Files
416rehman-DeepZero-Agentic-…/pyproject.toml
T
416rehmanandClaude Opus 5 5d58b6afaf ci: split the pipeline by what each job actually needs
Every job in the matrix installed a JDK and downloaded a
several-hundred-megabyte Ghidra archive, then ran the linter and the
security scan again. Neither of those reads the interpreter, and only one
test reads Ghidra, so both costs were paid once per python version for
no additional signal.

The work is now split three ways:

- lint runs once, and installs the tools and the package's own light
  dependencies rather than everything under full
- the version matrix runs the suite without Ghidra, which is every test
  but one, and so needs no JVM at all
- a single integration job drives the real Ghidra install

Ghidra is cached between runs, keyed on the version and build it pins,
and unpacked under HOME so restoring it needs no privileges. Its
checksum is still verified whenever it is downloaded. The test that needs
it now carries a marker, so selecting it is declarative instead of a path
spelled out in the workflow.

A newer push cancels an in-flight run for the same branch, and the
linters are pinned to a minor so their own releases cannot fail a build
on their own.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 14:41:37 -06:00

65 lines
1.8 KiB
TOML

[build-system]
requires = ["setuptools>=68.0"]
build-backend = "setuptools.build_meta"
[project]
name = "deepzero"
version = "0.3.0"
description = "agentic pipeline for automated vulnerability research on kernel drivers"
requires-python = ">=3.11"
license = {text = "MIT"}
dependencies = [
"click>=8.0",
"rich>=13.0",
"pyyaml>=6.0",
"jinja2>=3.0",
"python-dotenv>=1.0.0",
]
[project.optional-dependencies]
llm = ["litellm>=1.0"]
serve = ["starlette>=0.27", "uvicorn>=0.22"]
pe = ["lief>=0.14.0"]
full = ["deepzero[llm,serve,pe]"]
# pinned to a minor: these tools change their own rules between releases, so an
# unpinned upgrade can fail the build with nothing in this repository having
# changed. Bump deliberately, and local checks then match what CI runs.
lint = ["ruff==0.16.*", "bandit==1.9.*"]
dev = ["pytest>=7.0", "pytest-asyncio>=0.21.0", "deepzero[full,lint]"]
[project.scripts]
deepzero = "deepzero.cli:main"
[tool.setuptools.packages.find]
where = ["src"]
[tool.pytest.ini_options]
testpaths = ["tests"]
pythonpath = ["src", "."]
markers = [
# needs a real Ghidra install and a JDK, so it is selected on its own rather
# than making every interpreter under test pay to download one
"ghidra: drives a local Ghidra install (requires GHIDRA_INSTALL_DIR)",
]
[tool.ruff]
line-length = 100
target-version = "py311"
# docs contain illustrative python snippets in markdown. newer ruff versions
# format embedded code blocks, which made `ruff format --check` fail in CI
# purely from a ruff upgrade. documentation examples are prose, not build
# artifacts - keep them out of the code formatter's scope.
extend-exclude = ["docs"]
[tool.ruff.lint]
select = ["E", "F", "W", "I"]
ignore = ["E501"]
[tool.ruff.format]
quote-style = "double"
indent-style = "space"
[tool.bandit]
exclude_dirs = ["tests", ".venv", "venv"]
skips = []