release: v1.2.0 — Tool-Boundary Guardrails Complete & Structured Synt… #590
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| tags: ["v*"] | |
| pull_request: | |
| branches: [main] | |
| jobs: | |
| lint: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: actions/setup-python@v6 | |
| with: | |
| python-version: "3.12" | |
| cache: "pip" | |
| - name: Install ruff | |
| # Pinned to match the ruff-pre-commit rev in .pre-commit-config.yaml | |
| run: pip install ruff==0.15.8 | |
| - name: Ruff lint | |
| run: ruff check src/ tests/ | |
| - name: Ruff format check | |
| run: ruff format --check src/ tests/ | |
| test: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| python-version: ["3.10", "3.11", "3.12", "3.13"] | |
| name: test (py${{ matrix.python-version }}) | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: actions/setup-python@v6 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| cache: "pip" | |
| - name: Install dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -e ".[dev]" | |
| - name: Run tests with coverage | |
| run: | | |
| pip install pytest-cov | |
| pytest -n auto --cov=selectools --cov-fail-under=90 --cov-report=term-missing:skip-covered | |
| security: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: actions/setup-python@v6 | |
| with: | |
| python-version: "3.12" | |
| cache: "pip" | |
| - name: Install bandit | |
| run: pip install bandit | |
| - name: Security scan | |
| run: bandit -r src/ -ll -q -c pyproject.toml | |
| build: | |
| runs-on: ubuntu-latest | |
| needs: [lint, test, security] | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: actions/setup-python@v6 | |
| with: | |
| python-version: "3.13" | |
| cache: "pip" | |
| - name: Install build tooling | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -e ".[dev]" | |
| - name: Build artifacts | |
| run: python -m build | |
| - name: Twine check | |
| run: twine check dist/* | |
| publish-testpypi: | |
| runs-on: ubuntu-latest | |
| needs: build | |
| if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: actions/setup-python@v6 | |
| with: | |
| python-version: "3.13" | |
| cache: "pip" | |
| - name: Install build tooling | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install build twine | |
| - name: Build artifacts | |
| run: python -m build | |
| - name: Publish to TestPyPI | |
| env: | |
| TWINE_USERNAME: __token__ | |
| TWINE_PASSWORD: ${{ github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') && secrets.TEST_PYPI_API_TOKEN || '' }} | |
| run: | | |
| if [ -z "$TWINE_PASSWORD" ]; then | |
| echo "Skipping TestPyPI publish (missing token)" | |
| exit 0 | |
| fi | |
| twine upload --repository testpypi --skip-existing dist/* | |
| publish-pypi: | |
| runs-on: ubuntu-latest | |
| needs: build | |
| if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - uses: actions/setup-python@v6 | |
| with: | |
| python-version: "3.13" | |
| cache: "pip" | |
| - name: Install build tooling | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install build twine | |
| - name: Build artifacts | |
| run: python -m build | |
| - name: Publish to PyPI | |
| env: | |
| TWINE_USERNAME: __token__ | |
| TWINE_PASSWORD: ${{ github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') && secrets.PYPI_API_TOKEN || '' }} | |
| run: | | |
| if [ -z "$TWINE_PASSWORD" ]; then | |
| echo "Skipping PyPI publish (missing token)" | |
| exit 0 | |
| fi | |
| twine upload --skip-existing dist/* |