Skip to content

fix(signals): stop repository selection treating app events as vendor work #383759

fix(signals): stop repository selection treating app events as vendor work

fix(signals): stop repository selection treating app events as vendor work #383759

Workflow file for this run

# This workflow runs all of our backend django tests.
#
# If these tests get too slow, look at increasing concurrency and re-timing the tests by manually dispatching
# .github/workflows/ci-backend-update-test-timing.yml action
name: Hog CI
on:
push:
branches:
- master
pull_request:
paths-ignore:
- rust/**
- livestream/**
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
env:
# npm's audit blocks the pnpm bootstrap. See .github/actions/pnpm-install for why.
NPM_CONFIG_AUDIT: 'false'
NPM_CONFIG_FUND: 'false'
jobs:
# Learning mode: nothing reads these outputs, so a recommendation cannot change what runs.
# Fork and Dependabot runs get no secret; the queue always runs everything anyway.
# The step fails open, because this telemetry must not turn a passing workflow red.
dynamic-ci-filter:
name: Trunk Dynamic CI (Learning Mode)
if: >-
github.event_name == 'pull_request' &&
github.repository == 'PostHog/posthog' &&
github.event.pull_request.head.repo.full_name == github.repository &&
github.actor != 'dependabot[bot]' &&
!startsWith(github.head_ref, 'trunk-merge/')
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions: {}
steps:
- name: Ask Trunk which jobs this diff needs
continue-on-error: true
uses: trunk-io/dynamic-ci@7e3af9331e8ebdfe0c71ba7d0ff6b7424dde8c57 # v1
with:
token: ${{ secrets.TRUNK_API_TOKEN }}
# Job to decide if we should run backend ci
# See .github/actions/paths-filter/README.md for filter semantics
changes:
runs-on: ubuntu-24.04
timeout-minutes: 5
name: Determine need to run Hog checks
permissions:
contents: read
pull-requests: read
# Set job outputs to values from filter step
outputs:
hog: ${{ steps.filter.outputs.hog || 'true' }}
steps:
# For pull requests it's not necessary to checkout the code, but we
# also want this to run on master so we need to checkout
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
sparse-checkout: .github/actions/paths-filter
sparse-checkout-cone-mode: false
- uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
id: app-token
if: github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository
with:
client-id: ${{ vars.GH_APP_POSTHOG_PATHS_FILTER_APP_ID }}
private-key: ${{ secrets.GH_APP_POSTHOG_PATHS_FILTER_PRIVATE_KEY }}
- uses: ./.github/actions/paths-filter
id: filter
if: github.event_name != 'push' # Run all tests on master push
with:
token: ${{ steps.app-token.outputs.token || github.token }}
filters: |
hog:
# Avoid running tests for irrelevant changes
- 'common/hogvm/**/*'
- 'posthog/hogql/**/*'
- 'bin/hog'
- 'bin/hoge'
- 'package.json'
- requirements.txt
- requirements-dev.txt
- .github/workflows/ci-hog.yml
- .github/actions/setup-uv/**
hog-tests:
needs: changes
timeout-minutes: 30
name: Hog tests
runs-on: ubuntu-24.04
if: needs.changes.outputs.hog == 'true'
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 1
- name: Mint setup-action GitHub token
id: setup-gh-token
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
continue-on-error: true
uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
with:
client-id: ${{ vars.GH_APP_POSTHOG_SETUP_ACTIONS_APP_ID }}
private-key: ${{ secrets.GH_APP_POSTHOG_SETUP_ACTIONS_PRIVATE_KEY }}
skip-token-revoke: true
- name: Set up Python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version-file: 'pyproject.toml'
token: ${{ steps.setup-gh-token.outputs.token || github.token }}
- name: Install uv
id: setup-uv
uses: ./.github/actions/setup-uv
- name: Install SAML (python3-saml) dependencies
if: steps.setup-uv.outputs.cache-hit != 'true'
run: |
sudo apt-get update
sudo apt-get install libxml2-dev libxmlsec1 libxmlsec1-dev libxmlsec1-openssl
- name: Install Python dependencies
run: |
UV_PROJECT_ENVIRONMENT=$pythonLocation uv sync --frozen --dev
- name: Install pnpm dependencies
uses: ./.github/actions/pnpm-install
with:
install-command: pnpm --filter=@posthog/hogvm install --frozen-lockfile
token: ${{ steps.setup-gh-token.outputs.token || github.token }}
- name: Check if ANTLR definitions are up to date
run: |
cd ..
mkdir antlr
cd antlr
# Short budget: the `||` mirror is the real fallback for a host that is down.
fetch=(curl --fail --location --retry 3 --retry-all-errors --retry-max-time 30 --connect-timeout 10)
"${fetch[@]}" https://www.antlr.org/download/antlr-${ANTLR_VERSION}-complete.jar --output antlr.jar \
|| "${fetch[@]}" https://repo.maven.apache.org/maven2/org/antlr/antlr4/${ANTLR_VERSION}/antlr4-${ANTLR_VERSION}-complete.jar --output antlr.jar
export PWD=`pwd`
echo '#!/bin/bash' > antlr
echo "java -jar $PWD/antlr.jar \$*" >> antlr
chmod +x antlr
export CLASSPATH=".:$PWD/antlr.jar:$CLASSPATH"
export PATH="$PWD:$PATH"
cd ../posthog
antlr | grep "Version"
npm run grammar:build && git diff --exit-code
env:
# Installing a version of ANTLR compatible with what's in Homebrew as of August 2024 (version 4.13.2),
# as apt-get is quite out of date. The same version must be set in common/hogql_parser/pyproject.toml
ANTLR_VERSION: '4.13.2'
- name: Check if STL bytecode is up to date
run: |
python -m common.hogvm.stl.compile
git diff --exit-code
env:
TEST: 1
- name: Run HogVM Python tests
run: |
pytest common/hogvm
- name: Run HogVM TypeScript tests
run: |
pnpm --filter=@posthog/hogvm install --frozen-lockfile
pnpm --filter=@posthog/hogvm test
- name: Run Hog tests
run: |
pnpm --filter=@posthog/hogvm install --frozen-lockfile
pnpm --filter=@posthog/hogvm compile:stl
bin/turbo --filter=@posthog/hogvm build
cd common/hogvm
./test.sh && git diff --exit-code
env:
TEST: 1