Repository navigation
Feature/GitHub pipeline #3
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Pull Request Checks | |
| on: | |
| pull_request: | |
| branches: [ main, develop ] | |
| types: [opened, synchronize, reopened] | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| issues: write | |
| checks: write | |
| jobs: | |
| pr-checks: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| matrix: | |
| python-version: [3.10.x, 3.11.x, 3.12.x] | |
| services: | |
| postgres: | |
| image: postgres:15 | |
| env: | |
| POSTGRES_PASSWORD: postgres | |
| POSTGRES_USER: postgres | |
| POSTGRES_DB: test_backend | |
| options: >- | |
| --health-cmd pg_isready | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| ports: | |
| - 5432:5432 | |
| redis: | |
| image: redis:7 | |
| options: >- | |
| --health-cmd "redis-cli ping" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| ports: | |
| - 6379:6379 | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Set up Python ${{ matrix.python-version }} | |
| uses: actions/setup-python@v4 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| - name: Cache pip dependencies | |
| uses: actions/cache@v3 | |
| with: | |
| path: ~/.cache/pip | |
| key: ${{ runner.os }}-pip-${{ hashFiles('**/requirements.txt') }} | |
| restore-keys: | | |
| ${{ runner.os }}-pip- | |
| - name: Install dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -r requirements.txt | |
| - name: Set up environment variables | |
| run: | | |
| echo "DJANGO_DEBUG=False" >> $GITHUB_ENV | |
| echo "SECRET_KEY=test-secret-key-for-ci" >> $GITHUB_ENV | |
| echo "ALLOWED_HOSTS=localhost,127.0.0.1" >> $GITHUB_ENV | |
| echo "DATABASE_TYPE=pgsql" >> $GITHUB_ENV | |
| echo "DATABASE_USER=postgres" >> $GITHUB_ENV | |
| echo "DATABASE_PASSWORD=postgres" >> $GITHUB_ENV | |
| echo "DATABASE_HOST=localhost" >> $GITHUB_ENV | |
| echo "DATABASE_PORT=5432" >> $GITHUB_ENV | |
| echo "DATABASE_NAME=test_backend" >> $GITHUB_ENV | |
| echo "REDIS_HOST=localhost" >> $GITHUB_ENV | |
| echo "REDIS_PORT=6379" >> $GITHUB_ENV | |
| echo "REDIS_DB=0" >> $GITHUB_ENV | |
| - name: Run migrations | |
| run: | | |
| python manage.py migrate | |
| - name: Run Django system checks | |
| run: | | |
| python manage.py check | |
| - name: Run tests with coverage | |
| run: | | |
| pytest --verbose --tb=short --cov=. --cov-report=xml --cov-report=term | |
| - name: Upload coverage to Codecov | |
| uses: codecov/codecov-action@v3 | |
| with: | |
| file: ./coverage.xml | |
| flags: unittests | |
| name: codecov-umbrella | |
| fail_ci_if_error: false | |
| - name: Comment PR with test results | |
| uses: actions/github-script@v7 | |
| if: github.event_name == 'pull_request' | |
| with: | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| script: | | |
| try { | |
| const comment = `## π§ͺ Test Results for Python ${{ matrix.python-version }} | |
| β **All tests passed successfully!** | |
| ### π Summary: | |
| - β Django system checks passed | |
| - β Database migrations applied | |
| - β Unit tests completed | |
| - β Code coverage generated | |
| ### ποΈ Build Information: | |
| - **Python Version**: ${{ matrix.python-version }} | |
| - **Django Version**: 5.2.1 | |
| - **Database**: PostgreSQL 15 | |
| - **Cache**: Redis 7 | |
| --- | |
| *This comment was automatically generated by the CI pipeline.*`; | |
| await github.rest.issues.createComment({ | |
| issue_number: context.issue.number, | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| body: comment | |
| }); | |
| } catch (error) { | |
| console.log('Failed to post comment:', error.message); | |
| // Don't fail the workflow if commenting fails | |
| } | |
| - name: Lint with flake8 | |
| run: | | |
| flake8 . --count --select=E9,F63,F7,F82 --show-source --statistics | |
| flake8 . --count --exit-zero --max-complexity=10 --max-line-length=127 --statistics | |
| - name: Check code formatting with black | |
| run: | | |
| black --check --diff . | |
| - name: Check import sorting with isort | |
| run: | | |
| isort --check-only --diff . | |
| - name: Security scan with bandit | |
| run: | | |
| bandit -r . --severity-level medium | |
| - name: Dependency security check | |
| run: | | |
| # Install compatible versions for safety | |
| pip install "typer<0.13.0" "safety==2.4.0b2" || pip install "safety<3.0.0" | |
| # Run safety check with fallback | |
| safety check || { | |
| echo "Safety check failed, trying pip-audit as fallback..." | |
| pip install pip-audit | |
| pip-audit --desc || echo "Dependency security scan completed with warnings" | |
| } |