Skip to content

fix: Verwendung von sudo für Flatpak-Befehle in build_flatpak.sh und … #117

fix: Verwendung von sudo für Flatpak-Befehle in build_flatpak.sh und …

fix: Verwendung von sudo für Flatpak-Befehle in build_flatpak.sh und … #117

Workflow file for this run

name: CI/CD Pipeline
on:
push:
branches: [ main, develop ]
pull_request:
branches: [ main, develop ]
release:
types: [published]
permissions:
contents: read
env:
PYTHON_VERSION: "3.9"
jobs:
debug-environment:
runs-on: ubuntu-latest
steps:
- name: Print GitHub Context
run: |
echo "GitHub Context:"
echo "Current Event Name: ${{ github.event_name }}"
echo "Current Ref: ${{ github.ref }}"
# Test-Job für verschiedene Python-Versionen
test:
runs-on: ubuntu-latest
strategy:
matrix:
python-version: ["3.8", "3.9", "3.10", "3.11", "3.12"]
fail-fast: false
steps:
- uses: actions/checkout@v4
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v4
with:
python-version: ${{ matrix.python-version }}
- name: Install system dependencies
run: |
sudo apt-get update
sudo apt-get install -y python3-tk python3-pip zenity xterm
- name: Install Python dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements.txt
pip install pytest pytest-cov flake8 black mypy
- name: Lint with flake8
run: |
flake8 bash_script_maker.py syntax_highlighter.py --count --select=E9,F63,F7,F82 --show-source --statistics
flake8 bash_script_maker.py syntax_highlighter.py --count --exit-zero --max-complexity=10 --max-line-length=127 --statistics
- name: Type check with mypy
run: |
mypy bash_script_maker.py syntax_highlighter.py --ignore-missing-imports --no-error-summary --disable-error-code=import
- name: Format check with black
run: |
black --check --diff bash_script_maker.py syntax_highlighter.py
- name: Test with pytest
run: |
python -c "import bash_script_maker; import syntax_highlighter; print('Import test passed')"
python -c "import tkinter; print('Tkinter available')"
python -c "from bash_script_maker import BashScriptMaker; print('BashScriptMaker class available')"
python -c "from syntax_highlighter import BashScriptEditor; print('BashScriptEditor class available')"
- name: Generate coverage report
run: |
python -m pytest tests/ --cov-report=xml --cov-report=term
- name: Upload coverage to Codecov
uses: codecov/codecov-action@v3
with:
file: ./coverage.xml
fail_ci_if_error: false
# Build-Job für Package-Erstellung
build:
runs-on: ubuntu-latest
needs: test
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: Install build dependencies
run: |
python -m pip install --upgrade pip
pip install build twine wheel setuptools
- name: Build package
run: python -m build
- name: Check package
run: |
python -m twine check dist/*
- name: Upload build artifacts
uses: actions/upload-artifact@v4
with:
name: python-package
path: dist/
retention-days: 30
release:
runs-on: ubuntu-latest
needs: build
if: github.event_name == 'release' && github.event.action == 'published'
permissions:
contents: write
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install build twine
- name: Download build artifacts
uses: actions/download-artifact@v4
with:
name: python-package
path: dist/
- name: Publish to PyPI
if: github.repository_owner == 'securebitsorg' && github.event_name == 'release' && github.event.action == 'published'
env:
TWINE_USERNAME: __token__
TWINE_PASSWORD: ${{ secrets.PYPI_API_TOKEN }}
run: |
python -m twine upload dist/*
# Documentation-Job
docs:
runs-on: ubuntu-latest
needs: test
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: Install documentation dependencies
run: |
python -m pip install --upgrade pip
pip install pdoc3 -r requirements.txt
- name: Generate documentation
run: |
mkdir -p docs
pdoc3 --html --output-dir docs bash_script_maker syntax_highlighter
- name: Upload documentation
uses: actions/upload-artifact@v4
with:
name: documentation
path: docs/
retention-days: 30
# Docker-Image erstellen (optional)
docker:
runs-on: ubuntu-latest
needs: build
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Generate lowercase repository name for Docker tag
id: repo
run: echo "name=$(echo ${{ github.repository }} | tr '[:upper:]' '[:lower:]')" >> $GITHUB_OUTPUT
- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata (tags, labels) for Docker
id: meta
uses: docker/metadata-action@v5
with:
images: ghcr.io/${{ steps.repo.outputs.name }}
tags: |
type=ref,event=branch
type=ref,event=pr
type=ref,event=tag
# Immer 'latest' Tag für den Default-Branch
type=raw,value=latest,enable={{is_default_branch}}
- name: Build and push Docker image
uses: docker/build-push-action@v5
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max
# Security-Scan
security:
name: Security Scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Run Bandit security linter
run: |
python -m pip install --upgrade pip
pip install bandit
bandit -r . -f json -o bandit-results.json || echo "Bandit completed with warnings"
- name: Upload bandit results
uses: actions/upload-artifact@v4
with:
name: bandit-results
path: bandit-results.json
- name: Run Safety check
run: |
python -m pip install --upgrade pip
pip install "typer<0.10.0" # Kompatibilitäts-Fix
pip install "safety==2.3.5"
safety check --file requirements.txt --full-report
# Automatisches Versionierung und Release-Erstellung
version-and-release:
runs-on: ubuntu-latest
needs: [test, build, security]
if: github.ref == 'refs/heads/main' && github.event_name == 'push'
permissions:
contents: write
pull-requests: write
issues: write
repository-projects: write
packages: write
actions: write
env:
HAS_PYPI_TOKEN: ${{ secrets.PYPI_API_TOKEN != '' }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # WICHTIG: Volle Historie für semantic-release
token: ${{ secrets.GITHUB_TOKEN }}
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: Configure Git
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
- name: Debug Git History
run: |
echo "--- CURRENT BRANCH ---"
git branch --show-current
LATEST_TAG=$(git describe --tags --abbrev=0 2>/dev/null || echo "none")
echo "--- LATEST TAG FOUND: ${LATEST_TAG} ---"
if [ "$LATEST_TAG" != "none" ]; then
echo "--- COMMITS SINCE ${LATEST_TAG} ---"
git log --oneline ${LATEST_TAG}..HEAD
else
echo "--- ALL COMMITS (no tags found) ---"
git log --oneline
fi
- name: Semantic Release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PYPI_TOKEN: ${{ secrets.PYPI_API_TOKEN }}
TWINE_USERNAME: __token__
TWINE_PASSWORD: ${{ secrets.PYPI_API_TOKEN }}
LOG_LEVEL: DEBUG
run: |
pip install python-semantic-release
semantic-release publish
# Finish