Hardened Gitea Actions workflows and updated action pins.
CI / Formatting (push) Successful in 35s
CI / Linting (push) Successful in 5s
CI / Tests (Python 3.12) (push) Successful in 2m49s
CI / Tests (Python 3.13) (push) Successful in 2m53s
CI / Tests (Python 3.14) (push) Successful in 2m45s
CI / Type Checking (push) Successful in 9s
CI / Spelling (push) Successful in 6s

This commit is contained in:
2026-04-28 15:17:13 -04:00
parent b2688b7934
commit 231578eccb
4 changed files with 35 additions and 25 deletions
+5 -2
View File
@@ -12,6 +12,9 @@ on:
permissions:
contents: read
env:
UV_PYTHON_DOWNLOADS: never
jobs:
audit:
name: Dependencies
@@ -23,13 +26,13 @@ jobs:
fetch-depth: 0
- name: Cache uv packages
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: ~/.cache/uv
key: uv-${{ hashFiles('uv.lock') }}
- name: Install dependencies
run: uv sync
run: uv sync --locked
- name: Audit dependencies with pip-audit
run: uv run pip-audit --skip-editable
+7 -10
View File
@@ -8,6 +8,9 @@ permissions:
contents: read
# packages: write # not yet supported by Gitea
env:
UV_PYTHON_DOWNLOADS: never
jobs:
publish-package:
name: Publish Package
@@ -18,14 +21,8 @@ jobs:
with:
fetch-depth: 0
- name: Cache uv packages
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
with:
path: ~/.cache/uv
key: uv-${{ hashFiles('uv.lock') }}
- name: Install dependencies
run: uv sync
run: uv sync --locked
- name: Build package
run: uv build
@@ -45,19 +42,19 @@ jobs:
fetch-depth: 0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
with:
driver-opts: network=host
- name: Log in to Gitea Container Registry
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4.1.0
with:
registry: git.logal.dev
username: ${{ secrets.REGISTRY_USERNAME }}
password: ${{ secrets.REGISTRY_PASSWORD }}
- name: Build and push image
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0
with:
context: .
network: host
+21 -11
View File
@@ -8,6 +8,9 @@ on:
permissions:
contents: read
env:
UV_PYTHON_DOWNLOADS: never
jobs:
formatting:
name: Formatting
@@ -19,13 +22,13 @@ jobs:
fetch-depth: 0
- name: Cache uv packages
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: ~/.cache/uv
key: uv-${{ hashFiles('uv.lock') }}
- name: Install dependencies
run: uv sync
run: uv sync --locked
- name: Check formatting with Ruff
run: uv run ruff format --check --diff .
@@ -40,13 +43,13 @@ jobs:
fetch-depth: 0
- name: Cache uv packages
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: ~/.cache/uv
key: uv-${{ hashFiles('uv.lock') }}
- name: Install dependencies
run: uv sync
run: uv sync --locked
- name: Check linting with Ruff
run: uv run ruff check .
@@ -60,26 +63,33 @@ jobs:
env:
UV_PYTHON: ${{ matrix.python-version }}
UV_PYTHON_PREFERENCE: system
UV_PYTHON_DOWNLOADS: automatic
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- name: Cache uv managed Python installs
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: ~/.local/share/uv/python
key: uv-python-${{ matrix.python-version }}-${{ runner.os }}-${{ runner.arch }}
- name: Cache uv packages
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: ~/.cache/uv
key: uv-${{ matrix.python-version }}-${{ hashFiles('uv.lock') }}
- name: Cache Owncast binary
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: .owncast-test
key: owncast-${{ hashFiles('tests/integration/conftest.py') }}-${{ runner.os }}-${{ runner.arch }}
- name: Install dependencies
run: uv sync
run: uv sync --locked
- name: Run unit tests with Pytest
run: uv run pytest -v --cov --cov-report= --run-integration
@@ -97,13 +107,13 @@ jobs:
fetch-depth: 0
- name: Cache uv packages
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: ~/.cache/uv
key: uv-${{ hashFiles('uv.lock') }}
- name: Install dependencies
run: uv sync
run: uv sync --locked
- name: Check types with Mypy
run: uv run mypy .
@@ -118,13 +128,13 @@ jobs:
fetch-depth: 0
- name: Cache uv packages
uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
path: ~/.cache/uv
key: uv-${{ hashFiles('uv.lock') }}
- name: Install dependencies
run: uv sync
run: uv sync --locked
- name: Check spelling with codespell
run: uv run codespell
+2 -2
View File
@@ -6,9 +6,9 @@ ENV UV_LINK_MODE=copy \
WORKDIR /app
COPY pyproject.toml uv.lock ./
RUN uv sync --no-dev --frozen --no-install-project
RUN uv sync --no-dev --locked --no-install-project
COPY . .
RUN uv sync --no-dev --frozen --no-editable
RUN uv sync --no-dev --locked --no-editable
FROM archlinux:base