security-review/.github/workflows/ci.yaml

96 lines
2.7 KiB
YAML

name: CI
on:
pull_request:
branches: [main]
# Temporary outage smoke test (PLAT-87): inlined org ci-python-app jobs on the
# repo self-hosted runner. Aggregator job name preserves required check "ci / ci".
permissions:
contents: read
jobs:
lint:
runs-on: self-hosted
timeout-minutes: 10
concurrency:
group: ci-selfhosted-${{ github.workflow }}-${{ github.ref }}-lint
cancel-in-progress: true
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Install ruff
run: pip install 'ruff==0.15.22'
- name: Ruff check
run: ruff check .
- name: Ruff format check
run: ruff format --check .
- name: Conventions check
run: |
errors=0
fail() { echo "::error::$1"; errors=$((errors + 1)); }
if [[ ! -f README.md ]]; then
fail "Missing README.md"
fi
if [[ -f .gitignore ]]; then
if ! grep -qE '^\.env$|^\.env\b' .gitignore; then
fail ".gitignore does not include .env"
fi
else
fail "Missing .gitignore"
fi
if [[ $errors -gt 0 ]]; then
echo "Conventions check failed with $errors error(s)."
exit 1
fi
echo "Conventions check passed."
test-collect:
runs-on: self-hosted
timeout-minutes: 10
concurrency:
group: ci-selfhosted-${{ github.workflow }}-${{ github.ref }}-test-collect
cancel-in-progress: true
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
cache: pip
cache-dependency-path: requirements.txt
- name: Install dependencies
run: |
pip install -r requirements.txt
pip install pytest python-dotenv
- name: Pytest collect-only
run: pytest --collect-only -q
ci:
name: ci / ci
needs: [lint, test-collect]
if: always()
runs-on: self-hosted
concurrency:
group: ci-selfhosted-${{ github.workflow }}-${{ github.ref }}-ci
cancel-in-progress: true
steps:
- name: Require all jobs to have succeeded
run: |
if [ "${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}" = "true" ]; then
echo "A required CI job failed or was cancelled."
exit 1
fi
echo "All CI jobs passed."