Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ jobs:
# Proves the full VMAFX stack compiles. Runs the complete meson
# test suite (including Netflix golden assertions).
# ──────────────────────────────────────────────────────────────
- os: ubuntu-latest
- os: ubuntu-24.04
name: Build — Linux (GCC, all backends)
CC: ccache gcc
CXX: ccache g++
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ concurrency:

jobs:
build:
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand All @@ -37,7 +37,7 @@ jobs:

deploy:
needs: build
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
environment:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/ffmpeg-integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ jobs:
fail-fast: false
matrix:
include:
- os: ubuntu-latest
- os: ubuntu-24.04
CC: gcc
CXX: g++
name: FFmpeg — Ubuntu gcc (Build Only)
Expand All @@ -65,7 +65,7 @@ jobs:
python -m pip install --upgrade pip
pip install meson
- name: Install dependencies (ubuntu)
if: matrix.os == 'ubuntu-latest'
if: matrix.os == 'ubuntu-24.04'
run: |
sudo apt-get update
sudo -E apt-get -yq install ninja-build gcc nasm
Expand All @@ -92,7 +92,7 @@ jobs:
ffmpeg-sycl:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: FFmpeg — SYCL (Build Only)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
env:
CC: gcc
CXX: g++
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/fuzz.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ concurrency:
jobs:
fuzz:
name: ${{ matrix.target }}
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 15
strategy:
fail-fast: false
Expand Down
24 changes: 12 additions & 12 deletions .github/workflows/libvmaf-build-matrix.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,11 +46,11 @@ jobs:
matrix:
include:
# --- CPU-only builds ---
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache gcc
CXX: ccache g++
name: Build — Ubuntu gcc (CPU)
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache clang
CXX: ccache clang++
name: Build — Ubuntu clang (CPU)
Expand All @@ -73,7 +73,7 @@ jobs:
# the matrix. Tests are skipped (meson cross-build marks
# them SKIP 77 — host can run i686 binaries natively but
# meson doesn't know that). See ADR-0151.
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache gcc
CXX: ccache g++
i686: true
Expand All @@ -87,13 +87,13 @@ jobs:
# (Linux: MS tarball pinned to 1.22.0; macOS: Homebrew) and runs
# the meson dnn suite. macOS leg stays `experimental: true` so a
# Homebrew ORT bump that breaks ABI doesn't block merge.
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache gcc
CXX: ccache g++
dnn: true
meson_extra: -Denable_dnn=enabled
name: Build — Ubuntu gcc (CPU) + DNN
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache clang
CXX: ccache clang++
dnn: true
Expand All @@ -114,7 +114,7 @@ jobs:
# a compute-capable VkPhysicalDevice on headless runners
# so the smoke test can run end-to-end. Wraps for volk +
# VMA are sha256-pinned in core/subprojects/.
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache gcc
CXX: ccache g++
vulkan: true
Expand Down Expand Up @@ -158,7 +158,7 @@ jobs:
# device-resident smoke assertions, mirroring the
# Vulkan-on-lavapipe-less-CI pattern from ADR-0175). See
# ADR-0212 §"Status update 2026-05-09: CI lane enabled".
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache gcc
CXX: ccache g++
hip: true
Expand All @@ -185,7 +185,7 @@ jobs:
name: Build — macOS Metal (T8-1 scaffold)

# --- Static library builds ---
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache gcc
CXX: ccache g++
meson_extra: --default-library static
Expand All @@ -198,7 +198,7 @@ jobs:
# could catch shows up first on the dynamic lane). The
# CUDA Static lane stays because it exercises a distinct
# NVCC-static interaction not covered by the dynamic build.
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache gcc
CXX: ccache g++
cuda: true
Expand All @@ -208,15 +208,15 @@ jobs:
# --- SYCL build (icpx for both host + SYCL sources so the device
# image is registered at the .so link step; see post-T7-8
# SYCL revival in core/src/meson.build) ---
- os: ubuntu-latest
- os: ubuntu-24.04
CC: icx
CXX: icpx
sycl: true
meson_extra: -Denable_sycl=true -Db_lto=false
name: Build — Ubuntu SYCL

# --- CUDA build (gcc + nvcc) ---
- os: ubuntu-latest
- os: ubuntu-24.04
CC: ccache gcc
CXX: ccache g++
cuda: true
Expand All @@ -225,7 +225,7 @@ jobs:

