docs(benchmarks): round 7 plan — train and requantise with Unsloth, serve with Ollama, score on a fresh three-slot pin #3955
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CodeQL | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| schedule: | |
| - cron: "23 3 * * 3" | |
| permissions: | |
| contents: read | |
| security-events: write | |
| # The ci-target router dispatches the ci-heartbeat canary with | |
| # GITHUB_TOKEN, and a called reusable workflow can never exceed the | |
| # caller's envelope -- under-granting it startup-fails the whole run | |
| # as "Invalid workflow file" (quality.yml's inline router instead | |
| # elevates at its own job level). | |
| actions: write | |
| jobs: | |
| # Executor routing ("homeserver first, GitHub-hosted fallback") via the | |
| # shared ci-router.yml -- same trust gate and heartbeat liveness proof | |
| # quality.yml's ci-target job documents: push-to-main and the weekly | |
| # schedule are trusted; pull_request only when the repo | |
| # variable CI_HOMESERVER_PRS opts same-repo PRs in; fork PRs never reach | |
| # the box. CodeQL needs no docker/sudo (the action manages its own | |
| # toolchain under the runner's persistent _work/_tool cache), so the | |
| # single analyze job is executor-agnostic and just picks runs-on off the | |
| # router output -- the matrix rows serialize behind the single | |
| # registered runner instance, which the 90-min per-job ceiling only | |
| # bounds on a wedged pickup (GitHub-hosted keeps the platform default). | |
| ci-target: | |
| name: Pick CI executor | |
| uses: ./.github/workflows/ci-router.yml | |
| with: | |
| ci_homeserver_prs: ${{ vars.CI_HOMESERVER_PRS || '' }} | |
| analyze: | |
| name: Analyze ${{ matrix.language }}${{ needs.ci-target.outputs.homeserver != 'true' && ' (GitHub-hosted)' || '' }} | |
| needs: [ci-target] | |
| runs-on: ${{ needs.ci-target.outputs.homeserver == 'true' && fromJSON('["self-hosted", "linux", "x64", "honeypot-ci"]') || fromJSON('["ubuntu-latest"]') }} | |
| timeout-minutes: ${{ needs.ci-target.outputs.homeserver == 'true' && 90 || 360 }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| language: [go, javascript-typescript, python] | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - if: matrix.language == 'go' | |
| uses: actions/setup-go@v7 | |
| with: | |
| # CodeQL's Go autobuild shell-outs to `go` to enumerate build | |
| # targets; neither the homeserver runner nor the GitHub-hosted | |
| # fallback has a Go toolchain on $PATH by default, so install | |
| # it on every path. Pinned minor to keep the lockfile | |
| # reproducible. | |
| go-version: '1.23' | |
| # Cache only on the GitHub-hosted path -- mirror of this job's | |
| # own runs-on expression. The homeserver runners keep GOMODCACHE | |
| # on disk at /opt/github-ci-runner and Go writes its module dirs | |
| # mode 0555, so setup-go's restore `tar -x` cannot recreate an | |
| # already-present file: the whole archive downloads, fails to | |
| # unpack, and gets re-uploaded from the post step. Same | |
| # reasoning as the quality.yml Go jobs. | |
| cache: ${{ needs.ci-target.outputs.homeserver != 'true' }} | |
| - uses: github/codeql-action/init@v4 | |
| with: | |
| languages: ${{ matrix.language }} | |
| config-file: .github/codeql/codeql-config.yml | |
| - uses: github/codeql-action/analyze@v4 | |
| with: | |
| category: /language:${{ matrix.language }} |