Skip to content

Fix two live bugs reported in the PR backlog #258

Fix two live bugs reported in the PR backlog

Fix two live bugs reported in the PR backlog #258

Workflow file for this run

name: reactome_chatbot CI
on:
workflow_dispatch:
pull_request:
types:
- opened
- synchronize
push:
branches:
- main
# A second push to a PR makes the first run's result irrelevant; without this
# they both run to completion and queue behind each other.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
# Least privilege by default. id-token: write is granted only to docker-push,
# which needs it to assume the AWS role.
permissions:
contents: read
jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python and Poetry
uses: ./.github/actions/install_python_poetry
# ruff replaces black + isort; its `I` rules sort imports and
# `ruff format` is black-compatible. Config lives in pyproject.toml.
- name: Lint
run: poetry run ruff check .
- name: Check formatting
run: poetry run ruff format --check .
- name: Type check
run: poetry run mypy
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python and Poetry
uses: ./.github/actions/install_python_poetry
- name: Run tests
run: poetry run pytest
poetry-check:
if: ${{ github.event_name == 'pull_request' || github.event_name == 'workflow_dispatch' }}
runs-on: ${{ matrix.os }}
strategy:
matrix:
os: [ubuntu-latest, macos-15-intel]
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # need the base branch to diff against
# Plain git rather than a third-party action: this workflow can reach
# AWS, so every extra action is supply-chain surface for a one-line check.
- name: Check poetry.lock for changes
id: check-poetry-lock
shell: bash
run: |
base="${{ github.base_ref }}"
if [ -z "$base" ]; then
# manual run: no base to compare against, so always verify
echo "changed=true" >> "$GITHUB_OUTPUT"
elif git diff --name-only "origin/$base...HEAD" -- poetry.lock | grep -q .; then
echo "changed=true" >> "$GITHUB_OUTPUT"
else
echo "changed=false" >> "$GITHUB_OUTPUT"
fi
- name: Set up Python and Poetry
if: steps.check-poetry-lock.outputs.changed == 'true'
uses: ./.github/actions/install_python_poetry
- name: Verify Python imports
if: steps.check-poetry-lock.outputs.changed == 'true'
env:
PYTHONPATH: ./bin:./src
run: |
poetry check
poetry run python ./.github/actions/verify_imports.py
docker-build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build and push Docker image
uses: docker/build-push-action@v6
with:
context: .
file: ./Dockerfile
tags: reactome-chatbot:${{ github.sha }}
outputs: type=docker,dest=/tmp/image.tar
- uses: actions/upload-artifact@v4
with:
name: image-artifact
path: /tmp/image.tar
docker-push:
if: ${{ github.event_name == 'push' && github.ref == 'refs/heads/main' }}
needs: docker-build
runs-on: ubuntu-latest
permissions:
id-token: write # assume the AWS role via OIDC
contents: read
steps:
- uses: actions/download-artifact@v4
with:
name: image-artifact
path: /tmp
- id: get-hash
run: |
FULL_SHA=${{ github.sha }}
echo "SHORT_SHA=${FULL_SHA:0:7}" >> $GITHUB_OUTPUT
- env:
AWS_REGION: us-east-1
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ vars.AWS_ROLE }}
aws-region: ${{ env.AWS_REGION }}
- id: login-ecr
uses: aws-actions/amazon-ecr-login@v2
with:
registry-type: public
- env:
AWS_REGISTRY: ${{ steps.login-ecr.outputs.registry }}
AWS_REGISTRY_ALIAS: reactome
AWS_REPO: reactome-chatbot
IMG_TAG: ${{ steps.get-hash.outputs.SHORT_SHA }}
run: |
docker load --input /tmp/image.tar
docker image tag reactome-chatbot:${{ github.sha }} $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:$IMG_TAG
docker image tag reactome-chatbot:${{ github.sha }} $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:latest
docker push $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:$IMG_TAG
docker push $AWS_REGISTRY/$AWS_REGISTRY_ALIAS/$AWS_REPO:latest