Skip to content

release: v1.2.0 — Tool-Boundary Guardrails Complete & Structured Synt… #590

release: v1.2.0 — Tool-Boundary Guardrails Complete & Structured Synt…

release: v1.2.0 — Tool-Boundary Guardrails Complete & Structured Synt… #590

Workflow file for this run

name: CI
on:
push:
branches: [main]
tags: ["v*"]
pull_request:
branches: [main]
jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/setup-python@v6
with:
python-version: "3.12"
cache: "pip"
- name: Install ruff
# Pinned to match the ruff-pre-commit rev in .pre-commit-config.yaml
run: pip install ruff==0.15.8
- name: Ruff lint
run: ruff check src/ tests/
- name: Ruff format check
run: ruff format --check src/ tests/
test:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
python-version: ["3.10", "3.11", "3.12", "3.13"]
name: test (py${{ matrix.python-version }})
steps:
- uses: actions/checkout@v5
- uses: actions/setup-python@v6
with:
python-version: ${{ matrix.python-version }}
cache: "pip"
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
- name: Run tests with coverage
run: |
pip install pytest-cov
pytest -n auto --cov=selectools --cov-fail-under=90 --cov-report=term-missing:skip-covered
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: actions/setup-python@v6
with:
python-version: "3.12"
cache: "pip"
- name: Install bandit
run: pip install bandit
- name: Security scan
run: bandit -r src/ -ll -q -c pyproject.toml
build:
runs-on: ubuntu-latest
needs: [lint, test, security]
steps:
- uses: actions/checkout@v5
- uses: actions/setup-python@v6
with:
python-version: "3.13"
cache: "pip"
- name: Install build tooling
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
- name: Build artifacts
run: python -m build
- name: Twine check
run: twine check dist/*
publish-testpypi:
runs-on: ubuntu-latest
needs: build
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
steps:
- uses: actions/checkout@v5
- uses: actions/setup-python@v6
with:
python-version: "3.13"
cache: "pip"
- name: Install build tooling
run: |
python -m pip install --upgrade pip
pip install build twine
- name: Build artifacts
run: python -m build
- name: Publish to TestPyPI
env:
TWINE_USERNAME: __token__
TWINE_PASSWORD: ${{ github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') && secrets.TEST_PYPI_API_TOKEN || '' }}
run: |
if [ -z "$TWINE_PASSWORD" ]; then
echo "Skipping TestPyPI publish (missing token)"
exit 0
fi
twine upload --repository testpypi --skip-existing dist/*
publish-pypi:
runs-on: ubuntu-latest
needs: build
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
steps:
- uses: actions/checkout@v5
- uses: actions/setup-python@v6
with:
python-version: "3.13"
cache: "pip"
- name: Install build tooling
run: |
python -m pip install --upgrade pip
pip install build twine
- name: Build artifacts
run: python -m build
- name: Publish to PyPI
env:
TWINE_USERNAME: __token__
TWINE_PASSWORD: ${{ github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') && secrets.PYPI_API_TOKEN || '' }}
run: |
if [ -z "$TWINE_PASSWORD" ]; then
echo "Skipping PyPI publish (missing token)"
exit 0
fi
twine upload --skip-existing dist/*