Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: leejet/stable-diffusion.cpp
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: master
Choose a base ref
...
head repository: tetherto/qvac-ext-stable-diffusion.cpp
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: master
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 13 commits
  • 13 files changed
  • 4 contributors

Commits on Jun 16, 2026

  1. Configuration menu
    Copy the full SHA
    ef380d2 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    b16e2ba View commit details
    Browse the repository at this point in the history
  3. chore(ci): remove labeled trigger and verified label condition

    Remove the `labeled` trigger type from pull_request_target and the
    associated `verified` label guard from the if condition. The check
    now fires on opened and synchronize only, without requiring a label.
    sidj-thr committed Jun 16, 2026
    Configuration menu
    Copy the full SHA
    f7b8d2c View commit details
    Browse the repository at this point in the history

Commits on Jun 17, 2026

  1. Configuration menu
    Copy the full SHA
    1cb653b View commit details
    Browse the repository at this point in the history
  2. Merge pull request #14 from tetherto/chore/add-qvac-ci-pending-approval

    infra[notask]: add qvac-ci pending-approval workflow and CODEOWNERS
    sidj-thr authored Jun 17, 2026
    Configuration menu
    Copy the full SHA
    f785f41 View commit details
    Browse the repository at this point in the history

Commits on Jun 23, 2026

  1. Configuration menu
    Copy the full SHA
    088ff43 View commit details
    Browse the repository at this point in the history

Commits on Jun 25, 2026

  1. Configuration menu
    Copy the full SHA
    5e27830 View commit details
    Browse the repository at this point in the history

Commits on Jul 7, 2026

  1. QVAC-21550 infra: roll out canonical security baseline (TruffleHog + …

    …CodeQL) to qvac-ext-stable-diffusion.cpp (#17)
    
    * QVAC-21550 infra: add canonical security baseline caller (TruffleHog + CodeQL)
    
    * QVAC-21550 fix: drop paths-exclude (unsupported by reusable security v0)
    
    * QVAC-21550 fix: buildless CodeQL (codeql-build-mode: none) via qvac-actions#10
    
    * QVAC-21550 fix: drop secrets: inherit (baseline needs no repo secrets; github.token suffices)
    
    * QVAC-21550 fix: repin security baseline to qvac-actions 0.2.0 (buildless c-cpp)
    GSServita authored Jul 7, 2026
    Configuration menu
    Copy the full SHA
    705b7a4 View commit details
    Browse the repository at this point in the history

Commits on Jul 30, 2026

  1. QVAC-22747 infra: add weekly schedule to CodeScan caller (#23)

    The canonical CodeScan baseline currently runs on push/PR only, so the
    QVAC-19056 commitment to a weekly scan is unmet. Add a scheduled cron
    (staggered per repo across the fleet) alongside the existing
    push / pull_request / workflow_dispatch triggers. No other change.
    GSServita authored Jul 30, 2026
    Configuration menu
    Copy the full SHA
    e417a9e View commit details
    Browse the repository at this point in the history

Commits on Jul 31, 2026

  1. QVAC-22740 infra: bump CodeScan caller to qvac-actions 0.3.0 (#26)

    Bump the reusable security workflow pin 0.2.0 -> 0.3.0 (SHA bbb0740e). 0.3.0
    adds the findings-export artifact (export-report default on), so each run now
    publishes a downloadable security-scan-report (findings.json/md + SARIF).
    GSServita authored Jul 31, 2026
    Configuration menu
    Copy the full SHA
    48361f9 View commit details
    Browse the repository at this point in the history

Commits on Sep 4, 2026

  1. QVAC-14347 infra: centralize CI runner labels in a shared catalog (#36)

    Add .github/runners.yaml as the single source of truth for specialized CI runner labels, a generated reusable-runner-names workflow that exports them as job outputs, and sync/validate scripts with unit tests. Wire build.yml's Windows jobs to consume the output instead of hardcoding windows-2022. Rolling -latest aliases and matrix.os identities stay hardcoded.
    GSServita authored Sep 4, 2026
    Configuration menu
    Copy the full SHA
    88c1e8b View commit details
    Browse the repository at this point in the history

