Files
seedsigner/.github/workflows/tests.yml
T
kdmukai 596528f117 Give the hash-locked l10n install its own pip invocation
pip enables hash-checking for an entire invocation the moment any
requirement in it carries a hash, and then demands hashes for
everything else in that invocation. The combined install line mixed
requirements-l10n.txt with two unhashed files and an editable install,
so it fails now that the l10n pins are hash-locked -- and
requirements.txt cannot simply join hash mode, because hash-checking
rejects its git-pinned entries outright.

Splitting the install keeps the l10n file's hashes enforced while the
other files continue to install unhashed. The comment above the
split line records why it exists, so it doesn't get folded back into
the combined line and break CI later.
2026-08-19 19:03:59 -05:00

96 lines
3.3 KiB
YAML

name: CI
on:
push:
pull_request:
# Explicitly restrict the auto-provisioned GITHUB_TOKEN to the least privilege required
# for this workflow.
permissions:
contents: read
concurrency:
# Concurrency group that uses the workflow name and PR number if available
# or commit SHA as a fallback. If a new build is triggered under that
# concurrency group while a previous build is running it will be canceled.
# Repeated pushes to a PR will cancel all previous builds, while multiple
# merges to main will not cancel.
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }}
cancel-in-progress: true
env:
# Used by the `Version` class so it can identify the current fork
PR_AUTHOR: ${{ github.event.pull_request.user.login || github.actor }}
# Used by `Version`. We want the PR author's latest commit hash if this is a PR
# but the default SHA env var reflects a new commit into the target repo.
SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
jobs:
test:
runs-on: ubuntu-latest
timeout-minutes: 20
strategy:
matrix:
# 3.10: currently used by Seedsigner
# 3.12: latest stable Python as upper test bound
python-version: ["3.10", "3.12"]
steps:
- uses: actions/checkout@v4
with:
# Needs to also pull the seedsigner-translations repo
submodules: recursive
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
cache: "pip"
cache-dependency-path: |
requirements.txt
tests/requirements.txt
- name: Install dependencies
run: |
sudo apt-get install libzbar0
python -m pip install --upgrade pip
pip install -r requirements.txt -r tests/requirements.txt
# requirements-l10n.txt is hash-locked (SeedSigner OS installs it
# during image builds). It needs its own pip invocation: one hashed
# requirement makes pip demand hashes for everything else in the
# same invocation, which the unhashed files above and `-e .` below
# can't satisfy.
pip install -r l10n/requirements-l10n.txt
pip install -e .
- name: Compile translations
run: python setup.py compile_catalog
- name: Test with pytest
run: |
mkdir -p artifacts
python -m pytest \
--color=yes \
--cov=seedsigner \
--cov-branch \
--durations 5 \
-vv
- name: Generate screenshots
run: |
python -m pytest tests/screenshot_generator/generator.py \
--color=yes \
--cov=seedsigner \
--cov-append \
--cov-branch \
--cov-report html:./artifacts/cov_html \
-vv
cp -r ./seedsigner-screenshots ./artifacts/
- name: Coverage report
run: coverage report
- name: Archive CI Artifacts
uses: actions/upload-artifact@v4
with:
name: ci-artifacts-${{ matrix.python-version }}
path: artifacts/**
retention-days: 10
# Upload also when tests fail. The workflow result (red/green) will
# not be affected by this.
if: always()