong/missing/editable provenance and sibling source shadowing; restored provenance passed again.
  • Independent read-only review found no blockers.
  • Remote CI will be checked on this PR's final head before reporting completion.

@Pigbibi
Pigbibi marked this pull request as ready for review October 11, 2026 14:20
@Pigbibi
Pigbibi merged commit ef2324d into main Oct 11, 2026
2 checks passed
@Pigbibi
Pigbibi deleted the codex/binance-exact-pin-ci branch October 11, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant