Bump gitpython to 3.1.62 and soupsieve to 2.9.2 #602
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Unit Tests | |
| env: | |
| PYTHON_VERSION: "3.12" | |
| on: | |
| push: | |
| branches: [main] | |
| paths: | |
| - "socketsecurity/**/*.py" | |
| - "tests/unit/**/*.py" | |
| - "tests/core/**/*.py" | |
| - "pyproject.toml" | |
| - "uv.lock" | |
| - ".github/workflows/python-tests.yml" | |
| # Deliberately unfiltered, unlike the push trigger above. A required status | |
| # check that sits behind a paths filter never reports on a pull request that | |
| # misses the filter, and an unreported required check blocks the merge | |
| # forever. These jobs finish in well under a minute, so running them on every | |
| # pull request costs little and is what makes them safe to require. | |
| pull_request: | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: python-tests-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| python-tests: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 1 | |
| persist-credentials: false | |
| - name: π setup python | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: ${{ env.PYTHON_VERSION }} | |
| - name: π οΈ install deps | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install uv | |
| uv sync --extra test | |
| - name: π verify uv.lock is in sync with pyproject.toml | |
| run: uv lock --locked | |
| - name: π§ͺ run tests | |
| run: uv run pytest -q tests/unit/ tests/core/ | |
| - name: π¨ import smoke (catches API-removal breaks from upgraded deps) | |
| run: | | |
| uv run python -c " | |
| from socketsecurity.socketcli import cli | |
| from socketsecurity.core import Core | |
| from socketsecurity.core.exceptions import APIFailure, APIResourceNotFound | |
| from socketsecurity.core.git_interface import Git | |
| from socketsecurity.config import CliConfig | |
| print('import smoke OK') | |
| " | |
| # pip-audit used to run here. It moved to dependency-audit.yml, because | |
| # its result depends on when it runs rather than on the commit, and | |
| # mixing the two meant a third-party advisory publication reported itself | |
| # as "Unit Tests failed" while every test passed. | |
| ruff: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 1 | |
| persist-credentials: false | |
| - name: π setup python | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: ${{ env.PYTHON_VERSION }} | |
| - name: π οΈ install deps | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install uv | |
| uv sync --extra dev | |
| - name: π§Ή run ruff | |
| run: uv run ruff check | |
| unsupported-python-install: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 1 | |
| persist-credentials: false | |
| - name: π setup python | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.10" | |
| - name: π« verify install is rejected on unsupported python | |
| run: | | |
| python -m pip install --upgrade pip | |
| if pip install .; then | |
| echo "Expected pip install . to fail on Python 3.10" | |
| exit 1 | |
| fi |