mirror of
https://github.com/SeedSigner/seedsigner.git
synced 2026-10-05 15:08:25 +00:00
pip enables hash-checking for an entire invocation the moment any requirement in it carries a hash, and then demands hashes for everything else in that invocation. The combined install line mixed requirements-l10n.txt with two unhashed files and an editable install, so it fails now that the l10n pins are hash-locked -- and requirements.txt cannot simply join hash mode, because hash-checking rejects its git-pinned entries outright. Splitting the install keeps the l10n file's hashes enforced while the other files continue to install unhashed. The comment above the split line records why it exists, so it doesn't get folded back into the combined line and break CI later.
96 lines
3.3 KiB
YAML
96 lines
3.3 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
pull_request:
|
|
|
|
# Explicitly restrict the auto-provisioned GITHUB_TOKEN to the least privilege required
|
|
# for this workflow.
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
# Concurrency group that uses the workflow name and PR number if available
|
|
# or commit SHA as a fallback. If a new build is triggered under that
|
|
# concurrency group while a previous build is running it will be canceled.
|
|
# Repeated pushes to a PR will cancel all previous builds, while multiple
|
|
# merges to main will not cancel.
|
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }}
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
# Used by the `Version` class so it can identify the current fork
|
|
PR_AUTHOR: ${{ github.event.pull_request.user.login || github.actor }}
|
|
|
|
# Used by `Version`. We want the PR author's latest commit hash if this is a PR
|
|
# but the default SHA env var reflects a new commit into the target repo.
|
|
SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
|
|
|
|
jobs:
|
|
test:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 20
|
|
strategy:
|
|
matrix:
|
|
# 3.10: currently used by Seedsigner
|
|
# 3.12: latest stable Python as upper test bound
|
|
python-version: ["3.10", "3.12"]
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
# Needs to also pull the seedsigner-translations repo
|
|
submodules: recursive
|
|
- name: Set up Python ${{ matrix.python-version }}
|
|
uses: actions/setup-python@v5
|
|
with:
|
|
python-version: ${{ matrix.python-version }}
|
|
cache: "pip"
|
|
cache-dependency-path: |
|
|
requirements.txt
|
|
tests/requirements.txt
|
|
- name: Install dependencies
|
|
run: |
|
|
sudo apt-get install libzbar0
|
|
python -m pip install --upgrade pip
|
|
pip install -r requirements.txt -r tests/requirements.txt
|
|
# requirements-l10n.txt is hash-locked (SeedSigner OS installs it
|
|
# during image builds). It needs its own pip invocation: one hashed
|
|
# requirement makes pip demand hashes for everything else in the
|
|
# same invocation, which the unhashed files above and `-e .` below
|
|
# can't satisfy.
|
|
pip install -r l10n/requirements-l10n.txt
|
|
pip install -e .
|
|
- name: Compile translations
|
|
run: python setup.py compile_catalog
|
|
- name: Test with pytest
|
|
run: |
|
|
mkdir -p artifacts
|
|
python -m pytest \
|
|
--color=yes \
|
|
--cov=seedsigner \
|
|
--cov-branch \
|
|
--durations 5 \
|
|
-vv
|
|
- name: Generate screenshots
|
|
run: |
|
|
python -m pytest tests/screenshot_generator/generator.py \
|
|
--color=yes \
|
|
--cov=seedsigner \
|
|
--cov-append \
|
|
--cov-branch \
|
|
--cov-report html:./artifacts/cov_html \
|
|
-vv
|
|
cp -r ./seedsigner-screenshots ./artifacts/
|
|
- name: Coverage report
|
|
run: coverage report
|
|
- name: Archive CI Artifacts
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: ci-artifacts-${{ matrix.python-version }}
|
|
path: artifacts/**
|
|
retention-days: 10
|
|
# Upload also when tests fail. The workflow result (red/green) will
|
|
# not be affected by this.
|
|
if: always()
|