Repository navigation
Chore(deps-dev): Bump ruff from 0.16.8 to 0.16.10 in /examples/otlp #54
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| workflow_dispatch: | |
| # The repository is public and nothing here publishes, comments or deploys. | |
| permissions: | |
| contents: read | |
| # Supersede in-flight PR runs; never cancel a run for a commit on main. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| env: | |
| # Every uv invocation in this workflow resolves from the committed lock file | |
| # or fails. A gate that silently re-resolves proves nothing about what ships. | |
| UV_LOCKED: "1" | |
| PYTHONDONTWRITEBYTECODE: "1" | |
| jobs: | |
| # The whole gate, on the floor of the supported range and on the newest | |
| # release. mise.toml owns the tool versions; nothing is re-pinned here. | |
| gate: | |
| name: gate (${{ matrix.python }}) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| python: ["3.12", "3.14"] | |
| env: | |
| UV_PYTHON: "${{ matrix.python }}" | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| # mise.toml is the single source of truth for uv and gitleaks. uv, not a | |
| # second action, is what installs the interpreter, so the version this job | |
| # runs on is decided in one place. | |
| - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | |
| - name: Install and pin Python ${{ matrix.python }} | |
| run: | | |
| uv python install "${UV_PYTHON}" | |
| uv python pin "${UV_PYTHON}" | |
| mise run sync | |
| # fmt-check, gen-check, ruff, pyright, pylint, pytest, build + twine, | |
| # pip-audit. The live tests are deselected by addopts and nothing here | |
| # passes -m live, so no API key is ever needed. | |
| - name: mise run check | |
| run: mise run check | |
| # `twine check` reads the metadata; it never installs anything. This takes | |
| # the wheel the gate just built, puts it in an empty environment with no | |
| # source tree to fall back on, and imports it. Nothing else proves that | |
| # what a user downloads works, or that py.typed survived the build. | |
| - name: Install the built wheel and import it | |
| run: | | |
| uv venv /tmp/wheel-check | |
| VIRTUAL_ENV=/tmp/wheel-check uv pip install dist/*.whl | |
| cd /tmp | |
| /tmp/wheel-check/bin/python - <<'PY' | |
| import pathlib | |
| import guideme | |
| assert guideme.Guide | |
| installed = pathlib.Path(guideme.__file__).parent | |
| marker = installed / "py.typed" | |
| assert marker.is_file(), f"no py.typed in {installed}" | |
| print(f"imported {installed}; py.typed present") | |
| PY | |
| # The tracked pre-commit and pre-push hooks scan for secrets, but a hook is | |
| # opt-in and local. This is the copy that runs on every pull request, fork | |
| # included, and on every commit that reaches main. | |
| secrets: | |
| name: secrets (gitleaks) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| # The whole history: a secret on any commit is a leak, however old. | |
| fetch-depth: 0 | |
| # gitleaks' version comes from mise.toml, same as the hooks use. | |
| - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | |
| # Exit 2 is a leak, exit 1 is gitleaks failing to run. Both fail the job. | |
| - name: gitleaks over the full history | |
| run: gitleaks git --no-banner --redact --exit-code 2 | |
| # examples/otlp is its own uv project with its own lock file, so the root | |
| # gate never resolves it. --locked is the point: it fails when guideme moves | |
| # under the example instead of silently resolving around it. | |
| example: | |
| name: example (otlp) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| defaults: | |
| run: | |
| working-directory: examples/otlp | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | |
| - name: uv sync --locked | |
| run: uv sync --locked | |
| - name: ruff format --check | |
| run: uv run --locked ruff format --check . | |
| - name: ruff check | |
| run: uv run --locked ruff check . | |
| - name: pyright | |
| run: uv run --locked pyright | |
| # requires-python claims >= 3.12, so 3.12.0 is what has to run. The assert | |
| # is there because UV_PYTHON is easy to lose: a job that quietly ran 3.12.13 | |
| # would prove nothing about the floor. | |
| min-python: | |
| name: min-python (3.12.0) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| env: | |
| UV_PYTHON: "3.12.0" | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | |
| - name: Install and pin Python 3.12.0 | |
| run: | | |
| uv python install 3.12.0 | |
| uv python pin 3.12.0 | |
| uv sync --locked --all-groups | |
| - name: Assert the floor and run the suite on it | |
| run: | | |
| uv run --locked python -c "import sys; assert sys.version_info[:3] == (3, 12, 0), sys.version" | |
| uv run --locked pytest | |
| # Every other job resolves from uv.lock, which pins opentelemetry-api at the | |
| # floor of the range pyproject allows. The range users actually install is | |
| # therefore never exercised, and the logs API this package reaches for lives at | |
| # the private `opentelemetry._logs`. This job resolves the dependencies fresh, | |
| # ignoring the lock, so a release that moves something is seen here first. | |
| # | |
| # `uv sync --upgrade` is what re-resolves. `uv run --resolution highest` does | |
| # not: the committed lock already records the `highest` mode, so uv reuses it | |
| # and the job would silently test the pinned versions again. Measured against a | |
| # lock holding a deliberately stale certifi -- `--upgrade` moved it, the other | |
| # kept it. | |
| # | |
| # Deliberately NOT in the required-checks ruleset: a third party's release | |
| # should never block a merge here. It is an early warning, and a failure is a | |
| # ticket, not a gate. | |
| latest-deps: | |
| name: latest-deps (unpinned) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| env: | |
| # The workflow-wide UV_LOCKED=1 is the opposite of this job's purpose. It has | |
| # to be turned off with a value uv can parse: an empty string is rejected as | |
| # `expected a boolish value`, not read as unset. | |
| UV_LOCKED: "0" | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | |
| - name: Resolve every dependency at its newest allowed version | |
| run: uv sync --upgrade --all-groups | |
| # uv prints "Resolved N packages" whether it re-resolved or reused the lock, | |
| # so that line is not the proof. This one is: it reads the committed lock out | |
| # of git, because `--upgrade` has already rewritten the copy on disk, and | |
| # prints what the lock pins beside what the job resolved. Equal today, since | |
| # every runtime dependency is pinned at a floor that is also its newest | |
| # release; the day one moves, this step says so in one line, and a reader six | |
| # months from now can tell the job did its job either way. | |
| # | |
| # It is a file under scripts/, not a heredoc, so ruff, pyright strict and | |
| # pylint check it like everything else this repository runs. | |
| - name: What it resolved, against what the lock pins | |
| run: uv run --no-sync python scripts/resolved_vs_lock.py | |
| - name: Everything it resolved | |
| run: uv pip list | |
| # The import is the half that a moved `opentelemetry._logs` would break for | |
| # every user, traces included; the tracing suite is the half that proves the | |
| # logs signal still emits what docs/observability.md documents. | |
| - name: import guideme | |
| run: uv run --no-sync python -c "import guideme; print(guideme.Guide)" | |
| - name: pytest tests/test_tracing.py | |
| run: uv run --no-sync pytest tests/test_tracing.py | |
| # spec/ is vendored from guideme-rust. This is the check the main ruleset | |
| # requires; advisories.yml re-runs it weekly so drift is caught between PRs. | |
| spec-drift: | |
| name: spec-drift | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0 | |
| - name: mise run spec-check | |
| run: mise run spec-check |