Skip to content

Merge pull request #4567 from verifywise-ai/dependabot/pip/AIGateway/… #178

Merge pull request #4567 from verifywise-ai/dependabot/pip/AIGateway/…

Merge pull request #4567 from verifywise-ai/dependabot/pip/AIGateway/… #178

name: AIGateway Checks
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
on:
pull_request:
branches: ['master', 'develop']
paths:
- 'AIGateway/**'
- '.github/workflows/aigateway-checks.yml'
push:
branches: ['master', 'develop']
paths:
- 'AIGateway/**'
- '.github/workflows/aigateway-checks.yml'
jobs:
aigateway-tests:
name: AIGateway Tests (pytest)
runs-on: ubuntu-latest
timeout-minutes: 20
defaults:
run:
working-directory: AIGateway
steps:
- uses: actions/checkout@v7
- name: Set up Python
uses: actions/setup-python@v7
with:
python-version: '3.12'
cache: 'pip'
cache-dependency-path: AIGateway/requirements.txt
- name: Cache AIGateway virtualenv
uses: actions/cache@v6
with:
path: AIGateway/.venv
key: aigateway-venv-${{ runner.os }}-3.12-${{ hashFiles('AIGateway/requirements.txt') }}
restore-keys: |
aigateway-venv-${{ runner.os }}-3.12-
- name: Create virtualenv
run: |
if [ ! -x .venv/bin/python ]; then
rm -rf .venv
python -m venv .venv
fi
- name: Install AIGateway dependencies
run: |
.venv/bin/python -m pip install --upgrade pip
# presidio-anonymizer 2.2.364 caps cryptography<49.0.0, but VerifyWise requires >=50.0.0.
# Install presidio-anonymizer without deps; its only required dependency is cryptography,
# which is already declared in requirements.txt.
grep -v '^presidio-anonymizer' requirements.txt > /tmp/requirements-install.txt
.venv/bin/python -m pip install -r /tmp/requirements-install.txt
.venv/bin/python -m pip install --no-deps presidio-anonymizer>=2.2.364
.venv/bin/python -m pip install pytest pytest-asyncio
.venv/bin/python -m spacy download en_core_web_md
- name: Audit AIGateway dependencies (pip-audit)
run: |
.venv/bin/python -m pip install pip-audit
# Audit the installed environment so presidio-anonymizer (installed with --no-deps)
# is checked alongside the cryptography>=50.0.0 requirement.
.venv/bin/python -m pip_audit
# Most tests under tests/ are E2E and need a live Express backend,
# gateway, and database (see tests/conftest.py). Run only the
# self-contained subset that passes without live services.
- name: Run self-contained AIGateway tests
env:
DB_USER: test
DB_PASSWORD: test
DB_HOST: localhost
DB_PORT: '5432'
DB_NAME: verifywise_test
AI_GATEWAY_INTERNAL_KEY: test-internal-key-not-real
ENCRYPTION_KEY: default-key-change-this-in-production-32chars!!
OPENAI_API_KEY: sk-test
run: |
.venv/bin/python -m pytest \
tests/test_cache_service.py \
-v