-
Notifications
You must be signed in to change notification settings - Fork 1
43 lines (43 loc) · 2.16 KB
/
Copy pathci.yml
File metadata and controls
43 lines (43 loc) · 2.16 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
# wads CI — calls the reusable workflow hosted in i2mint/wads.
#
# All configuration comes from this repo's pyproject.toml [tool.wads.ci.*].
# To customize the workflow itself (rare), replace this file with the
# full inline template `wads/data/github_ci_uv.yml` from i2mint/wads.
#
# Pinning: `@master` floats with wads. If you need version stability for
# a release-sensitive repo, change `@master` to a wads tag (e.g. `@0.2.15`;
# tags have no `v` prefix). A stub whose `secrets:` block passes the JSON
# transport (the default below) needs a tag from a release after 0.2.14 —
# older tags don't declare that secret and GitHub then rejects the
# workflow at parse time.
# CI failure does not block a published release — it blocks the publish
# step itself — so floating master is generally safe.
#
# Permissions: GitHub validates that the caller grants AT LEAST the
# permissions any job in the called workflow requests — at workflow-parse
# time, not at run-time, even if the job would be skipped via `if:`.
# The reusable workflow needs:
# contents: write for the publish job's version-bump push-back
# and for the github-pages job's gh-pages branch push
# pages: write for the github-pages job's REST API Pages config
# Both default to `write` on org-account GITHUB_TOKEN and need to be
# granted explicitly on personal-account callers (where the default is
# read-only). No `id-token: write` needed — the publish-github-pages
# action uses peaceiris/actions-gh-pages (branch-based) + REST API,
# not the OIDC `actions/deploy-pages` flow.
name: Continuous Integration
on: [push, pull_request]
jobs:
ci:
uses: i2mint/wads/.github/workflows/uv-ci.yml@master
permissions:
contents: write
pages: write
# Transport (NAMED, legacy): explicitly passes only the secrets
# listed below (PYPI_PASSWORD + those declared in
# [tool.wads.ci.env]). Every name must be in the frozen wads
# superset (wads/ci_secrets.py) or GitHub rejects the workflow
# at parse time. The default JSON transport has no such limit;
# regenerate with `wads-migrate ci-to-stub` to switch.
secrets:
PYPI_PASSWORD: ${{ secrets.PYPI_PASSWORD }}