mirror of
https://github.com/416rehman/DeepZero-Agentic-Vulnerability-Research-Pipeline
synced 2026-08-09 11:55:01 +00:00
Every job in the matrix installed a JDK and downloaded a several-hundred-megabyte Ghidra archive, then ran the linter and the security scan again. Neither of those reads the interpreter, and only one test reads Ghidra, so both costs were paid once per python version for no additional signal. The work is now split three ways: - lint runs once, and installs the tools and the package's own light dependencies rather than everything under full - the version matrix runs the suite without Ghidra, which is every test but one, and so needs no JVM at all - a single integration job drives the real Ghidra install Ghidra is cached between runs, keyed on the version and build it pins, and unpacked under HOME so restoring it needs no privileges. Its checksum is still verified whenever it is downloaded. The test that needs it now carries a marker, so selecting it is declarative instead of a path spelled out in the workflow. A newer push cancels an in-flight run for the same branch, and the linters are pinned to a minor so their own releases cannot fail a build on their own. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
65 lines
1.8 KiB
TOML
65 lines
1.8 KiB
TOML
[build-system]
|
|
requires = ["setuptools>=68.0"]
|
|
build-backend = "setuptools.build_meta"
|
|
|
|
[project]
|
|
name = "deepzero"
|
|
version = "0.3.0"
|
|
description = "agentic pipeline for automated vulnerability research on kernel drivers"
|
|
requires-python = ">=3.11"
|
|
license = {text = "MIT"}
|
|
dependencies = [
|
|
"click>=8.0",
|
|
"rich>=13.0",
|
|
"pyyaml>=6.0",
|
|
"jinja2>=3.0",
|
|
"python-dotenv>=1.0.0",
|
|
]
|
|
|
|
[project.optional-dependencies]
|
|
llm = ["litellm>=1.0"]
|
|
serve = ["starlette>=0.27", "uvicorn>=0.22"]
|
|
pe = ["lief>=0.14.0"]
|
|
full = ["deepzero[llm,serve,pe]"]
|
|
# pinned to a minor: these tools change their own rules between releases, so an
|
|
# unpinned upgrade can fail the build with nothing in this repository having
|
|
# changed. Bump deliberately, and local checks then match what CI runs.
|
|
lint = ["ruff==0.16.*", "bandit==1.9.*"]
|
|
dev = ["pytest>=7.0", "pytest-asyncio>=0.21.0", "deepzero[full,lint]"]
|
|
|
|
[project.scripts]
|
|
deepzero = "deepzero.cli:main"
|
|
|
|
[tool.setuptools.packages.find]
|
|
where = ["src"]
|
|
|
|
[tool.pytest.ini_options]
|
|
testpaths = ["tests"]
|
|
pythonpath = ["src", "."]
|
|
markers = [
|
|
# needs a real Ghidra install and a JDK, so it is selected on its own rather
|
|
# than making every interpreter under test pay to download one
|
|
"ghidra: drives a local Ghidra install (requires GHIDRA_INSTALL_DIR)",
|
|
]
|
|
|
|
[tool.ruff]
|
|
line-length = 100
|
|
target-version = "py311"
|
|
# docs contain illustrative python snippets in markdown. newer ruff versions
|
|
# format embedded code blocks, which made `ruff format --check` fail in CI
|
|
# purely from a ruff upgrade. documentation examples are prose, not build
|
|
# artifacts - keep them out of the code formatter's scope.
|
|
extend-exclude = ["docs"]
|
|
|
|
[tool.ruff.lint]
|
|
select = ["E", "F", "W", "I"]
|
|
ignore = ["E501"]
|
|
|
|
[tool.ruff.format]
|
|
quote-style = "double"
|
|
indent-style = "space"
|
|
|
|
[tool.bandit]
|
|
exclude_dirs = ["tests", ".venv", "venv"]
|
|
skips = []
|