Commits on Sep 8, 2026

  1. QVAC-24629 infra: cancel superseded CI runs on push and dispatch (#38)

    build.yml's group fell back to github.run_id whenever head_ref was empty, so pushes and dispatches never cancelled. Key on the PR number, then on the publish predicate, then the ref. Anything that publishes is exempt and keyed per run: every publish gate has a branch-free disjunct (github.event.inputs.create_release == 'true'), so a create_release dispatch publishes from any ref and must never be superseded mid-uploadReleaseAsset. runner-names-validate gains a block.
    tobi-legan authored Sep 8, 2026
    Configuration menu
    Copy the full SHA
    d3f773a View commit details
    Browse the repository at this point in the history

Commits on Sep 24, 2026

  1. QVAC-24501 fix: unignore .github/scripts/test and add the tests CI al…

    …ready runs (#45)
    
    * QVAC-24501 fix: unignore .github/scripts/test and add the tests CI already runs
    
    runner-names-validate.yml has always had this step:
    
      - name: Unit tests
        run: node --test .github/scripts/test/runner-names.test.mjs
    
    but that file is not in the repo, and `node --test` on a missing path exits 1.
    The workflow has therefore failed on every run since infra/runner-label-catalog
    introduced it on 2026-09-01 - master included, and throughout the QVAC-24629
    concurrency branch. Run 34256435445 on master shows the shape:
    
      validate-runner-names: ok (1 targets, 1 workflow(s))
      ##[error]Process completed with exit code 1
    
    The validator passes. The step after it is what fails. A check that is
    permanently red is also a silent one: nothing here has ever been enforced by a
    green run.
    
    ROOT CAUSE
    
    .gitignore line 3 is a bare `test/`. An unanchored directory pattern matches at
    ANY depth, so it covers .github/scripts/test/ as well as the local build scratch
    dir it is grouped with (build*/, cmake-build-*/, .cache/). Whoever added the
    workflow step almost certainly wrote the test file too and git silently refused
    it. None of the other five engine repos carry this rule.
    
    Kept the broad rule rather than anchoring it to /test/ - a nested test/
    elsewhere in the tree may rely on it - and re-included just the CI path. The
    directory itself has to be re-included, because git cannot re-include a file
    whose parent directory is excluded. Verified: test/x.cpp and examples/test/y.cpp
    are both still ignored, .github/scripts/test/ is not.
    
    THE TESTS
    
    Ported from qvac-ext-bergamot-translator, whose lib/runner-names.mjs is
    identical to this one apart from the repo name and the ADDON_WORKFLOWS set, and
    which is hosted-only like this repo. Adapted to this catalog (windows_2022),
    plus two assertions specific to it:
    
    - The catalog stays hosted-only. This repo runs entirely on GitHub images and
      has no reusable-authorize-self-hosted.yml, so a self-hosted entry appearing
      here would put fork PRs on a self-hosted runner with no fork-ci gate. The
      self-hosted engine repos all carry that gate; this one has nothing to carry
      it with. Checked the guard fires rather than passing vacuously.
    - The validated allowlist is non-empty and still contains build.yml. A wired
      workflow missing from ADDON_WORKFLOWS is not checked at all, which would make
      every other assertion in this file vacuous.
    
      node --test .github/scripts/test/runner-names.test.mjs -> 11 passed, 0 failed
      node .github/scripts/validate-runner-names.mjs -> ok (1 targets, 1 workflow(s))
    
    No workflow or catalog change. QVAC-24501's runner repoint does not apply here:
    every runs-on in this repo is ubuntu-latest, macos-latest or windows-2022, so
    there is no unroutable self-hosted label of the kind fixed in fabric-llm and
    ext-ggml. This closes the guardrail gap instead.
    
    Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
    
    * chore: trim comments to the non-obvious bits
    
    The gitignore rationale belongs in the commit and PR, not inline next to a
    one-line negation. The hosted-only test's comment restated its own name and
    assert message.
    
    Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
    
    ---------
    
    Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
    tobi-legan and claude authored Sep 24, 2026
    Configuration menu
    Copy the full SHA
    54bfafe View commit details
    Browse the repository at this point in the history
Loading