Skip to content

Development and Release

Mohammed Danish Amber edited this page Oct 5, 2026 · 1 revision

Development and Release

Layout

engine/     the aphasia Python package (CLI, attacker, connectors, canary/mirror, report)
  src/aphasia/data/scenarios.yaml   the 11 scenarios
  src/aphasia/data/payloads.yaml    the seed-payload library
fixture/    the deliberately-vulnerable HTTP agent + MCP server (Docker)
docs/       quickstart, scenarios, demo script, assets

Tests

cd engine && uv run pytest -m "not live"      # offline engine suite (StubProvider; no network)
# fixture suite (sandbox-inert + in-process seed end-to-end):
uv run --with-editable ./engine --with flask --with "mcp>=2" --with pytest python -m pytest fixture/tests

A @pytest.mark.live test runs the real CLI against the fixture; it is skipped unless OLLAMA_HOST is set and is excluded from CI.

CI

.github/workflows/ci.yml runs the offline engine suite and the fixture suite (incl. the sandbox-inert checks and the end-to-end seed run) on every push/PR. No Docker, no live tests.

Build

cd engine && uv build        # -> engine/dist/aphasia_agentry-<ver>-py3-none-any.whl + .tar.gz

The scenario/payload YAML ship inside the wheel (aphasia/data/), so an installed CLI works.

Release & PyPI

.github/workflows/publish.yml runs on a published GitHub Release: it builds the wheel+sdist, attaches them to the release, and publishes to PyPI via Trusted Publishing (OIDC) — no stored token.

To cut a release:

  1. Bump version in engine/pyproject.toml.
  2. Commit, then gh release create vX.Y.Z --title "vX.Y.Z" --notes "...".
  3. The workflow attaches artifacts and publishes to PyPI.

(Trusted Publishing must be registered once on PyPI: Project → Publishing → GitHub, owner mddanish, repo Aphasia-Agentry, workflow publish.yml, environment pypi.)

Clone this wiki locally