Repository navigation
69 lines (63 loc) · 2.17 KB
/
Copy pathci.yml
File metadata and controls
69 lines (63 loc) · 2.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
name: CI
on:
push:
branches: [main, dev]
pull_request:
workflow_dispatch:
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
permissions:
contents: read
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7.0.1
- name: Install uv
uses: astral-sh/setup-uv@v9.0.0
- name: Export locked runtime dependencies
run: uv export --frozen --no-dev --all-extras --no-emit-project --no-hashes --format requirements-txt -o audit-requirements.txt
# The export is already a fully resolved tree, so --no-deps audits the pins
# directly without a hash-checked reinstall of platform-specific wheels.
- name: Audit dependencies for known vulnerabilities
run: uvx pip-audit --strict --no-deps --requirement audit-requirements.txt
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7.0.1
with:
fetch-depth: 0
- name: Install uv
uses: astral-sh/setup-uv@v9.0.0
- name: Lint
run: uv run ruff check .
- name: Format check
run: uv run ruff format --check .
- name: Test with coverage
run: uv run pytest
- name: Upload coverage report
if: always()
uses: actions/upload-artifact@v7
with:
name: coverage-report
path: coverage.xml
sonar:
needs: test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7.0.1
with:
fetch-depth: 0
- name: Download coverage report
uses: actions/download-artifact@v8
with:
name: coverage-report
- name: SonarCloud Scan
if: github.event_name != 'pull_request' || github.event.pull_request.user.login != 'dependabot[bot]'
uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
- name: Skip SonarCloud scan for Dependabot
if: github.event_name == 'pull_request' && github.event.pull_request.user.login == 'dependabot[bot]'
run: echo "SonarCloud credentials are unavailable to Dependabot pull requests."