afterhours-shift-manager/.github/workflows/ci.yaml
dependabot[bot] 5704e27f33
Some checks are pending
Deploy API / Deploy API to dev (push) Waiting to run
Deploy API / Deploy API to prod (push) Waiting to run
chore(deps): bump pyjwt from 2.14.0 to 2.15.0 in /tests in the pip group across 1 directory (#289)
* chore(deps): bump pyjwt in /tests in the pip group across 1 directory

Bumps the pip group with 1 update in the /tests directory: [pyjwt](https://github.com/jpadilla/pyjwt).


Updates `pyjwt` from 2.14.0 to 2.15.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix: update org workflow SHA pins to latest version

* test(infra): expect org workflow pins at v1.0.21

The contract tests still asserted the v1.0.19 SHA after the workflow pin bump, so CI failed on the PyJWT bump PR.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-10-02 22:09:58 +00:00

106 lines
3.4 KiB
YAML

name: CI
on:
pull_request:
branches: [main, hotfix/**, release/**]
merge_group:
push:
branches: [hotfix/**, release/**]
permissions:
contents: read
jobs:
autofix:
if: github.event_name == 'pull_request' && !github.event.pull_request.head.repo.fork
uses: Sea-Haven-Industries/.github/.github/workflows/ci-autofix.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21
permissions:
contents: write
secrets: inherit
with:
presets: ruff,terraform
terraform-version: "1.16.0"
lint:
needs: autofix
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21
with:
python-version: "3.12"
test:
needs: autofix
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Install test dependencies
run: |
set -euo pipefail
python -m pip install --upgrade pip
pip install -r tests/requirements.txt
pip install -r src/slack-bot/requirements.txt
pip install -r src/weekly-post/requirements.txt
pip install -r src/shared/requirements.txt
pip install -r src/portal-api/requirements.txt
pip install -r requirements-api.txt
- name: Pytest
run: pytest
terraform:
needs: autofix
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
uses: Sea-Haven-Industries/.github/.github/workflows/ci-terraform.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21
with:
terraform-version: "1.16.0"
openapi:
name: OpenAPI
needs: autofix
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24.19.0"
cache: npm
- name: Install JavaScript tooling
run: npm ci
- name: Lint OpenAPI
run: npm run openapi:lint
ci-complete:
name: ci-complete
needs: [autofix, lint, test, terraform, openapi]
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Require portions
env:
LINT: ${{ needs.lint.result }}
TEST: ${{ needs.test.result }}
TERRAFORM: ${{ needs.terraform.result }}
OPENAPI: ${{ needs.openapi.result }}
run: |
set -euo pipefail
test "${LINT}" = success
test "${TEST}" = success
test "${TERRAFORM}" = success
test "${OPENAPI}" = success