Skip to content

chore: bump aces-sdl from 0.20.0 to 0.23.1 #79

chore: bump aces-sdl from 0.20.0 to 0.23.1

chore: bump aces-sdl from 0.20.0 to 0.23.1 #79

Workflow file for this run

name: CI
on:
push:
branches: [main, dev]
pull_request:
workflow_dispatch:
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Install uv
uses: astral-sh/setup-uv@v8.3.2
- name: Export locked runtime dependencies
run: uv export --frozen --no-dev --all-extras --no-emit-project --no-hashes --format requirements-txt -o audit-requirements.txt
# The export is already a fully resolved tree, so --no-deps audits the pins
# directly without a hash-checked reinstall of platform-specific wheels.
- name: Audit dependencies for known vulnerabilities
run: uvx pip-audit --strict --no-deps --requirement audit-requirements.txt
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Install uv
uses: astral-sh/setup-uv@v8.3.2
- name: Lint
run: uv run ruff check .
- name: Format check
run: uv run ruff format --check .
- name: Test with coverage
run: uv run pytest
- name: Upload coverage report
if: always()
uses: actions/upload-artifact@v7
with:
name: coverage-report
path: coverage.xml
sonar:
needs: test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Download coverage report
uses: actions/download-artifact@v4
with:
name: coverage-report
- name: SonarCloud Scan
uses: SonarSource/sonarqube-scan-action@713881670b6b3676cda39549040e2d88c70d582e # v8
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}