-
Notifications
You must be signed in to change notification settings - Fork 6
117 lines (102 loc) · 3.93 KB
/
Copy pathcoverage.yml
File metadata and controls
117 lines (102 loc) · 3.93 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
name: Coverage Badge
on:
push:
branches: [ "master" ]
paths:
- '**.py'
- 'pyproject.toml'
- '.github/workflows/coverage.yml'
# No paths filter on pull requests, so this check can be required before
# merging: a required check that never starts blocks the pull request. It
# also covers pull requests that only touch files outside the push filter,
# such as CHANGELOG.md, whose format tests/test_changelog_release.py checks.
pull_request:
branches: [ "master" ]
# Only the badge job below writes, and it runs only on pushes to master.
permissions:
contents: read
jobs:
coverage:
runs-on: ubuntu-latest
services:
memcached:
image: memcached:1.6-alpine
ports:
- 11211:11211
redis:
image: redis:alpine
ports:
- 6379:6379
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.14"
- name: Install uv
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
- name: Sync dependencies
run: uv sync
- name: Generate coverage report
run: |
uv run coverage run -m pytest
uv run coverage report
uv run coverage xml
uv tool run --from "genbadge[coverage]" genbadge coverage -i coverage.xml -o coverage.svg
env:
# The suites that talk to a real server are opt-in: they wipe what they
# connect to, so they skip unless a port is named. These are the service
# containers above, which exist only for this job.
CACHEX_TEST_REDIS_PORT: 6379
CACHEX_TEST_MEMCACHED_PORT: 11211
# ...and here the services are this workflow's own responsibility, so a
# skipped suite is a broken job, not a safe default. Without this a
# wrong port silently drops those tests and the run is still green:
# coverage stays near 97%, well over the 90% gate.
CACHEX_REQUIRE_LIVE_SERVERS: 1
- name: Keep the badge for the deploy job
if: github.event_name == 'push'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: coverage-badge
path: coverage.svg
if-no-files-found: error
retention-days: 1
badge:
# Only a push to master updates the badge. A pull request's coverage is
# not master's, and a fork's pull request gets a read-only token, so the
# push would fail with 403 and turn the check red. The deploy runs in its
# own job so that the write permission never reaches the job that runs
# the tests.
needs: coverage
if: github.event_name == 'push'
runs-on: ubuntu-latest
permissions:
contents: write
# Deploy in push order; two deploys at once race on the branch.
concurrency:
group: coverage-badge
cancel-in-progress: false
steps:
# The deploy action runs git in the workspace, so it needs a checkout. It
# does not need the checkout's credentials: it drops the checkout's auth
# header and pushes to a remote URL built from its own `token` input
# (the job's GITHUB_TOKEN by default).
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Download coverage badge
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: coverage-badge
path: badge
- name: Upload coverage badge
uses: JamesIves/github-pages-deploy-action@fa24774553152dd7873cd16ebd8d959b010c5445 # v4.9.0
with:
branch: coverage-badge
# Only the badge. `clean` removes what earlier deploys left there:
# they published the whole checkout, not just coverage.svg.
folder: badge
clean: true