The published checksums named a directory nobody downloaded #285
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: ci | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| # A push to a branch is not a superseded pull-request commit. Keying the group | |
| # on the ref alone gave every commit on `main` ONE shared slot: GitHub allows | |
| # one running plus one pending run per group, so a second push cancels the run | |
| # the first commit was still executing (`cancel-in-progress: true`), and a | |
| # third push evicts the second from the pending slot (`false`). Either way the | |
| # commit lands with no verdict at all, and it is reported as `cancelled` or is | |
| # simply absent -- never as red -- so nothing surfaces it. | |
| # | |
| # The discriminator below gives each pushed commit its own slot while leaving | |
| # pull-request runs grouped per PR, so a superseded PR commit is still | |
| # cancelled. `cancel-in-progress` is deliberately unchanged. | |
| group: ci-${{ github.ref }}-${{ github.event_name == 'pull_request' && 'pr' || github.sha }} | |
| cancel-in-progress: ${{ github.event_name == 'pull_request' }} | |
| jobs: | |
| # Every interpreter `requires-python = ">=3.12"` admits. Declaring support and | |
| # never running it is how three tests came to depend on a 3.12-only recursion | |
| # depth without anything noticing (issue #90). | |
| verify-python: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| python-version: ["3.12", "3.13", "3.14"] | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| # tests/test_release_versions.py reads this repository's tags to check | |
| # what README.md and CITATION.cff claim about releases. The default | |
| # checkout is one commit deep and carries no tags, and reading an empty | |
| # tag list out of that would make every release claim here | |
| # unfalsifiable in the run that gates a merge. Fetch them. | |
| fetch-depth: 0 | |
| fetch-tags: true | |
| - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 | |
| with: | |
| version: "0.11.29" | |
| python-version: ${{ matrix.python-version }} | |
| enable-cache: true | |
| cache-dependency-glob: uv.lock | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| cache: 'npm' | |
| node-version: "24.18.0" | |
| - name: Install locked environment | |
| run: uv sync --locked | |
| - name: Install locked browser-lab dependency | |
| run: npm ci --ignore-scripts | |
| - name: Check every committed browser-lab script | |
| run: make lint-lab | |
| - name: Verify | |
| env: | |
| # Issue #89 built the mechanism and left the switch off. Without this, | |
| # the four tool-dependent gate tests skip themselves when node or uv is | |
| # absent and the suite still reports green -- which is the state the | |
| # issue existed to end. Setting it makes a missing tool fail here. | |
| EXITDRILL_REQUIRE_GATE_TOOLS: "1" | |
| run: make verify | |
| - name: Exercise both declared outcomes and comparison policy | |
| run: make demo-compare-policy | |
| - name: Verify the offline CiviCRM target-roundtrip canary | |
| run: make demo-civicrm-target-canary | |
| # A matrix renames its own check runs, so the branch ruleset's required | |
| # `verify` context would stop being reported. This carries that name and | |
| # fails unless every interpreter above verified. | |
| verify: | |
| needs: [verify-python] | |
| if: always() | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| steps: | |
| - name: Require every declared interpreter to have verified | |
| env: | |
| MATRIX_RESULT: ${{ needs.verify-python.result }} | |
| run: test "$MATRIX_RESULT" = success | |
| package: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 | |
| with: | |
| enable-cache: true | |
| version: "0.11.29" | |
| python-version: "3.12" | |
| - name: Build and smoke-test wheel | |
| run: make package | |
| dependency-scan: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 | |
| with: | |
| enable-cache: true | |
| version: "0.11.29" | |
| python-version: "3.12" | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| cache: 'npm' | |
| node-version: "24.18.0" | |
| - name: Audit locked runtime dependencies | |
| run: | | |
| uv export --locked --no-dev --no-emit-project --no-hashes > /tmp/runtime-requirements.txt | |
| if test -s /tmp/runtime-requirements.txt; then | |
| uvx --from pip-audit==2.10.1 pip-audit --strict --requirement /tmp/runtime-requirements.txt | |
| else | |
| echo "No runtime dependencies to audit." | |
| fi | |
| - name: Audit locked browser-lab dependency | |
| run: | | |
| npm ci --ignore-scripts | |
| npm audit --audit-level=high | |
| secret-scan: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3.0.0 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| sast: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 | |
| with: | |
| enable-cache: true | |
| version: "0.11.29" | |
| python-version: "3.12" | |
| - name: Semgrep | |
| run: >- | |
| uvx --from semgrep==1.168.0 semgrep scan --error --metrics off | |
| --config p/python --config p/nodejs src tests scripts | |
| zizmor: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| permissions: | |
| contents: read | |
| security-events: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - uses: zizmorcore/zizmor-action@70fb788f84895a7701f5643d103d587e460b5c99 # v0.6.3 |