Repository navigation
CI and Release Process
| Workflow | File | Triggers |
|---|---|---|
| Build & Test | build.yml |
Push to main / fix/v3.23-custom, any PR, manual |
| Dash/POSIX Compatibility | dash-compat.yml |
Push to main / fix/v3.23-custom, PR, manual |
| Release Binaries | release.yml |
Push a v* tag, manual |
| Pre-Release Shakedown | shakedown.yml |
Push a v3.23.0-fix.* tag, manual |
| Shakedown Droplet Sweeper | shakedown-sweeper.yml |
Every 15 minutes (schedule), manual |
| CodeQL Security Scan | codeql.yml |
Sunday 22:00 UTC weekly, manual |
| Upstream Monitor | upstream_monitor.yml |
Midnight + noon UTC daily, manual |
Two jobs run in parallel:
- Checks out code with full git history and tags
- Sets up Go 1.26 with module cache
- Runs shell installer tests (
scripts/test_provider_install.sh) - Runs shell fallback logic tests (
scripts/test_fallback_logic.sh) - Runs Go unit tests across the root and
provider/packages - Runs
go veton root andprovider/ - Runs
govulncheck(non-blocking โ reports CVEs but doesn't fail the build)
- Sets up QEMU + Docker Buildx for multi-arch
- Logs into GHCR and Docker Hub
- Extracts version from tag or most recent git tag
- Builds and pushes
linux/amd64+linux/arm64Docker image- On PRs: build only, no push
-
On push to
mainor tag: build + push
Wall-clock time is dominated by the Docker build (~4-8 min with QEMU). The test job runs alongside it and completes first.
Guards the Linux installer (scripts/Provider_Install_Linux.sh, aka urnet-tools): it is
intended to run under dash via #!/bin/sh. This workflow rejects bashisms in the
installer and any published instruction that pipes the installer to bash instead of sh.
Triggered automatically when a v* tag is pushed. Also runnable manually from the Actions tab.
What it does:
- Builds native
providerbinaries via a matrix overgoos: [linux, darwin, windows]รgoarch: [amd64, arm64] - Assembles binaries into
urnetwork-provider-<version>.tar.gz - Checks for a matching release notes file at
releases/<version>.md- If found: uses it as the GitHub Release body
- If not found: auto-generates release notes from git log
- Creates a GitHub Release with the tarball attached
- Tags containing
-rc,-alpha, or-betaare marked pre-release automatically
- Tags containing
The release publishes right after the builds finish. It does not wait for malware scanning. VirusTotal and ClamAV scans run afterward, in a separate job that runs in parallel with nothing blocking on it. The scans append their verdict to the release body once done. They never delay or block publication. NOTE: a malware hit is reported loudly in the release body, but it does not unpublish the release.
Runs a live droplet test against the freshly tagged release. It waits for the release workflow's own conclusion instead of running on a fixed timer. This keeps the droplet test aligned with the actual release build. If the release build fails, the shakedown fails fast instead of testing a stale or missing artifact.
-
Write release notes (optional but recommended):
# Create releases/v3.23.0-fix.29.0.md with your notesKeep
FORK_CHANGES.mdandCHANGELOG.mdcurrent in the same PR that lands the code (see the repo's docs workflow). House style (since 2026-08-14): write release notes and PR bodies in STE100 (Simplified Technical English) โ short sentences (~8-14 words), active voice, one meaning per word,NOTE:/mustmarkers, no em dashes or metaphor. Always keep the machine-generatedWhat's Changedsection with full PR links. Long narrative prose is rejected. -
Commit everything to
mainand push:git push origin main
-
Tag and push:
git tag v3.23.0-fix.28.1 git push origin v3.23.0-fix.28.1
-
GitHub Actions triggers
release.ymlandbuild.ymlautomatically. The Docker image will be tagged with bothlatestand the version tag. The binary tarball will appear on the Releases page.
Version format:
v3.23.0-fix.<N>for stable,v3.23.0-fix.<N>-rc.<M>for release candidates.
Runs a full static analysis of the Go codebase once per week (Sunday nights UTC). Results appear under the Security โ Code scanning tab in GitHub.
- Never runs on PRs or pushes โ no CI latency impact
- Restricted to the
full-bars/urnetwork-3.23-fixrepository to avoid wasting Actions minutes on forks - Can be triggered manually from the Actions tab for an on-demand scan
Runs twice daily (midnight and noon UTC) and watches upstream repos for activity that could affect this fork. Sends Discord alerts via DISCORD_WEBHOOK secret.
Six parallel jobs:
| Job | What it watches | Alert color |
|---|---|---|
monitor-critical-files |
PRs on urnetwork/connect (last 12h) touching critical files (ip.go, transfer.go, etc.) |
๐ด Red โ requires review |
monitor-all-prs |
Any PR activity on upstream urnetwork/connect in the last 12h |
๐ต Blue โ informational |
monitor-commits |
Commits merged to urnetwork/connect main in the last 12h touching critical files |
๐ข Green โ shipped upstream |
monitor-sibling-drift |
Commits to full-bars/connect (the upstream-tracking sibling fork) touching shared critical files โ port check |
๐ Orange โ port check |
monitor-build-releases |
New urnetwork/build releases; classifies provider-impact vs client-only |
๐ก Yellow โ evaluate |
monitor-sn-repo |
Commits to urfoundation/sn (Bittensor subnet repo that absorbed the old provider code) touching miner/, cli/miner/, cmd/, onchain/, proto, or dependency files โ portability assessment |
๐ Orange โ port check |
Critical files watched on urnetwork/connect: ip.go, transfer.go, transfer_contract_manager.go, transfer_route_manager.go, net_http.go, net_http_doh.go, transport.go, transfer_encrypt.go, provider/main.go, proxy_health.go, message_pool.go
AI-generated diff summaries (red/orange/yellow alerts) use a 3-tier fallback chain: opencode-go gateway first (opencode-go/deepseek-v4-flash via the opencode CLI), then the DeepSeek API (deepseek-v4-flash), then Gemini (gemini-3.1-flash-lite). Each tier is skipped if its API key is unset or the call fails.
| Secret | Required by |
|---|---|
GITHUB_TOKEN |
All workflows (auto-provided) |
DISCORD_WEBHOOK |
upstream_monitor.yml |
OPENCODE_API_KEY |
upstream_monitor.yml (AI summaries โ primary tier) |
DEEPSEEK_API_KEY |
upstream_monitor.yml (AI summaries โ fallback tier) |
GEMINI_API_KEY |
upstream_monitor.yml (AI summaries โ final fallback) |
DOCKERHUB_USERNAME |
build.yml |
DOCKERHUB_TOKEN |
build.yml |