Skip to content

test: run release environment policy checks only in CI - #4037

Draft
yoni-oai wants to merge 2 commits into
mainfrom
codex/ci-only-package-policy-tests
Draft

yoni-oai wants to merge 2 commits into
mainfrom
codex/ci-only-package-policy-tests

Conversation

@yoni-oai

@yoni-oai yoni-oai commented Oct 8, 2026

Copy link
Copy Markdown

Four package-policy tests fail during local development when a managed registry rewrites the lockfile or cached installations avoid exercising build restrictions. Run these checks only when CI=true, which GitHub Actions supplies automatically; developers can opt in locally with the same variable.

Fixture-based security checks continue running locally. This changes only the four test decorators and their shared skip condition; package management and workflow commands stay unchanged.

Validation:

  • Workflow test file: 1,920 passed, 4 skipped locally.
  • CI=true enabled all four checks and reproduced the expected failures against the locally adapted lockfile/environment.
  • Ruff lint, formatting, and whitespace checks passed.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Castiron custom code

Evaluated main: 4e152cdefe1844c2d5d78653310e9b9c0195c44e.

✅ No new custom-code files detected.

46 mixed files remain; 0 existing customizations changed.

Compared 4e152cdefe18 → 7a58e79c1714. Generated baselines verified.

46 existing customizations unchanged
  • api.md
  • src/openai/init.py
  • src/openai/_client.py
  • src/openai/resources/audio/transcriptions.py
  • src/openai/resources/audio/translations.py
  • src/openai/resources/beta/agents/environments/files.py
  • src/openai/resources/beta/agents/sessions/artifacts.py
  • src/openai/resources/beta/agents/sessions/sessions.py
  • src/openai/resources/beta/beta.py
  • src/openai/resources/beta/responses/responses.py
  • src/openai/resources/beta/threads/runs/runs.py
  • src/openai/resources/beta/threads/threads.py
  • src/openai/resources/chat/completions/completions.py
  • src/openai/resources/embeddings.py
  • src/openai/resources/files.py
  • src/openai/resources/live/forks.py
  • src/openai/resources/live/live.py
  • src/openai/resources/live/sideband.py
  • src/openai/resources/realtime/api.md
  • src/openai/resources/realtime/realtime.py
  • src/openai/resources/responses/responses.py
  • src/openai/resources/uploads/uploads.py
  • src/openai/resources/vector_stores/file_batches.py
  • src/openai/resources/vector_stores/files.py
  • src/openai/resources/videos.py
  • src/openai/resources/webhooks/init.py
  • src/openai/resources/webhooks/webhooks.py
  • src/openai/types/beta/agent_session_message.py
  • src/openai/types/chat/init.py
  • src/openai/types/chat/chat_completion_message_tool_call.py
  • src/openai/types/fine_tuning/fine_tuning_job_integration.py
  • src/openai/types/realtime/conversation_item_input_audio_transcription_delta_event.py
  • src/openai/types/realtime/realtime_error_event.py
  • src/openai/types/responses/init.py
  • src/openai/types/responses/response.py
  • src/openai/types/responses/response_function_web_search.py
  • src/openai/types/responses/response_function_web_search_param.py
  • src/openai/types/responses/responses_client_event.py
  • src/openai/types/responses/responses_client_event_param.py
  • src/openai/types/responses/tool.py

6 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 37715968770 --repo openai/openai-python \
  --name castiron-custom-code-37715968770-1 --dir /tmp/castiron-custom-code-37715968770-1
git apply --stat /tmp/castiron-custom-code-37715968770-1/custom-code.patch
cat /tmp/castiron-custom-code-37715968770-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 4e152cdefe1844c2d5d78653310e9b9c0195c44e 7a58e79c17140e38e551613b59070508ddb35787
python3 scripts/castiron/custom_code_report.py report \
  --base 4e152cdefe1844c2d5d78653310e9b9c0195c44e \
  --head 7a58e79c17140e38e551613b59070508ddb35787 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-7a58e79c1714
cat /tmp/castiron-custom-code-7a58e79c1714/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@marcuswood-oai marcuswood-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ship it!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants