Bump python from 3.13-slim to 3.14-slim #5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Python AI Vision Service for face recognition | |
| on: | |
| push: | |
| branches: | |
| - master | |
| paths: | |
| - '.github/workflows/CICD.yaml' | |
| - '**/*.py' | |
| - 'pyproject.toml' | |
| - 'uv.lock' | |
| - 'Dockerfile' | |
| pull_request: | |
| paths: | |
| - '.github/workflows/CICD.yaml' | |
| - '**/*.py' | |
| - 'pyproject.toml' | |
| - 'uv.lock' | |
| - 'Dockerfile' | |
| workflow_dispatch: | |
| # Declare default permissions as read only. | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ !contains(github.ref, 'master') && !startsWith(github.ref, 'refs/tags/') }} | |
| jobs: | |
| # --------------------------------------------------------------------------- | |
| # Lint – formatting and style | |
| # --------------------------------------------------------------------------- | |
| lint: | |
| name: Lint (ruff) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Harden Runner | |
| uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 | |
| with: | |
| egress-policy: audit | |
| - name: Checkout code | |
| uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - name: Set up uv | |
| uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 | |
| with: | |
| enable-cache: true | |
| - name: Install dev dependencies | |
| run: uv sync --frozen | |
| - name: Check formatting | |
| run: uv run ruff format --check app/ tests/ | |
| - name: Lint | |
| run: uv run ruff check app/ tests/ | |
| # --------------------------------------------------------------------------- | |
| # Type check | |
| # --------------------------------------------------------------------------- | |
| typecheck: | |
| name: Type check (ty) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Harden Runner | |
| uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 | |
| with: | |
| egress-policy: audit | |
| - name: Checkout code | |
| uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - name: Set up uv | |
| uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 | |
| with: | |
| enable-cache: true | |
| - name: Install dev dependencies | |
| run: uv sync --frozen | |
| - name: Type check | |
| run: uv run ty check app/ | |
| # --------------------------------------------------------------------------- | |
| # Test matrix – Python 3.13 and 3.14 | |
| # --------------------------------------------------------------------------- | |
| test: | |
| name: Tests (Python ${{ matrix.python-version }}) | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| python-version: | |
| - "3.13" | |
| steps: | |
| - name: Harden Runner | |
| uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 | |
| with: | |
| egress-policy: audit | |
| - name: Checkout code | |
| uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - name: Set up uv | |
| uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 | |
| with: | |
| enable-cache: true | |
| python-version: ${{ matrix.python-version }} | |
| - name: Install dev dependencies | |
| run: uv sync --frozen | |
| - name: Run tests | |
| run: uv run pytest --cov=app --cov-report=xml -v | |
| - name: Upload coverage | |
| if: matrix.python-version == '3.13' | |
| uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 | |
| with: | |
| files: ai-vision-service/face-recognition/coverage.xml | |
| flags: ai-vision-service/face-recognition | |
| continue-on-error: true | |
| # --------------------------------------------------------------------------- | |
| # Docker build verification | |
| # --------------------------------------------------------------------------- | |
| docker-build: | |
| name: Docker build | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Harden Runner | |
| uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4 | |
| with: | |
| egress-policy: audit | |
| - name: Checkout code | |
| uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 #v4.1.0 | |
| - name: Build Docker image (no model bake in CI to save time) | |
| uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0 | |
| with: | |
| context: . | |
| push: false | |
| load: true | |
| tags: lychee-ai-vision:ci | |
| # Override the model-bake step by targeting the builder stage | |
| # to avoid downloading 300MB of model weights in CI. | |
| target: builder | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max |