Skip to content

Bump gitpython to 3.1.62 and soupsieve to 2.9.2 #602

Bump gitpython to 3.1.62 and soupsieve to 2.9.2

Bump gitpython to 3.1.62 and soupsieve to 2.9.2 #602

Workflow file for this run

name: Unit Tests
env:
PYTHON_VERSION: "3.12"
on:
push:
branches: [main]
paths:
- "socketsecurity/**/*.py"
- "tests/unit/**/*.py"
- "tests/core/**/*.py"
- "pyproject.toml"
- "uv.lock"
- ".github/workflows/python-tests.yml"
# Deliberately unfiltered, unlike the push trigger above. A required status
# check that sits behind a paths filter never reports on a pull request that
# misses the filter, and an unreported required check blocks the merge
# forever. These jobs finish in well under a minute, so running them on every
# pull request costs little and is what makes them safe to require.
pull_request:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: python-tests-${{ github.ref }}
cancel-in-progress: true
jobs:
python-tests:
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
persist-credentials: false
- name: 🐍 setup python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: πŸ› οΈ install deps
run: |
python -m pip install --upgrade pip
pip install uv
uv sync --extra test
- name: πŸ”’ verify uv.lock is in sync with pyproject.toml
run: uv lock --locked
- name: πŸ§ͺ run tests
run: uv run pytest -q tests/unit/ tests/core/
- name: πŸ’¨ import smoke (catches API-removal breaks from upgraded deps)
run: |
uv run python -c "
from socketsecurity.socketcli import cli
from socketsecurity.core import Core
from socketsecurity.core.exceptions import APIFailure, APIResourceNotFound
from socketsecurity.core.git_interface import Git
from socketsecurity.config import CliConfig
print('import smoke OK')
"
# pip-audit used to run here. It moved to dependency-audit.yml, because
# its result depends on when it runs rather than on the commit, and
# mixing the two meant a third-party advisory publication reported itself
# as "Unit Tests failed" while every test passed.
ruff:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
persist-credentials: false
- name: 🐍 setup python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: πŸ› οΈ install deps
run: |
python -m pip install --upgrade pip
pip install uv
uv sync --extra dev
- name: 🧹 run ruff
run: uv run ruff check
unsupported-python-install:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
persist-credentials: false
- name: 🐍 setup python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.10"
- name: 🚫 verify install is rejected on unsupported python
run: |
python -m pip install --upgrade pip
if pip install .; then
echo "Expected pip install . to fail on Python 3.10"
exit 1
fi