Files
seedsigner/.github/workflows/tests.yml
T
kdmukai 175db636e6 Hash-lock the remaining requirements pins
Cover requirements.txt, tests/requirements.txt, and
requirements-raspi.txt like the l10n pins: every entry now carries the
sha256 of every published file for its release, so pip refuses any
unverified artifact.

Hash-checking mode can't verify git checkouts, so the pyzbar and
urtypes deps become commit-pinned GitHub archive tarballs. The mode
also demands pins for everything in the invocation, so pytest's
transitive deps are pinned too, and coverage is pinned as
coverage[toml]: older pips (e.g. the docker dev image's) won't accept
a plain pin as satisfying pytest-cov's extra-qualified dependency.
2026-08-22 07:11:27 -05:00

93 lines
3.1 KiB
YAML

name: CI
on:
push:
pull_request:
# Explicitly restrict the auto-provisioned GITHUB_TOKEN to the least privilege required
# for this workflow.
permissions:
contents: read
concurrency:
# Concurrency group that uses the workflow name and PR number if available
# or commit SHA as a fallback. If a new build is triggered under that
# concurrency group while a previous build is running it will be canceled.
# Repeated pushes to a PR will cancel all previous builds, while multiple
# merges to main will not cancel.
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }}
cancel-in-progress: true
env:
# Used by the `Version` class so it can identify the current fork
PR_AUTHOR: ${{ github.event.pull_request.user.login || github.actor }}
# Used by `Version`. We want the PR author's latest commit hash if this is a PR
# but the default SHA env var reflects a new commit into the target repo.
SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
jobs:
test:
runs-on: ubuntu-latest
timeout-minutes: 20
strategy:
matrix:
# 3.10: currently used by Seedsigner
# 3.12: latest stable Python as upper test bound
python-version: ["3.10", "3.12"]
steps:
- uses: actions/checkout@v4
with:
# Needs to also pull the seedsigner-translations repo
submodules: recursive
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
cache: "pip"
cache-dependency-path: |
requirements.txt
tests/requirements.txt
- name: Install dependencies
run: |
sudo apt-get install libzbar0
python -m pip install --upgrade pip
# hash-locked requirements files
pip install -r requirements.txt -r tests/requirements.txt l10n/requirements-l10n.txt
# An editable install can't satisfy hash-checking, so `-e .` can't
# share an invocation with the hash-locked files above.
pip install -e .
- name: Compile translations
run: python setup.py compile_catalog
- name: Test with pytest
run: |
mkdir -p artifacts
python -m pytest \
--color=yes \
--cov=seedsigner \
--cov-branch \
--durations 5 \
-vv
- name: Generate screenshots
run: |
python -m pytest tests/screenshot_generator/generator.py \
--color=yes \
--cov=seedsigner \
--cov-append \
--cov-branch \
--cov-report html:./artifacts/cov_html \
-vv
cp -r ./seedsigner-screenshots ./artifacts/
- name: Coverage report
run: coverage report
- name: Archive CI Artifacts
uses: actions/upload-artifact@v4
with:
name: ci-artifacts-${{ matrix.python-version }}
path: artifacts/**
retention-days: 10
# Upload also when tests fail. The workflow result (red/green) will
# not be affected by this.
if: always()