Repository navigation
ci: give only the badge deploy write access; drop the duplicate tox run - #282
Merged
Merged
Conversation
coverage.yml granted contents: write to the whole workflow, including the job that installs dependencies and runs the test suite on every pull request. The workflow is now read-only, and the deploy is a separate push-only job that is the only one with write access. It publishes just coverage.svg; earlier deploys published the whole checkout to the coverage-badge branch, and clean: true removes those leftovers. tox.yml ran the same 3.10-3.14 suites as test.yml, against the same lockfile, extras and live servers, only serially in one job. test.yml stays as the single matrix run; tox remains for local use. Closes #193
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #193
Part of #124.
coverage.yml: only the badge deploy can write
Until now,
contents: writeapplied to the whole workflow. That included the job that installs dependencies and runs the test suite on every pull request from this repository.Changes:
contents: read.badgejob.coverage.contents: write.coverage.svgfrom thecoveragejob as an artifact. The artifact is uploaded on pushes only and kept for one day.coverage-badgeconcurrency group, so deploys from back-to-back pushes do not race on the branch.folder: ., which is the whole checkout. Thecoverage-badgebranch therefore holds a copy of the source tree next tocoverage.svg, including files master deleted long ago.clean: true, the first deploy after this merges leaves onlycoverage.svgon that branch. The README badge reads only that file.genbadge[coverage]is now quoted in the shell step (shellcheck SC2102; the brackets are a glob).test.yml vs tox.yml: one matrix run
tox.ymlranuv run toxon one runner, which runs py310 through py314 one after another. Each env:uv-venv-lock-runner, which runsuv sync --lockedwith the default dev group (PyJWT included);redisandmemcachedextras;That is the same set of versions, packages and servers as the
test.ymlmatrix.test.ymlalso runs each version as a separate job, which is faster and makes failures easier to read.Roles after this PR:
test.yml)contents: readexplicitly. Its README badge is unchanged.coverage.yml)tox.ini)docs/DEVELOPMENT.mdsays so.tox.ymlis removed.The trade-off is that nothing in CI exercises
tox.iniitself any more, so a brokentox.iniwould surface only in a local run.A run against the lowest supported dependency versions (#194) fits as a separate job in
test.yml. A comment above the matrix job marks the spot.Verification
actionlint1.7.12 with shellcheck, over all six workflow files in the branch (coverage.yml,docs.yml,lint.yml,release.yml,renovate-validate.yml,test.yml): no findings. The SC2102 finding it reports on master'scoverage.ymlis gone.uv run tox -e py314works locally. It confirms what the tox env installs:uv sync --locked --extra memcached --extra redis, with the dev group, so PyJWT and pytest are included.zensical build --strictfor the English docs passes.DEVELOPMENT.mdhas no zh-TW copy.uv lock --checkpasses.badgejob. The first real deploy is the push to master after merging. What to check then:coverage-badgebranch holds onlycoverage.svg;CHANGELOG
None: CI only.