Skip to content

docs(benchmarks): round 7 plan — train and requantise with Unsloth, serve with Ollama, score on a fresh three-slot pin #3955

docs(benchmarks): round 7 plan — train and requantise with Unsloth, serve with Ollama, score on a fresh three-slot pin

docs(benchmarks): round 7 plan — train and requantise with Unsloth, serve with Ollama, score on a fresh three-slot pin #3955

Workflow file for this run

name: CodeQL
on:
push:
branches: [main]
pull_request:
schedule:
- cron: "23 3 * * 3"
permissions:
contents: read
security-events: write
# The ci-target router dispatches the ci-heartbeat canary with
# GITHUB_TOKEN, and a called reusable workflow can never exceed the
# caller's envelope -- under-granting it startup-fails the whole run
# as "Invalid workflow file" (quality.yml's inline router instead
# elevates at its own job level).
actions: write
jobs:
# Executor routing ("homeserver first, GitHub-hosted fallback") via the
# shared ci-router.yml -- same trust gate and heartbeat liveness proof
# quality.yml's ci-target job documents: push-to-main and the weekly
# schedule are trusted; pull_request only when the repo
# variable CI_HOMESERVER_PRS opts same-repo PRs in; fork PRs never reach
# the box. CodeQL needs no docker/sudo (the action manages its own
# toolchain under the runner's persistent _work/_tool cache), so the
# single analyze job is executor-agnostic and just picks runs-on off the
# router output -- the matrix rows serialize behind the single
# registered runner instance, which the 90-min per-job ceiling only
# bounds on a wedged pickup (GitHub-hosted keeps the platform default).
ci-target:
name: Pick CI executor
uses: ./.github/workflows/ci-router.yml
with:
ci_homeserver_prs: ${{ vars.CI_HOMESERVER_PRS || '' }}
analyze:
name: Analyze ${{ matrix.language }}${{ needs.ci-target.outputs.homeserver != 'true' && ' (GitHub-hosted)' || '' }}
needs: [ci-target]
runs-on: ${{ needs.ci-target.outputs.homeserver == 'true' && fromJSON('["self-hosted", "linux", "x64", "honeypot-ci"]') || fromJSON('["ubuntu-latest"]') }}
timeout-minutes: ${{ needs.ci-target.outputs.homeserver == 'true' && 90 || 360 }}
strategy:
fail-fast: false
matrix:
language: [go, javascript-typescript, python]
steps:
- uses: actions/checkout@v7
- if: matrix.language == 'go'
uses: actions/setup-go@v7
with:
# CodeQL's Go autobuild shell-outs to `go` to enumerate build
# targets; neither the homeserver runner nor the GitHub-hosted
# fallback has a Go toolchain on $PATH by default, so install
# it on every path. Pinned minor to keep the lockfile
# reproducible.
go-version: '1.23'
# Cache only on the GitHub-hosted path -- mirror of this job's
# own runs-on expression. The homeserver runners keep GOMODCACHE
# on disk at /opt/github-ci-runner and Go writes its module dirs
# mode 0555, so setup-go's restore `tar -x` cannot recreate an
# already-present file: the whole archive downloads, fails to
# unpack, and gets re-uploaded from the post step. Same
# reasoning as the quality.yml Go jobs.
cache: ${{ needs.ci-target.outputs.homeserver != 'true' }}
- uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
config-file: .github/codeql/codeql-config.yml
- uses: github/codeql-action/analyze@v4
with:
category: /language:${{ matrix.language }}