Expand Ruff quality rules #271
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Tests | |
| on: | |
| push: | |
| pull_request: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| validate: | |
| name: Validate (${{ matrix.os }}, Python ${{ matrix.python-version }}) | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: | |
| - macos-latest | |
| - ubuntu-latest | |
| - windows-latest | |
| python-version: ["3.10", "3.11", "3.12", "3.13", "3.14"] | |
| runs-on: ${{ matrix.os }} | |
| timeout-minutes: 10 | |
| defaults: | |
| run: | |
| shell: bash | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Validate repository baseline | |
| run: ./tests/validate.sh | |
| - name: Set up Python | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| - name: Install test dependencies | |
| run: python -m pip install ".[dev,typer]" | |
| - name: Run Python tests | |
| run: python -m pytest | |
| - name: Type-check public contract sample | |
| run: python -m mypy --strict examples/typed_consumer.py | |
| - name: Type-check library | |
| run: python -m mypy --strict lib/python/base_cli | |
| quality: | |
| name: Quality and security gates | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Python | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.13" | |
| - name: Install quality dependencies | |
| run: python -m pip install ".[dev,typer,quality]" | |
| - name: Run formatting and lint checks | |
| run: | | |
| ruff format --check scripts examples | |
| ruff check lib/python/base_cli scripts examples tests | |
| - name: Run strict typing and documentation checks | |
| run: | | |
| python -m mypy --strict examples/typed_consumer.py | |
| python -m mypy --strict lib/python/base_cli | |
| python scripts/validate_docs.py | |
| python scripts/benchmark_runtime.py --check | |
| python -m compileall -q examples | |
| - name: Run tests with coverage threshold | |
| run: python -m pytest --cov=base_cli --cov-report=term-missing --cov-fail-under=80 | |
| - name: Run static security checks | |
| run: | | |
| bandit -q -r lib/python/base_cli scripts -lll -iii | |
| # The project itself is installed from this checkout and may not be | |
| # published to PyPI yet (for example, while validating a release PR). | |
| # Audit every installed third-party package without asking pip-audit | |
| # to resolve the unpublished project distribution. | |
| python -m pip freeze \ | |
| | grep -Eiv '^base-cli([[:space:]]|$)' \ | |
| > "$RUNNER_TEMP/base-cli-audit-requirements.txt" | |
| pip-audit --strict -r "$RUNNER_TEMP/base-cli-audit-requirements.txt" | |
| linux-distributions: | |
| name: Validate (${{ matrix.name }}) | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - name: Debian 12 | |
| image: debian:12-slim | |
| family: debian | |
| - name: Fedora latest | |
| image: fedora:latest | |
| family: fedora | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Run distribution validation in Docker | |
| env: | |
| DISTRO_IMAGE: ${{ matrix.image }} | |
| DISTRO_FAMILY: ${{ matrix.family }} | |
| run: | | |
| docker run --rm \ | |
| --volume "$GITHUB_WORKSPACE:/workspace" \ | |
| --workdir /workspace \ | |
| --env DISTRO_FAMILY \ | |
| "$DISTRO_IMAGE" \ | |
| sh -lc ' | |
| set -eu | |
| if [ "$DISTRO_FAMILY" = debian ]; then | |
| apt-get update | |
| DEBIAN_FRONTEND=noninteractive apt-get install -y bash python3 python3-pip python3-venv | |
| else | |
| dnf install -y python3 python3-pip | |
| fi | |
| ./tests/validate.sh | |
| python3 -m venv /tmp/base-cli-venv | |
| /tmp/base-cli-venv/bin/python -m pip install ".[dev,typer]" | |
| /tmp/base-cli-venv/bin/python -m pytest | |
| /tmp/base-cli-venv/bin/python -c "import base_cli; print(base_cli.__version__)" | |
| ' | |
| wsl: | |
| name: Validate (WSL) | |
| runs-on: windows-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Validate repository baseline inside WSL | |
| shell: pwsh | |
| run: | | |
| $distros = (wsl --list --quiet 2>$null | Out-String) | |
| if ($distros -notmatch "Ubuntu") { | |
| wsl --install --distribution Ubuntu --no-launch | |
| } | |
| $drive = $env:GITHUB_WORKSPACE.Substring(0, 1).ToLowerInvariant() | |
| $path = $env:GITHUB_WORKSPACE.Substring(2).Replace('\', '/') | |
| $linuxWorkspace = "/mnt/$drive$path" | |
| wsl --distribution Ubuntu --user root -- bash -lc "set -eu; cd '$linuxWorkspace'; sed -i 's/\r$//' tests/validate.sh; bash tests/validate.sh; python3 --version" |