name: CI on: push: branches: [main, dev] pull_request: branches: [main, dev] permissions: contents: read env: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" jobs: lint: runs-on: ubuntu-latest steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.13" # Hash-pinned tool install (Scorecard: Pinned-Dependencies). Pins ruff to # the version this lint gate is known-green against; see .github/requirements/lint.in. - run: python -m pip install --require-hashes -r .github/requirements/lint.txt - run: ruff check src/ tests/ - run: ruff format --check src/ tests/ test: strategy: fail-fast: false matrix: python-version: ["3.10", "3.11", "3.12", "3.13"] runs-on: ubuntu-latest steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: ${{ matrix.python-version }} - run: | python -m pip install --require-hashes -r .github/requirements/pip.txt pip install -e ".[dev]" # tests/e2e build a wheel + clean venv per the dedicated e2e-wheel.yml # workflow — they are not part of the fast unit lane. - run: coverage run -m pytest -v --tb=short --rootdir=. --ignore=tests/e2e standards: name: seedgo-audit runs-on: ubuntu-latest steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: # Full history: the README-freshness check reads `git log` to find the # last commit touching each branch's .py. A shallow (depth-1) checkout # makes every file look born at HEAD, so every README false-fails as # "stale". Full history makes CI match a local audit exactly. fetch-depth: 0 - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.13" - run: | python -m pip install --require-hashes -r .github/requirements/pip.txt # Install the `memory` extra (numpy/chromadb/fastembed) alongside dev: # the diagnostics standard runs pyright over every branch, and memory's # handlers import chromadb/numpy. Without these deps installed, pyright # reports them as unresolved imports (reportMissingImports=error) and # memory scores <100 — a false failure from a missing CI dep, not a code # defect. Installing the declared extra lets pyright resolve them so the # audit measures real type-correctness (and matches a local audit). pip install -e ".[dev,memory]" - name: Run seedgo standards audit run: python .github/scripts/seedgo_audit.py coverage: name: coverage needs: [test] runs-on: ubuntu-latest steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.13" - run: | python -m pip install --require-hashes -r .github/requirements/pip.txt pip install -e ".[dev]" - run: coverage run -m pytest --rootdir=. --ignore=tests/e2e - run: coverage xml - uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 with: files: ./coverage.xml fail_ci_if_error: false