Merge pull request #193 from Manishrdy/fix/admin-brand-links-home #224
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI/CD Pipeline | |
| on: | |
| push: | |
| branches: [ main, develop ] | |
| pull_request: | |
| branches: [ main, develop ] | |
| workflow_dispatch: | |
| jobs: | |
| lint: | |
| name: Code Quality | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Set up Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: '3.11' | |
| - name: Install dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -r requirements.txt | |
| - name: Run flake8 | |
| continue-on-error: true | |
| run: | | |
| # Exclude venv and cache directories to avoid linting third-party code | |
| flake8 . --count --select=E9,F63,F7,F82 --show-source --statistics \ | |
| --exclude=venv,.venv,env,__pycache__,*.egg-info | |
| flake8 . --count --exit-zero --max-complexity=10 --max-line-length=127 --statistics \ | |
| --exclude=venv,.venv,env,__pycache__,*.egg-info | |
| - name: Check formatting with black | |
| continue-on-error: true | |
| run: | | |
| black --check --diff . | |
| - name: Check import order with isort | |
| continue-on-error: true | |
| run: | | |
| isort --check-only --diff . | |
| security: | |
| name: Security Scan | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Set up Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: '3.11' | |
| - name: Install dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -r requirements.txt | |
| - name: Run safety check | |
| continue-on-error: true | |
| run: | | |
| safety check --json | |
| - name: Run bandit security check | |
| continue-on-error: true | |
| run: | | |
| bandit -r . -f json -o bandit-report.json || true | |
| - name: Upload security reports | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: security-reports | |
| path: | | |
| bandit-report.json |