Repository navigation
config(kimik3): refresh MI355X vLLM image to the 2026-09-24 ROCm 10.0 nightly / 将 Kimi-K3 MI355X vLLM 镜像刷新至 2026-09-24 的 ROCm 10.0 nightly #10672
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CODEOWNER Sign-off Verify | |
| on: | |
| issue_comment: | |
| types: [created, edited] | |
| pull_request_review: | |
| types: [submitted, edited] | |
| pull_request_review_comment: | |
| types: [created, edited] | |
| workflow_dispatch: | |
| inputs: | |
| pr-number: | |
| description: PR number | |
| required: true | |
| type: number | |
| comment_url: | |
| description: >- | |
| URL of the sign-off comment/review to verify, e.g. | |
| https://github.com/OWNER/REPO/pull/123#issuecomment-456 (also accepts | |
| #pullrequestreview-<id> and #discussion_r<id> review URLs). | |
| required: true | |
| type: string | |
| permissions: | |
| contents: read | |
| jobs: | |
| verify: | |
| name: Check sign-off | |
| if: | | |
| github.event_name == 'workflow_dispatch' || | |
| (github.event_name == 'issue_comment' && github.event.issue.pull_request && | |
| contains(github.event.comment.body || '', 'As a PR reviewer and CODEOWNER')) || | |
| (github.event_name == 'pull_request_review' && | |
| contains(github.event.review.body || '', 'As a PR reviewer and CODEOWNER')) || | |
| (github.event_name == 'pull_request_review_comment' && | |
| contains(github.event.comment.body || '', 'As a PR reviewer and CODEOWNER')) | |
| runs-on: ubuntu-latest | |
| concurrency: | |
| group: codeowner-signoff-pr-${{ github.event.pull_request.number || github.event.issue.number || inputs.pr-number }} | |
| cancel-in-progress: false | |
| permissions: | |
| contents: read | |
| pull-requests: write # Publish PR feedback. | |
| issues: write # Post a new verdict comment. | |
| actions: read # Read workflow runs and artifacts. | |
| steps: | |
| - name: Checkout trusted workflow code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| ref: ${{ github.event.repository.default_branch }} | |
| persist-credentials: false | |
| - name: Set up uv | |
| uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 | |
| - name: Check changed-file ownership | |
| id: scope | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: uv run --locked --extra workflows python -m infx.workflows.signoff_scope | |
| - name: Resolve PR state and sign-off metadata | |
| id: resolve | |
| if: steps.scope.outputs.required == 'true' | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| SCOPED_HEAD_SHA: ${{ steps.scope.outputs.head-sha }} | |
| run: uv run --locked --extra workflows python -m infx.workflows.signoff_resolve | |
| - name: Render verifier prompt | |
| if: steps.resolve.outputs.proceed == 'true' | |
| env: | |
| REPO: ${{ github.repository }} | |
| PR_NUMBER: ${{ steps.scope.outputs.pr-number }} | |
| HEAD_SHA: ${{ steps.scope.outputs.head-sha }} | |
| SIGNOFF_AUTHOR: ${{ steps.resolve.outputs.signoff-author }} | |
| SIGNOFF_KIND: ${{ steps.resolve.outputs.signoff-kind }} | |
| SIGNOFF_FETCH_CMD: ${{ steps.resolve.outputs.signoff-fetch-cmd }} | |
| run: | | |
| # These placeholders must remain literal for envsubst. | |
| # shellcheck disable=SC2016 | |
| envsubst '${REPO} ${PR_NUMBER} ${HEAD_SHA} ${SIGNOFF_AUTHOR} ${SIGNOFF_KIND} ${SIGNOFF_FETCH_CMD}' \ | |
| < .github/codeowner-signoff-verify-prompt.md \ | |
| > /tmp/codeowner-signoff-verify-prompt.md | |
| grep -q "PR #${PR_NUMBER}" /tmp/codeowner-signoff-verify-prompt.md | |
| wc -c /tmp/codeowner-signoff-verify-prompt.md | |
| - name: Install Claude Code 2.1.282 | |
| id: claude_cli | |
| if: steps.resolve.outputs.proceed == 'true' | |
| run: | # zizmor: ignore[adhoc-packages] Claude CLI and its native packages are pinned to 2.1.282 | |
| npm install --prefix "$RUNNER_TEMP/claude-code" --no-audit --no-fund @anthropic-ai/claude-code@2.1.282 | |
| claude_cli="$RUNNER_TEMP/claude-code/node_modules/.bin/claude" | |
| test "$("$claude_cli" --version)" = "2.1.282 (Claude Code)" | |
| echo "path=$claude_cli" >> "$GITHUB_OUTPUT" | |
| - name: Verify sign-off with Claude | |
| id: claude | |
| if: steps.resolve.outputs.proceed == 'true' | |
| uses: anthropics/claude-code-action@9171db3e57d6a3140a37ddc2ba92788584e0ead6 # v1.0.234 | |
| env: | |
| # Repository verifier credential; trusted code checks writer authorization before this step. | |
| GH_TOKEN: ${{ secrets.AGENT_PAT }} # zizmor: ignore[secrets-outside-env] | |
| # Repository verifier credential; trusted code checks writer authorization before this step. | |
| GITHUB_TOKEN: ${{ secrets.AGENT_PAT }} # zizmor: ignore[secrets-outside-env] | |
| INFERENCEMAX_ROOT: ${{ github.workspace }} | |
| BASH_DEFAULT_TIMEOUT_MS: "1800000" | |
| BASH_MAX_TIMEOUT_MS: "3600000" | |
| with: | |
| # Repository verifier credential; trusted code checks writer authorization before this step. | |
| anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }} # zizmor: ignore[secrets-outside-env] | |
| # Repository verifier credential; trusted code checks writer authorization before this step. | |
| github_token: ${{ secrets.AGENT_PAT }} # zizmor: ignore[secrets-outside-env] | |
| path_to_claude_code_executable: ${{ steps.claude_cli.outputs.path }} | |
| track_progress: false | |
| allowed_bots: '' | |
| additional_permissions: | | |
| actions: read | |
| settings: | | |
| {"fastMode": true} | |
| claude_args: | | |
| --model 'claude-opus-5-5' | |
| --mcp-config .github/mcp-ci.json '{"mcpServers": {"fetch": {"command": "npx", "args": ["-y", "@anthropic-ai/mcp-server-fetch@latest"]}}}' | |
| --allowedTools "Read,Write,Glob,Grep,WebFetch,mcp__github__*,mcp__github_ci__*,mcp__fetch__*,mcp__inferencemax-repos__*,Bash" | |
| prompt: | | |
| Read the file /tmp/codeowner-signoff-verify-prompt.md and follow the | |
| instructions in it exactly — it is your complete task specification, | |
| already rendered with this run's PR number, head SHA, and sign-off | |
| metadata. | |
| - name: Post verdict comment | |
| if: always() && steps.resolve.outputs.proceed == 'true' | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| HEAD_SHA: ${{ steps.scope.outputs.head-sha }} | |
| PR_NUMBER: ${{ steps.scope.outputs.pr-number }} | |
| SIGNOFF_KEY: ${{ steps.resolve.outputs.signoff-key }} | |
| VERIFICATION_SUCCEEDED: ${{ steps.claude.outcome == 'success' }} | |
| VERDICT_PATH: /tmp/codeowner-signoff-verdict.md | |
| run: uv run --locked --extra workflows python -m infx.workflows.signoff_publish |