Fix 207 #128
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: main | |
| on: | |
| push: | |
| branches: ["**"] | |
| tags: ["v*"] # Trigger on version tags for release workflow chain | |
| pull_request: | |
| branches: [master] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| env: | |
| UV_CACHE_DIR: ${{ github.workspace }}/.uv-cache | |
| jobs: | |
| identifiers: | |
| # GitHub needs to know where .cicd/workflows/identifiers.yml lives at parse time, | |
| # and submodules aren't included in that context! thus the following does NOT work: | |
| # uses: ./.cicd/workflows/identifiers.yml | |
| # we MUST reference the remote repo directly: | |
| uses: wamp-proto/wamp-cicd/.github/workflows/identifiers.yml@main | |
| # IMPORTANT: we still need .cicd as a Git submodule in the using repo though! | |
| # because e.g. identifiers.yml wants to access scripts/sanitize.sh ! | |
| quality-checks: | |
| name: Code Quality Checks | |
| needs: identifiers | |
| runs-on: ubuntu-24.04 | |
| env: | |
| BASE_REPO: ${{ needs.identifiers.outputs.base_repo }} | |
| BASE_BRANCH: ${{ needs.identifiers.outputs.base_branch }} | |
| PR_NUMBER: ${{ needs.identifiers.outputs.pr_number }} | |
| PR_REPO: ${{ needs.identifiers.outputs.pr_repo }} | |
| PR_BRANCH: ${{ needs.identifiers.outputs.pr_branch }} | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| submodules: recursive | |
| - name: Install Just | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| curl -H "Authorization: Bearer $GITHUB_TOKEN" \ | |
| --proto '=https' --tlsv1.2 -sSf \ | |
| https://just.systems/install.sh | bash -s -- --to ~/bin | |
| echo "$HOME/bin" >> $GITHUB_PATH | |
| - name: Install uv (Astral) | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| export GITHUB_TOKEN | |
| curl -H "Authorization: Bearer $GITHUB_TOKEN" \ | |
| -LsSf https://astral.sh/uv/install.sh | sh | |
| echo "$HOME/.cargo/bin" >> $GITHUB_PATH | |
| # ty (Astral type checker) is declared in the [dev] extra and installed | |
| # into the venv via `just install-tools` below; no separate global | |
| # `uv tool install ty` step is needed. This keeps local and CI on the | |
| # same (latest) ty resolved from the pyproject constraint. | |
| - name: Verify toolchain installation | |
| run: | | |
| just --version | |
| uv --version | |
| - name: Setup uv cache | |
| uses: actions/cache@v4 | |
| with: | |
| path: ${{ env.UV_CACHE_DIR }} | |
| key: uv-cache-ubuntu-quality-${{ | |
| hashFiles('pyproject.toml') }} | |
| restore-keys: | | |
| uv-cache-ubuntu-quality- | |
| - name: Create Python environment and install tools | |
| run: | | |
| just create cpy314 | |
| just install-tools cpy314 | |
| - name: Lint code using Ruff | |
| run: just check-format cpy314 | |
| - name: Run static type checking with ty | |
| run: just check-typing cpy314 | |
| - name: Run tests | |
| run: just test cpy314 | |
| - name: Run tests with coverage report | |
| run: just check-coverage cpy314 | |
| - name: Upload coverage report | |
| if: always() | |
| uses: wamp-proto/wamp-cicd/actions/upload-artifact-verified@main | |
| with: | |
| name: coverage-report | |
| path: docs/_build/html/coverage/ | |
| retention-days: 14 | |
| documentation: | |
| name: Documentation Build | |
| needs: identifiers | |
| runs-on: ubuntu-24.04 | |
| env: | |
| BASE_REPO: ${{ needs.identifiers.outputs.base_repo }} | |
| BASE_BRANCH: ${{ needs.identifiers.outputs.base_branch }} | |
| PR_NUMBER: ${{ needs.identifiers.outputs.pr_number }} | |
| PR_REPO: ${{ needs.identifiers.outputs.pr_repo }} | |
