Skip to content

The published checksums named a directory nobody downloaded #285

The published checksums named a directory nobody downloaded

The published checksums named a directory nobody downloaded #285

Workflow file for this run

name: ci
on:
push:
branches: [main]
pull_request:
permissions:
contents: read
concurrency:
# A push to a branch is not a superseded pull-request commit. Keying the group
# on the ref alone gave every commit on `main` ONE shared slot: GitHub allows
# one running plus one pending run per group, so a second push cancels the run
# the first commit was still executing (`cancel-in-progress: true`), and a
# third push evicts the second from the pending slot (`false`). Either way the
# commit lands with no verdict at all, and it is reported as `cancelled` or is
# simply absent -- never as red -- so nothing surfaces it.
#
# The discriminator below gives each pushed commit its own slot while leaving
# pull-request runs grouped per PR, so a superseded PR commit is still
# cancelled. `cancel-in-progress` is deliberately unchanged.
group: ci-${{ github.ref }}-${{ github.event_name == 'pull_request' && 'pr' || github.sha }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
# Every interpreter `requires-python = ">=3.12"` admits. Declaring support and
# never running it is how three tests came to depend on a 3.12-only recursion
# depth without anything noticing (issue #90).
verify-python:
runs-on: ubuntu-latest
timeout-minutes: 30
strategy:
fail-fast: false
matrix:
python-version: ["3.12", "3.13", "3.14"]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# tests/test_release_versions.py reads this repository's tags to check
# what README.md and CITATION.cff claim about releases. The default
# checkout is one commit deep and carries no tags, and reading an empty
# tag list out of that would make every release claim here
# unfalsifiable in the run that gates a merge. Fetch them.
fetch-depth: 0
fetch-tags: true
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
version: "0.11.29"
python-version: ${{ matrix.python-version }}
enable-cache: true
cache-dependency-glob: uv.lock
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
cache: 'npm'
node-version: "24.18.0"
- name: Install locked environment
run: uv sync --locked
- name: Install locked browser-lab dependency
run: npm ci --ignore-scripts
- name: Check every committed browser-lab script
run: make lint-lab
- name: Verify
env:
# Issue #89 built the mechanism and left the switch off. Without this,
# the four tool-dependent gate tests skip themselves when node or uv is
# absent and the suite still reports green -- which is the state the
# issue existed to end. Setting it makes a missing tool fail here.
EXITDRILL_REQUIRE_GATE_TOOLS: "1"
run: make verify
- name: Exercise both declared outcomes and comparison policy
run: make demo-compare-policy
- name: Verify the offline CiviCRM target-roundtrip canary
run: make demo-civicrm-target-canary
# A matrix renames its own check runs, so the branch ruleset's required
# `verify` context would stop being reported. This carries that name and
# fails unless every interpreter above verified.
verify:
needs: [verify-python]
if: always()
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Require every declared interpreter to have verified
env:
MATRIX_RESULT: ${{ needs.verify-python.result }}
run: test "$MATRIX_RESULT" = success
package:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
enable-cache: true
version: "0.11.29"
python-version: "3.12"
- name: Build and smoke-test wheel
run: make package
dependency-scan:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
enable-cache: true
version: "0.11.29"
python-version: "3.12"
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
cache: 'npm'
node-version: "24.18.0"
- name: Audit locked runtime dependencies
run: |
uv export --locked --no-dev --no-emit-project --no-hashes > /tmp/runtime-requirements.txt
if test -s /tmp/runtime-requirements.txt; then
uvx --from pip-audit==2.10.1 pip-audit --strict --requirement /tmp/runtime-requirements.txt
else
echo "No runtime dependencies to audit."
fi
- name: Audit locked browser-lab dependency
run: |
npm ci --ignore-scripts
npm audit --audit-level=high
secret-scan:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3.0.0
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
sast:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
enable-cache: true
version: "0.11.29"
python-version: "3.12"
- name: Semgrep
run: >-
uvx --from semgrep==1.168.0 semgrep scan --error --metrics off
--config p/python --config p/nodejs src tests scripts
zizmor:
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
security-events: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: zizmorcore/zizmor-action@70fb788f84895a7701f5643d103d587e460b5c99 # v0.6.3