Repository navigation
Bump pyjwt from 2.13.0 to 2.15.0 #1858
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ci-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| selection: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| python: ${{ steps.plan.outputs.python }} | |
| frontend: ${{ steps.plan.outputs.frontend }} | |
| native: ${{ steps.plan.outputs.native }} | |
| python_browser: ${{ steps.plan.outputs.python_browser }} | |
| python_node: ${{ steps.plan.outputs.python_node }} | |
| python_versions: ${{ steps.plan.outputs.python_versions }} | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| with: | |
| fetch-depth: 0 | |
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | |
| - name: Validate reviewed test selection | |
| id: plan | |
| env: | |
| BASELINE: ${{ github.event.pull_request.base.sha || github.event.before }} | |
| CANDIDATE: ${{ github.event.pull_request.head.sha || github.sha }} | |
| run: | | |
| python scripts/test_selection.py --baseline "$BASELINE" --candidate "$CANDIDATE" --output test-selection-receipt.json | |
| printf 'python=%s\n' "$(jq -c '.python' test-selection-receipt.json)" >> "$GITHUB_OUTPUT" | |
| printf 'frontend=%s\n' "$(jq -c '.frontend' test-selection-receipt.json)" >> "$GITHUB_OUTPUT" | |
| printf 'native=%s\n' "$(jq -c '.native' test-selection-receipt.json)" >> "$GITHUB_OUTPUT" | |
| printf 'python_browser=%s\n' "$(jq -r '.python_browser // false' test-selection-receipt.json)" >> "$GITHUB_OUTPUT" | |
| printf 'python_node=%s\n' "$(jq -r '.python_node // false' test-selection-receipt.json)" >> "$GITHUB_OUTPUT" | |
| printf 'python_versions=%s\n' "$(jq -c '.python_versions // ["3.12"]' test-selection-receipt.json)" >> "$GITHUB_OUTPUT" | |
| cat test-selection-receipt.json >> "$GITHUB_STEP_SUMMARY" | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: always() | |
| with: | |
| name: test-selection-receipt | |
| path: test-selection-receipt.json | |
| python: | |
| needs: selection | |
| if: always() | |
| runs-on: ubuntu-latest | |
| env: | |
| RUN_SELECTED: ${{ needs.selection.result == 'success' && needs.selection.outputs.python != '[]' && contains(fromJSON(needs.selection.outputs.python_versions || '[]'), matrix.python-version) }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # Keep required branch-protection check names, not implicit test runs. | |
| python-version: ["3.11", "3.12", "3.13"] | |
| steps: | |
| - name: Require a valid reviewed selection | |
| env: | |
| SELECTION_RESULT: ${{ needs.selection.result }} | |
| run: test "$SELECTION_RESULT" = success | |
| - name: Record omitted runtime without running tests | |
| if: env.RUN_SELECTED != 'true' | |
| run: echo 'This Python runtime was not selected. No installation or tests run; see the test-selection receipt.' >> "$GITHUB_STEP_SUMMARY" | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| if: env.RUN_SELECTED == 'true' | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| if: env.RUN_SELECTED == 'true' && needs.selection.outputs.python_node == 'true' | |
| with: | |
| node-version: 20 | |
| - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 | |
| if: env.RUN_SELECTED == 'true' | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| cache: pip | |
| - name: Install Poetry | |
| if: env.RUN_SELECTED == 'true' | |
| run: python -m pip install "poetry==2.1.3" | |
| - name: Validate package metadata | |
| if: env.RUN_SELECTED == 'true' | |
| run: poetry check | |
| - name: Install project | |
| if: env.RUN_SELECTED == 'true' | |
| run: poetry install --no-interaction | |
| - name: Install Chromium for browser runtime regression tests | |
| if: env.RUN_SELECTED == 'true' && needs.selection.outputs.python_browser == 'true' | |
| run: poetry run playwright install --with-deps chromium | |
| - name: Test | |
| if: env.RUN_SELECTED == 'true' | |
| env: | |
| SELECTED_TESTS: ${{ needs.selection.outputs.python }} | |
| run: | | |
| mapfile -t targets < <(jq -r '.[]' <<<"$SELECTED_TESTS") | |
| poetry run pytest --collect-only -q "${targets[@]}" | |
| poetry run pytest -q "${targets[@]}" | |
| - name: Lint Nebula 3 | |
| if: env.RUN_SELECTED == 'true' | |
| run: poetry run ruff check src/nebula/v3 tests/v3 | |
| - name: Check Nebula 3 formatting | |
| if: env.RUN_SELECTED == 'true' | |
| run: poetry run ruff format --check src/nebula/v3 tests/v3 | |
| - name: Audit diagnostic blind spots | |
