Skip to content

Bump pyjwt from 2.13.0 to 2.15.0 #1858

Bump pyjwt from 2.13.0 to 2.15.0

Bump pyjwt from 2.13.0 to 2.15.0 #1858

Workflow file for this run

name: CI
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
selection:
runs-on: ubuntu-latest
outputs:
python: ${{ steps.plan.outputs.python }}
frontend: ${{ steps.plan.outputs.frontend }}
native: ${{ steps.plan.outputs.native }}
python_browser: ${{ steps.plan.outputs.python_browser }}
python_node: ${{ steps.plan.outputs.python_node }}
python_versions: ${{ steps.plan.outputs.python_versions }}
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
fetch-depth: 0
ref: ${{ github.event.pull_request.head.sha || github.sha }}
- name: Validate reviewed test selection
id: plan
env:
BASELINE: ${{ github.event.pull_request.base.sha || github.event.before }}
CANDIDATE: ${{ github.event.pull_request.head.sha || github.sha }}
run: |
python scripts/test_selection.py --baseline "$BASELINE" --candidate "$CANDIDATE" --output test-selection-receipt.json
printf 'python=%s\n' "$(jq -c '.python' test-selection-receipt.json)" >> "$GITHUB_OUTPUT"
printf 'frontend=%s\n' "$(jq -c '.frontend' test-selection-receipt.json)" >> "$GITHUB_OUTPUT"
printf 'native=%s\n' "$(jq -c '.native' test-selection-receipt.json)" >> "$GITHUB_OUTPUT"
printf 'python_browser=%s\n' "$(jq -r '.python_browser // false' test-selection-receipt.json)" >> "$GITHUB_OUTPUT"
printf 'python_node=%s\n' "$(jq -r '.python_node // false' test-selection-receipt.json)" >> "$GITHUB_OUTPUT"
printf 'python_versions=%s\n' "$(jq -c '.python_versions // ["3.12"]' test-selection-receipt.json)" >> "$GITHUB_OUTPUT"
cat test-selection-receipt.json >> "$GITHUB_STEP_SUMMARY"
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: test-selection-receipt
path: test-selection-receipt.json
python:
needs: selection
if: always()
runs-on: ubuntu-latest
env:
RUN_SELECTED: ${{ needs.selection.result == 'success' && needs.selection.outputs.python != '[]' && contains(fromJSON(needs.selection.outputs.python_versions || '[]'), matrix.python-version) }}
strategy:
fail-fast: false
matrix:
# Keep required branch-protection check names, not implicit test runs.
python-version: ["3.11", "3.12", "3.13"]
steps:
- name: Require a valid reviewed selection
env:
SELECTION_RESULT: ${{ needs.selection.result }}
run: test "$SELECTION_RESULT" = success
- name: Record omitted runtime without running tests
if: env.RUN_SELECTED != 'true'
run: echo 'This Python runtime was not selected. No installation or tests run; see the test-selection receipt.' >> "$GITHUB_STEP_SUMMARY"
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
if: env.RUN_SELECTED == 'true'
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
if: env.RUN_SELECTED == 'true' && needs.selection.outputs.python_node == 'true'
with:
node-version: 20
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
if: env.RUN_SELECTED == 'true'
with:
python-version: ${{ matrix.python-version }}
cache: pip
- name: Install Poetry
if: env.RUN_SELECTED == 'true'
run: python -m pip install "poetry==2.1.3"
- name: Validate package metadata
if: env.RUN_SELECTED == 'true'
run: poetry check
- name: Install project
if: env.RUN_SELECTED == 'true'
run: poetry install --no-interaction
- name: Install Chromium for browser runtime regression tests
if: env.RUN_SELECTED == 'true' && needs.selection.outputs.python_browser == 'true'
run: poetry run playwright install --with-deps chromium
- name: Test
if: env.RUN_SELECTED == 'true'
env:
SELECTED_TESTS: ${{ needs.selection.outputs.python }}
run: |
mapfile -t targets < <(jq -r '.[]' <<<"$SELECTED_TESTS")
poetry run pytest --collect-only -q "${targets[@]}"
poetry run pytest -q "${targets[@]}"
- name: Lint Nebula 3
if: env.RUN_SELECTED == 'true'
run: poetry run ruff check src/nebula/v3 tests/v3
