Skip to content

chore(deps): update python #76

chore(deps): update python

chore(deps): update python #76

Workflow file for this run

# CI pipeline for the prd-build track.
#
# Coverage threshold note: --cov-fail-under=80 matches the project-wide
# coding-standards floor in rules/common/testing.md. Ratcheted from the
# prior transitional 70% in the v0.6.0 review follow-ups (batch-a #4).
# Measured at 87% locally across tests/ before the flip.
#
# ZFC lint note: the scripts/lint_zfc.py step is now blocking. Ratcheted
# from non-blocking in the v0.6.0 review follow-ups (batch-a #3). The
# allowlist in scripts/lint_zfc.allowlist.toml covers all pre-existing
# violations documented in CLAUDE.md's Known Violations section.
name: CI (prd-build)
on:
push:
branches:
- main
- "prd-build/**"
pull_request:
branches:
- main
- "prd-build/**"
jobs:
build:
name: "build (py${{ matrix.python-version }})"
runs-on: ubuntu-22.04
strategy:
fail-fast: true
matrix:
python-version: ["3.11", "3.12", "3.13"]
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v6
with:
python-version: ${{ matrix.python-version }}
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
- name: ruff
run: ruff check src/ tests/ scripts/
- name: mypy
run: mypy src/codeprobe --strict-optional
- name: pytest (coverage floor 80%)
run: pytest tests/ -x --cov=src/codeprobe --cov-fail-under=80
env:
# INV2 tenant guard: derive_tenant() fail-louds when CI=true and no
# tenant is set. Set it explicitly so the guard fires only for user
# error, not for our own test suite.
CODEPROBE_TENANT: ci-${{ github.sha }}
- name: lint_zfc (blocking)
run: python3 scripts/lint_zfc.py src/codeprobe/ --allowlist scripts/lint_zfc.allowlist.toml
- name: snapshot-format compatibility check
run: |
python3 - <<'PY'
import json
import sys
from pathlib import Path
fixture_path = Path("tests/fixtures/snapshot_compat_sha.json")
if not fixture_path.exists():
print(f"FAIL: {fixture_path} missing", file=sys.stderr)
sys.exit(1)
try:
data = json.loads(fixture_path.read_text(encoding="utf-8"))
except json.JSONDecodeError as exc:
print(f"FAIL: {fixture_path} is not valid JSON: {exc}", file=sys.stderr)
sys.exit(1)
placeholder = "TBD-partner-fixture"
required_keys = ("csb_fixture_sha", "eb_fixture_sha")
missing = [k for k in required_keys if k not in data]
if missing:
print(f"FAIL: {fixture_path} missing keys: {missing}", file=sys.stderr)
sys.exit(1)
exit_code = 0
for key in required_keys:
value = data[key]
if value == placeholder:
print(f"WARN: {key} is still the placeholder '{placeholder}' — pin once partner fixture selected")
continue
# Real SHAs would be compared against the CSB/EB fixture SHA here.
# For now, any non-placeholder value is accepted; a dedicated
# work unit will wire the real comparison in.
print(f"OK: {key} pinned to {value}")
sys.exit(exit_code)
PY
# macOS coverage for mining (codeprobe-ra12). Publication renames a staged
# directory into place with a descriptor-relative, fail-if-destination-exists
# rename, and that syscall is spelled differently per platform —
# renameat2/RENAME_NOREPLACE on Linux, renameatx_np/RENAME_EXCL on Darwin.
# The ubuntu matrix cannot exercise the Darwin branch, so a real macOS runner
# is what keeps the "Operating System :: MacOS :: MacOS X" classifier honest.
# Runs on every push to main, so no tag is ever cut from an unverified tree.
mining-macos:
name: mining (macos)
runs-on: macos-latest
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Set up Python 3.12
uses: actions/setup-python@v6
with:
python-version: "3.14.8"
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
- name: pytest (mining)
run: pytest tests/mining/ -x
env:
CODEPROBE_TENANT: ci-${{ github.sha }}
# The self-serve acceptance exit gate (codeprobe-f7rl.46): from nothing
# but a built wheel in a fresh venv, proves a customer can install
# skills, mine a fixture repo, run an MCP-vs-baseline A/B comparison,
# and get an honest HTML report — and that the four honesty refusals
# actually refuse. Required in normal CI (not just at release time) so a
# regression is caught on the PR that introduced it, not months later
# when someone finally tags a release.
e2e-self-serve:
name: e2e-self-serve
needs: [build]
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Set up Python 3.12
uses: actions/setup-python@v6
with:
python-version: "3.14.8"
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
- name: Self-serve acceptance harness
run: python scripts/e2e/self_serve_acceptance.py