Skip to content

ci: give only the badge deploy write access; drop the duplicate tox run - #282

Merged
allen0099 merged 1 commit into
masterfrom
ci/coverage-permissions-test-matrix-193
Sep 27, 2026
Merged

allen0099 merged 1 commit into
masterfrom
ci/coverage-permissions-test-matrix-193

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Summary

Closes #193

Part of #124.

coverage.yml: only the badge deploy can write

Until now, contents: write applied to the whole workflow. That included the job that installs dependencies and runs the test suite on every pull request from this repository.

Changes:

  • The workflow is now contents: read.
  • The deploy moved into its own badge job.
    • It runs only on a push to master, after coverage.
    • It is the only job with contents: write.
    • It gets coverage.svg from the coverage job as an artifact. The artifact is uploaded on pushes only and kept for one day.
    • It has a coverage-badge concurrency group, so deploys from back-to-back pushes do not race on the branch.
  • The deploy now publishes only the badge.
    • Before, it deployed folder: ., which is the whole checkout. The coverage-badge branch therefore holds a copy of the source tree next to coverage.svg, including files master deleted long ago.
    • With clean: true, the first deploy after this merges leaves only coverage.svg on that branch. The README badge reads only that file.
  • genbadge[coverage] is now quoted in the shell step (shellcheck SC2102; the brackets are a glob).

test.yml vs tox.yml: one matrix run

tox.yml ran uv run tox on one runner, which runs py310 through py314 one after another. Each env:

  • uses uv-venv-lock-runner, which runs uv sync --locked with the default dev group (PyJWT included);
  • adds the redis and memcached extras;
  • runs against the same live Redis/Memcached services.

That is the same set of versions, packages and servers as the test.yml matrix. test.yml also runs each version as a separate job, which is faster and makes failures easier to read.

Roles after this PR:

Workflow Role
Test (test.yml) The one CI run of the 3.10–3.14 matrix, with live servers. Now declares contents: read explicitly. Its README badge is unchanged.
Coverage Badge (coverage.yml) 3.14 coverage report (gate 90%). Badge deploy on push.
tox (tox.ini) Local use only. docs/DEVELOPMENT.md says so. tox.yml is removed.

The trade-off is that nothing in CI exercises tox.ini itself any more, so a broken tox.ini would surface only in a local run.

A run against the lowest supported dependency versions (#194) fits as a separate job in test.yml. A comment above the matrix job marks the spot.

Verification

  • actionlint 1.7.12 with shellcheck, over all six workflow files in the branch (coverage.yml, docs.yml, lint.yml, release.yml, renovate-validate.yml, test.yml): no findings. The SC2102 finding it reports on master's coverage.yml is gone.
  • uv run tox -e py314 works locally. It confirms what the tox env installs: uv sync --locked --extra memcached --extra redis, with the dev group, so PyJWT and pytest are included.
  • zensical build --strict for the English docs passes. DEVELOPMENT.md has no zh-TW copy.
  • pre-commit passes, and uv lock --check passes.
  • A pull request cannot run the badge job. The first real deploy is the push to master after merging. What to check then:
    • the coverage-badge branch holds only coverage.svg;
    • the README badge still renders.

CHANGELOG

None: CI only.

coverage.yml granted contents: write to the whole workflow, including the
job that installs dependencies and runs the test suite on every pull
request. The workflow is now read-only, and the deploy is a separate
push-only job that is the only one with write access. It publishes just
coverage.svg; earlier deploys published the whole checkout to the
coverage-badge branch, and clean: true removes those leftovers.

tox.yml ran the same 3.10-3.14 suites as test.yml, against the same
lockfile, extras and live servers, only serially in one job. test.yml
stays as the single matrix run; tox remains for local use.

Closes #193
@allen0099 allen0099 added the enhancement New feature or request label Sep 27, 2026
@allen0099
allen0099 merged commit ae6fbde into master Sep 27, 2026
11 checks passed
@allen0099
allen0099 deleted the ci/coverage-permissions-test-matrix-193 branch September 27, 2026 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: scope coverage.yml write permission, reduce test/tox overlap

1 participant