| PR_BRANCH: ${{ needs.identifiers.outputs.pr_branch }} | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| submodules: recursive | |
| - name: Install Just | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| curl -H "Authorization: Bearer $GITHUB_TOKEN" \ | |
| --proto '=https' --tlsv1.2 -sSf \ | |
| https://just.systems/install.sh | bash -s -- --to ~/bin | |
| echo "$HOME/bin" >> $GITHUB_PATH | |
| - name: Install uv (Astral) | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| export GITHUB_TOKEN | |
| curl -H "Authorization: Bearer $GITHUB_TOKEN" \ | |
| -LsSf https://astral.sh/uv/install.sh | sh | |
| echo "$HOME/.cargo/bin" >> $GITHUB_PATH | |
| - name: Verify toolchain installation | |
| run: | | |
| just --version | |
| uv --version | |
| - name: Setup uv cache | |
| uses: actions/cache@v4 | |
| with: | |
| path: ${{ env.UV_CACHE_DIR }} | |
| key: uv-cache-ubuntu-docs-${{ hashFiles('pyproject.toml') | |
| }} | |
| restore-keys: | | |
| uv-cache-ubuntu-docs- | |
| - name: Create Python environment and install tools | |
| run: | | |
| just create cpy314 | |
| just install-tools cpy314 | |
| - name: Build documentation | |
| run: just docs cpy314 | |
| - name: Upload documentation artifacts | |
| uses: wamp-proto/wamp-cicd/actions/upload-artifact-verified@main | |
| with: | |
| name: documentation | |
| path: docs/_build/html/ | |
| retention-days: 14 | |
| build-package: | |
| name: Package Build | |
| runs-on: ubuntu-24.04 | |
| needs: [identifiers, quality-checks] | |
| env: | |
| BASE_REPO: ${{ needs.identifiers.outputs.base_repo }} | |
| BASE_BRANCH: ${{ needs.identifiers.outputs.base_branch }} | |
| PR_NUMBER: ${{ needs.identifiers.outputs.pr_number }} | |
| PR_REPO: ${{ needs.identifiers.outputs.pr_repo }} | |
| PR_BRANCH: ${{ needs.identifiers.outputs.pr_branch }} | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| submodules: recursive | |
| - name: Install Just | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| curl -H "Authorization: Bearer $GITHUB_TOKEN" \ | |
| --proto '=https' --tlsv1.2 -sSf \ | |
| https://just.systems/install.sh | bash -s -- --to ~/bin | |
| echo "$HOME/bin" >> $GITHUB_PATH | |
| - name: Install uv (Astral) | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| export GITHUB_TOKEN | |
| curl -H "Authorization: Bearer $GITHUB_TOKEN" \ | |
| -LsSf https://astral.sh/uv/install.sh | sh | |
| echo "$HOME/.cargo/bin" >> $GITHUB_PATH | |
| - name: Verify toolchain installation | |
| run: | | |
| just --version | |
| uv --version | |
| - name: Setup uv cache | |
| uses: actions/cache@v4 | |
| with: | |
| path: ${{ env.UV_CACHE_DIR }} | |
| key: uv-cache-ubuntu-build-${{ | |
| hashFiles('pyproject.toml') }} | |
| restore-keys: | | |
| uv-cache-ubuntu-build- | |
| - name: Create Python environment and install tools | |
| run: | | |
| just create cpy311 | |
| just install-tools cpy311 | |
| # Build the full release fileset once (txaio is pure-Python: a single | |
| # universal wheel + source distribution). This is the canonical artifact | |
| # that the release workflow downloads (verified) and publishes - so what | |
| # is tested here is exactly what ships (chain-of-custody). | |
| - name: Build wheel and source distribution | |
| run: | | |
| just build cpy311 | |
| just build-sourcedist cpy311 | |
| - name: List built artifacts | |
| run: | | |
| echo "Built release fileset (wheel + sdist):" | |
| ls -la dist/ | |
| - name: Upload build artifacts (verified) | |
| uses: wamp-proto/wamp-cicd/actions/upload-artifact-verified@main | |
| with: | |
| name: package | |
| path: dist/ | |
| retention-days: 14 |