[Snyk] Security upgrade react-router from 7.7.1 to 7.14.1 #62
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This is a GitHub workflow defining a set of jobs with a set of steps. | |
| # ref: https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions | |
| # | |
| # Test build release artifacts (PyPI package) and publish them on | |
| # pushed git tags. | |
| # | |
| name: Release | |
| on: | |
| pull_request: | |
| paths-ignore: | |
| - "docs/**" | |
| - "**.md" | |
| - "**.rst" | |
| - ".github/workflows/*" | |
| - "!.github/workflows/release.yml" | |
| push: | |
| paths-ignore: | |
| - "docs/**" | |
| - "**.md" | |
| - "**.rst" | |
| - ".github/workflows/*" | |
| - "!.github/workflows/release.yml" | |
| branches-ignore: | |
| - "dependabot/**" | |
| - "pre-commit-ci-update-config" | |
| tags: | |
| - "**" | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| build-release: | |
| runs-on: ubuntu-22.04 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| cache: pip | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| - name: install build requirements | |
| run: | | |
| npm install -g yarn | |
| pip install --upgrade pip | |
| pip install build | |
| pip freeze | |
| - name: build release | |
| run: | | |
| python -m build --sdist --wheel . | |
| ls -l dist | |
| - name: verify sdist | |
| run: | | |
| ./ci/check_sdist.py dist/jupyterhub-*.tar.gz | |
| - name: verify data-files are installed where they are found | |
| run: | | |
| pip install dist/*.whl | |
| ./ci/check_installed_data.py | |
| - name: verify sdist can be installed without npm/yarn | |
| run: | | |
| docker run --rm -v $PWD/dist:/dist:ro docker.io/library/python:3.9-slim-bullseye bash -c 'pip install /dist/jupyterhub-*.tar.gz' | |
| # ref: https://github.com/actions/upload-artifact#readme | |
| - uses: actions/upload-artifact@v4 | |
| with: | |
| name: jupyterhub-${{ github.sha }} | |
| path: "dist/*" | |
| if-no-files-found: error | |
| - name: Publish to PyPI | |
| if: startsWith(github.ref, 'refs/tags/') | |
| env: | |
| TWINE_USERNAME: __token__ | |
| TWINE_PASSWORD: ${{ secrets.PYPI_PASSWORD }} | |
| run: | | |
| pip install twine | |
| twine upload --skip-existing dist/* |