Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
* @DerDennisOP
41 changes: 41 additions & 0 deletions .github/ISSUE_TEMPLATE/bug-report-backend.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
name: Bug report (backend)
description: A stuck or failed evaluation, build or worker, with a diagnostic report attached.
labels: ["bug"]
body:
- type: markdown
attributes:
value: |
Generate the report on the evaluation panel: three-dot menu -> **Diagnostic report** -> **Generate**. See [Report a Bug with a Diagnostic Report](https://wavelens.github.io/gradient/guides/diagnostic-report/).

- type: textarea
id: description
attributes:
label: What went wrong
description: What happened and what you expected instead.
validations:
required: true

- type: textarea
id: report
attributes:
label: Diagnostic report
description: GitHub does not accept `.db` files. Compress the report first (`gzip gradient-report-*.db`), then drag the `.db.gz` file in here.
placeholder: Drop gradient-report-<id>-<date>.db.gz here
validations:
required: true

- type: input
id: version
attributes:
label: Gradient version
description: Shown in the frontend footer.
placeholder: 2.0.0
validations:
required: true

- type: textarea
id: logs
attributes:
label: Server or worker logs
description: Relevant lines from `journalctl -u gradient-server` or `journalctl -u gradient-worker`.
render: text
41 changes: 41 additions & 0 deletions .github/ISSUE_TEMPLATE/bug-report-cli.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
name: Bug report (CLI)
description: A failing or misbehaving `gradient` command.
labels: ["bug"]
body:
- type: textarea
id: description
attributes:
label: What went wrong
description: What happened and what you expected instead.
validations:
required: true

- type: textarea
id: command
attributes:
label: Command and output
description: The full command line and its output. Remove tokens and other secrets first.
render: shell
validations:
required: true

- type: input
id: cli-version
attributes:
label: CLI version
description: Output of `gradient --version`.
validations:
required: true

- type: input
id: server-version
attributes:
label: Server version
description: Shown in the frontend footer.
placeholder: 2.0.0

- type: input
id: system
attributes:
label: Operating system and installation
placeholder: NixOS 26.05, nix profile install github:wavelens/gradient#gradient-cli
60 changes: 60 additions & 0 deletions .github/ISSUE_TEMPLATE/bug-report-frontend.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
name: Bug report (frontend)
description: A broken page, wrong display or accessibility barrier in the web UI.
labels: ["bug", "frontend"]
body:
- type: textarea
id: description
attributes:
label: What went wrong
description: What happened and what you expected instead.
validations:
required: true

- type: input
id: page
attributes:
label: Page
description: Path of the affected page, without the domain.
placeholder: /project/web/task/main/settings
validations:
required: true

- type: textarea
id: steps
attributes:
label: Steps to reproduce
placeholder: |
1. Open the task page
2. Click the three-dot menu on the evaluation panel
3. ...

- type: textarea
id: screenshot
attributes:
label: Screenshot or recording
description: Drag images or videos in here.

- type: input
id: browser
attributes:
label: Browser and operating system
description: Also any assistive technology, e.g. a screen reader.
placeholder: Firefox 143, NixOS 26.05
validations:
required: true

- type: input
id: version
attributes:
label: Gradient version
description: Shown in the frontend footer.
placeholder: 2.0.0
validations:
required: true

- type: textarea
id: console
attributes:
label: Browser console errors
description: Errors from the developer tools console (F12).
render: text
5 changes: 5 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Security vulnerability
url: https://github.com/wavelens/gradient/security/advisories/new
about: Report vulnerabilities privately, never in a public issue.
44 changes: 44 additions & 0 deletions .github/ISSUE_TEMPLATE/feature-request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
name: Feature request
description: A new capability or a change to existing behavior.
labels: ["enhancement"]
body:
- type: markdown
attributes:
value: |
Check the [Roadmap](https://wavelens.github.io/gradient/roadmap/) first. Open questions fit better in [GitHub Discussions](https://github.com/wavelens/gradient/discussions).

- type: dropdown
id: area
attributes:
label: Area
options:
- Server
- Worker
- Frontend
- CLI
- NixOS module
- Documentation
validations:
required: true

- type: textarea
id: problem
attributes:
label: Problem
description: The use case and the current blocker.
validations:
required: true

- type: textarea
id: solution
attributes:
label: Proposed solution
description: How Gradient could solve it, from the user's side.
validations:
required: true

- type: textarea
id: alternatives
attributes:
label: Alternatives
description: Workarounds in use today, or how other CI systems solve it.
18 changes: 18 additions & 0 deletions .github/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
changelog:
exclude:
authors:
- gradient-ci[bot]
- dependabot[bot]
categories:
- title: Breaking Changes
labels: [breaking]
- title: Security
labels: [security]
- title: Features
labels: [enhancement]
- title: Fixes
labels: [bug]
- title: Documentation
labels: [documentation]
- title: Other Changes
labels: ["*"]
47 changes: 46 additions & 1 deletion .github/workflows/standalone-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,8 @@ on:
permissions:
contents: read
packages: write
id-token: write
attestations: write

env:
IMAGE: ghcr.io/wavelens/gradient-standalone
Expand All @@ -33,14 +35,48 @@ jobs:
extra-substituters = https://public.gradient.ci/cache/main
extra-trusted-public-keys = public.gradient.ci-main:qmxRE+saUvhNa3jqaCMWje+feVU77TjABchZrPGf7A8=

- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: "Build image"
run: nix build -L .#packages.${{ matrix.system }}.standalone-image