- name: Check Nebula 3 formatting
if: env.RUN_SELECTED == 'true'
run: poetry run ruff format --check src/nebula/v3 tests/v3
- name: Audit diagnostic blind spots
if: env.RUN_SELECTED == 'true' && matrix.python-version == '3.12'
run: poetry run python scripts/audit_diagnostic_blind_spots.py --python --rust
- name: Type-check Nebula 3
if: env.RUN_SELECTED == 'true' && matrix.python-version == '3.12'
run: poetry run mypy src/nebula/v3
- name: Build distributions
if: env.RUN_SELECTED == 'true'
run: poetry build
database-migrations:
needs: selection
if: contains(needs.selection.outputs.python, 'tests/v3/test_migrations.py')
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16-alpine
env:
POSTGRES_DB: nebula_migrations
POSTGRES_PASSWORD: nebula
POSTGRES_USER: nebula
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U nebula -d nebula_migrations"
--health-interval 5s
--health-timeout 5s
--health-retries 10
env:
NEBULA_TEST_POSTGRES_URL: postgresql+psycopg://nebula:nebula@127.0.0.1:5432/nebula_migrations
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.12"
cache: pip
- run: python -m pip install "poetry==2.1.3"
- run: poetry install --with dev --no-interaction
- name: Exercise SQLite and PostgreSQL upgrade/downgrade paths
run: >-
poetry run pytest -q tests/v3/test_migrations.py
frontend:
needs: selection
if: needs.selection.outputs.frontend != '[]'
runs-on: ubuntu-latest
env:
POETRY_VIRTUALENVS_IN_PROJECT: "true"
defaults:
run:
working-directory: ui
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.12"
cache: pip
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 20
cache: npm
cache-dependency-path: ui/package-lock.json
- run: python -m pip install "poetry==2.1.3"
working-directory: .
- run: poetry install --only main --no-interaction
working-directory: .
- run: npm ci
- run: npm run lint --if-present
- run: npm run audit:diagnostics
- name: Test selected frontend files
env:
SELECTED_TESTS: ${{ needs.selection.outputs.frontend }}
run: |
mapfile -t targets < <(jq -r '.[] | ltrimstr("ui/")' <<<"$SELECTED_TESTS")
npm test -- "${targets[@]}" --testTimeout=15000
- run: npm run build
desktop-macos:
needs: selection
if: needs.selection.outputs.native != '[]'
runs-on: macos-14
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 20
cache: npm
cache-dependency-path: ui/package-lock.json
- uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30
with:
toolchain: stable
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.12"
cache: pip
- run: npm --prefix ui ci
- run: npm --prefix ui run build
- run: python -m pip install "poetry==2.1.3"
- run: poetry install --with dev --no-interaction
- name: Test macOS Docker Desktop and Podman Machine command boundaries
run: poetry run pytest -q tests/v3/test_sandbox.py -k macos
- name: Prepare compile-time sidecar boundary
run: |
target="$(rustc -vV | sed -n 's/^host: //p')"
mkdir -p ui/src-tauri/binaries
mkdir -p build/nebula-core-metadata
printf 'Generated CI fixture for native shell tests.\n' > build/nebula-core-metadata/THIRD_PARTY_NOTICES.txt
touch "ui/src-tauri/binaries/nebula-core-$target"
chmod +x "ui/src-tauri/binaries/nebula-core-$target"
- name: Test native menus and sidecar boundary
env:
SELECTED_TESTS: ${{ needs.selection.outputs.native }}
run: |
while IFS= read -r target; do
cargo test --locked --manifest-path ui/src-tauri/Cargo.toml "$target" -- --exact --list | grep -F "$target: test"
cargo test --locked --manifest-path ui/src-tauri/Cargo.toml "$target" -- --exact
done < <(jq -r '.[]' <<<"$SELECTED_TESTS")
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: anchore/sbom-action@fbfd9c6c189226748411491745178e0c2017392d # v0.20.10
with:
path: .
format: spdx-json
output-file: nebula.spdx.json
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: sbom
path: nebula.spdx.json