| if: env.RUN_SELECTED == 'true' && matrix.python-version == '3.12' | |
| run: poetry run python scripts/audit_diagnostic_blind_spots.py --python --rust | |
| - name: Type-check Nebula 3 | |
| if: env.RUN_SELECTED == 'true' && matrix.python-version == '3.12' | |
| run: poetry run mypy src/nebula/v3 | |
| - name: Build distributions | |
| if: env.RUN_SELECTED == 'true' | |
| run: poetry build | |
| database-migrations: | |
| needs: selection | |
| if: contains(needs.selection.outputs.python, 'tests/v3/test_migrations.py') | |
| runs-on: ubuntu-latest | |
| services: | |
| postgres: | |
| image: postgres:16-alpine | |
| env: | |
| POSTGRES_DB: nebula_migrations | |
| POSTGRES_PASSWORD: nebula | |
| POSTGRES_USER: nebula | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd "pg_isready -U nebula -d nebula_migrations" | |
| --health-interval 5s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| env: | |
| NEBULA_TEST_POSTGRES_URL: postgresql+psycopg://nebula:nebula@127.0.0.1:5432/nebula_migrations | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 | |
| with: | |
| python-version: "3.12" | |
| cache: pip | |
| - run: python -m pip install "poetry==2.1.3" | |
| - run: poetry install --with dev --no-interaction | |
| - name: Exercise SQLite and PostgreSQL upgrade/downgrade paths | |
| run: >- | |
| poetry run pytest -q tests/v3/test_migrations.py | |
| frontend: | |
| needs: selection | |
| if: needs.selection.outputs.frontend != '[]' | |
| runs-on: ubuntu-latest | |
| env: | |
| POETRY_VIRTUALENVS_IN_PROJECT: "true" | |
| defaults: | |
| run: | |
| working-directory: ui | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 | |
| with: | |
| python-version: "3.12" | |
| cache: pip | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 20 | |
| cache: npm | |
| cache-dependency-path: ui/package-lock.json | |
| - run: python -m pip install "poetry==2.1.3" | |
| working-directory: . | |
| - run: poetry install --only main --no-interaction | |
| working-directory: . | |
| - run: npm ci | |
| - run: npm run lint --if-present | |
| - run: npm run audit:diagnostics | |
| - name: Test selected frontend files | |
| env: | |
| SELECTED_TESTS: ${{ needs.selection.outputs.frontend }} | |
| run: | | |
| mapfile -t targets < <(jq -r '.[] | ltrimstr("ui/")' <<<"$SELECTED_TESTS") | |
| npm test -- "${targets[@]}" --testTimeout=15000 | |
| - run: npm run build | |
| desktop-macos: | |
| needs: selection | |
| if: needs.selection.outputs.native != '[]' | |
| runs-on: macos-14 | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 20 | |
| cache: npm | |
| cache-dependency-path: ui/package-lock.json | |
| - uses: dtolnay/rust-toolchain@4be7066ada62dd38de10e7b70166bc74ed198c30 | |
| with: | |
| toolchain: stable | |
| - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 | |
| with: | |
| python-version: "3.12" | |
| cache: pip | |
| - run: npm --prefix ui ci | |
| - run: npm --prefix ui run build | |
| - run: python -m pip install "poetry==2.1.3" | |
| - run: poetry install --with dev --no-interaction | |
| - name: Test macOS Docker Desktop and Podman Machine command boundaries | |
| run: poetry run pytest -q tests/v3/test_sandbox.py -k macos | |
| - name: Prepare compile-time sidecar boundary | |
| run: | | |
| target="$(rustc -vV | sed -n 's/^host: //p')" | |
| mkdir -p ui/src-tauri/binaries | |
| mkdir -p build/nebula-core-metadata | |
| printf 'Generated CI fixture for native shell tests.\n' > build/nebula-core-metadata/THIRD_PARTY_NOTICES.txt | |
| touch "ui/src-tauri/binaries/nebula-core-$target" | |
| chmod +x "ui/src-tauri/binaries/nebula-core-$target" | |
| - name: Test native menus and sidecar boundary | |
| env: | |
| SELECTED_TESTS: ${{ needs.selection.outputs.native }} | |
| run: | | |
| while IFS= read -r target; do | |
| cargo test --locked --manifest-path ui/src-tauri/Cargo.toml "$target" -- --exact --list | grep -F "$target: test" | |
| cargo test --locked --manifest-path ui/src-tauri/Cargo.toml "$target" -- --exact | |
| done < <(jq -r '.[]' <<<"$SELECTED_TESTS") | |
| security: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: anchore/sbom-action@fbfd9c6c189226748411491745178e0c2017392d # v0.20.10 | |
| with: | |
| path: . | |
| format: spdx-json | |
| output-file: nebula.spdx.json | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: sbom | |
| path: nebula.spdx.json |