- name: "Push image"
id: push
env:
CREDS: ${{ github.actor }}:${{ secrets.GITHUB_TOKEN }}
TAG: ${{ github.ref_name }}-${{ matrix.arch }}
run: nix run nixpkgs#skopeo -- copy --dest-creds "$CREDS" docker-archive:result "docker://$IMAGE:$TAG"
run: |
nix run nixpkgs#skopeo -- copy --digestfile digest --dest-creds "$CREDS" docker-archive:result "docker://$IMAGE:$TAG"
echo "digest=$(cat digest)" >> "$GITHUB_OUTPUT"

- name: "Generate SBOM"
uses: anchore/sbom-action@v0.24.3
with:
image: ${{ env.IMAGE }}@${{ steps.push.outputs.digest }}
registry-username: ${{ github.actor }}
registry-password: ${{ secrets.GITHUB_TOKEN }}
format: spdx-json
output-file: sbom.spdx.json
upload-artifact: false

- name: "Attest build provenance"
uses: actions/attest-build-provenance@v4.2.2
with:
subject-name: ${{ env.IMAGE }}
subject-digest: ${{ steps.push.outputs.digest }}
push-to-registry: true

- name: "Attest SBOM"
uses: actions/attest-sbom@v4.1.0
with:
subject-name: ${{ env.IMAGE }}
subject-digest: ${{ steps.push.outputs.digest }}
sbom-path: sbom.spdx.json
push-to-registry: true

manifest:
needs: build
Expand All @@ -53,9 +89,18 @@ jobs:
password: ${{ secrets.GITHUB_TOKEN }}

- name: "Publish multi-arch manifest"
id: manifest
env:
REF: ${{ github.ref_name }}
run: |
for tag in "$REF" latest; do
docker buildx imagetools create -t "$IMAGE:$tag" "$IMAGE:$REF-amd64" "$IMAGE:$REF-arm64"
done
echo "digest=$(docker buildx imagetools inspect "$IMAGE:$REF" --format '{{json .Manifest}}' | jq -r .digest)" >> "$GITHUB_OUTPUT"

- name: "Attest build provenance"
uses: actions/attest-build-provenance@v4.2.2
with:
subject-name: ${{ env.IMAGE }}
subject-digest: ${{ steps.manifest.outputs.digest }}
push-to-registry: true
16 changes: 16 additions & 0 deletions ACCESSIBILITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Accessibility

Every page of the Gradient frontend should work with a keyboard and a screen reader, without relying on color or motion.

## In Place

- Light, dark and system theme.
- No animation of status icons, progress bars and the command palette under `prefers-reduced-motion`.
- Command palette on `/`, navigable with the arrow keys or `Ctrl+J` / `Ctrl+K`.
- Status icons carry a text label for screen readers.

## Reporting a Barrier

Barriers go into a [Bug report (frontend)](https://github.com/wavelens/gradient/issues/new?template=bug-report-frontend.yml), together with the assistive technology in use.

Accessibility issues are bugs and get the same priority as functional ones.
36 changes: 36 additions & 0 deletions GOVERNANCE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# Governance

Gradient is an open source project under the AGPL, stewarded by Wavelens GmbH.

## Roles

| Role | Rights | Duties |
|---|---|---|
| Lead maintainer | Final say on direction, releases and disputes | Roadmap, releases, security advisories |
| Maintainer | Review, merge and triage | Code review, issue triage, release testing |
| Contributor | Issues, discussions and pull requests | [Contributing guide](./CONTRIBUTING.md) and [Code of Conduct](./CODE_OF_CONDUCT.md) |

## Maintainers

| Name | GitHub | Role |
|---|---|---|
| Dennis Wuitz | [@DerDennisOP](https://github.com/DerDennisOP) | Lead maintainer, Wavelens GmbH |
| Sandro Jäckel | [@SuperSandro2000](https://github.com/SuperSandro2000) | Maintainer |

## Decisions

- Maintainers decide day-to-day changes through pull request review.
- Every pull request needs the approval of one maintainer other than the author.
- Larger changes start as an issue or discussion before any code.
- The lead maintainer can settle a disagreement among maintainers.
- Planned direction in the [Roadmap](https://wavelens.github.io/gradient/roadmap/).

## Becoming a Maintainer

- Sustained, high-quality contributions over a few months.
- Nomination by an existing maintainer and approval by the lead maintainer.
- Inactive maintainers can step down or move to an emeritus list after six months without activity.

## Changes to This Document

Changes to the governance go through a pull request with the approval of the lead maintainer.
28 changes: 28 additions & 0 deletions PRIVACY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# Privacy

Gradient instances send no data to Wavelens GmbH or any third party. There is no telemetry, no usage tracking and no phone-home.

## Self-Hosted Data

All data remain on infrastructure of the operator.

| Data | Location |
|---|---|
| Accounts, projects, evaluations, build logs | PostgreSQL of the instance |
| Build outputs and cache contents | Disk or S3 storage of the operator |
| Store paths on workers | Nix store of each worker |

- The operator is the data controller under the GDPR.
- Users can delete their own account in the web UI or through `DELETE /user`.

## Outgoing Connections

Gradient can only reach services the operator configured.

- Git hosts, upstream caches and S3 storage.
- Webhooks, OIDC providers and SCIM clients.
- Crash reports to Wavelens, only with `services.gradient.sentry.enable = true`. Off by default.

## Diagnostic Reports

A [diagnostic report](https://wavelens.github.io/gradient/guides/diagnostic-report/) can leave the instance only as an attachment a user uploaded. Identities stay anonymized without an explicit opt-in. Credentials are never part of the file.
Loading
Loading