# --- SYCL + CUDA combined (icpx host so SYCL link works; nvcc
# handles the CUDA TUs separately via -Denable_nvcc=true) ---
- os: ubuntu-latest
- os: ubuntu-24.04
CC: icx
CXX: icpx
sycl: true
Expand Down
16 changes: 8 additions & 8 deletions .github/workflows/lint-and-format.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ jobs:
pre-commit:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: Pre-Commit (Formatters + Basic Checks)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand Down Expand Up @@ -55,7 +55,7 @@ jobs:
clang-tidy:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: Clang-Tidy (Changed C/C++ Files)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 25
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand Down Expand Up @@ -263,7 +263,7 @@ jobs:
# don't lose the actual signal — only the lint pass on top of it.
name: Clang-Tidy SYCL (Changed Files, Advisory — Disabled)
if: (github.event_name != 'pull_request' || github.event.pull_request.draft == false) && (false)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 35
continue-on-error: true
steps:
Expand Down Expand Up @@ -396,7 +396,7 @@ jobs:
# Variable `ARC_RUNNERS_ENABLED=true` flips this job to the in-cluster
# `arc-runners` scale set; default `false` keeps GitHub-hosted. If the
# ARC pool is degraded, flip the var off and re-trigger CI.
runs-on: ${{ vars.ARC_RUNNERS_ENABLED == 'true' && 'arc-runners' || 'ubuntu-latest' }}
runs-on: ${{ vars.ARC_RUNNERS_ENABLED == 'true' && 'arc-runners' || 'ubuntu-24.04' }}
# Bumped 15→30 min on 2026-05-09: GitHub-hosted runner queue
# saturation pushed Cppcheck past 15 min on ~all PRs and master.
# Last green run on master took 5 min; the new ceiling absorbs
Expand Down Expand Up @@ -442,7 +442,7 @@ jobs:
# "Python Lint (mypy)" lands separately together with the
# branch-protection change.
name: Python Lint (Ruff + Black + isort + mypy)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand All @@ -460,7 +460,7 @@ jobs:
# available, plus cross-file invariants (sha256 matches, sidecars
# exist). Fails closed.
name: Tiny-Model Registry Validate
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand All @@ -485,7 +485,7 @@ jobs:
# (38 of 50 docs.yml runs were failing before this job was added).
# The job is intentionally path-filtered so C-only PRs skip it quickly.
name: Docs Build — mkdocs strict (PR gate)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand All @@ -508,7 +508,7 @@ jobs:
# apt-install / shfmt-curl steps are dropped — pre-commit covers
# the same surface in the same PR via the pinned hook revs.
name: ShellCheck + shfmt (All *.sh)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 1
needs: pre-commit
steps:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-please.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ permissions:

jobs:
release-please:
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
# Scoped to the one job that creates release PRs / tags; the workflow
# default stays `contents: read` so any step added later starts from
# least-privilege (Scorecard TokenPermissionsID).
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/required-aggregator.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ concurrency:
jobs:
aggregator:
name: Required Checks Aggregator
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 100
steps:
- name: Block draft PRs from satisfying the required check
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/rule-enforcement.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ jobs:
deep-dive-checklist:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: Deep-Dive Deliverables Checklist (ADR-0108)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand Down Expand Up @@ -81,7 +81,7 @@ jobs:
doc-substance-check:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: Doc-Substance Gate (ADR-0100 / 0167)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
# ADR-0167 (2026-04-25): promoted from advisory to blocking and
# tightened to require a *path-mapped* docs hit. ADR additions
Expand Down Expand Up @@ -201,7 +201,7 @@ jobs:
state-md-touch-check:
if: github.event.pull_request.draft == false || github.event_name != 'pull_request'
name: docs/state.md Touch Gate (ADR-0165)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
# ADR-0334 (2026-05-08): promotes CLAUDE.md §12 rule 13 (the
# docs/state.md update discipline) from reviewer-enforced to
Expand Down Expand Up @@ -230,7 +230,7 @@ jobs:
ffmpeg-patches-surface-check:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: FFmpeg-Patches Surface Sync (CLAUDE.md §12 r14, ADR-0356)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
# Blocking gate: every PR that changes a libvmaf public-surface
# symbol consumed by ffmpeg-patches/*.patch must update at least
Expand All @@ -255,7 +255,7 @@ jobs:
adr-backfill-check:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: ADR-Backfill Advisory (ADR-0106)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
continue-on-error: true
steps:
Expand Down Expand Up @@ -302,7 +302,7 @@ jobs:
adr-collision-check:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: ADR Number Collision Guard (ADR-0386 / ADR-0628)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
# Blocking gate: every ADR file added in this PR must have a 4-digit prefix
# that does NOT already exist on origin/master AND does NOT collide with any
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/sanitizers.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ jobs:
github.event_name == 'pull_request' && github.event.pull_request.draft == false
|| github.event_name == 'workflow_dispatch'
name: "Sanitizers — ASan + UBSan (PR gate)"
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 30
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand Down Expand Up @@ -111,7 +111,7 @@ jobs:
github.event_name == 'push' && github.ref == 'refs/heads/master'
|| github.event_name == 'workflow_dispatch'
name: "Sanitizers — TSan (master push)"
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 35
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand Down Expand Up @@ -158,7 +158,7 @@ jobs:
github.event_name == 'schedule'
|| github.event_name == 'workflow_dispatch'
name: "Fuzz — ${{ matrix.target }} (nightly)"
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 15
strategy:
fail-fast: false
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ permissions: read-all
jobs:
analysis:
name: Scorecard analysis
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
permissions:
security-events: write # upload SARIF to the Security tab
id-token: write # Sigstore attestation for the public dashboard
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/security-scans.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ jobs:
semgrep:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: Semgrep (CWE Top 25 + CERT-C + Custom)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
Expand Down Expand Up @@ -95,7 +95,7 @@ jobs:
codeql-cpp:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: CodeQL (C/C++)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 35
permissions:
contents: read
Expand All @@ -121,7 +121,7 @@ jobs:
codeql-python:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: CodeQL (Python)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 15
permissions:
contents: read
Expand Down Expand Up @@ -149,7 +149,7 @@ jobs:
codeql-actions:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: CodeQL (Actions)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: read
Expand All @@ -168,7 +168,7 @@ jobs:
secret-scan:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
name: Gitleaks (Secret Scan)
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
contents: read
Expand Down Expand Up @@ -208,7 +208,7 @@ jobs:
dependency-review:
name: Dependency Review (PR Diff)
if: (github.event_name != 'pull_request' || github.event.pull_request.draft == false) && (github.event_name == 'pull_request')
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand Down
Loading
Loading