Skip to content

chore: require an engineering approval on every change #18

chore: require an engineering approval on every change

chore: require an engineering approval on every change #18

Workflow file for this run

name: CI
# The default-branch ruleset of Kaiten's SDK repositories requires three checks, named `lint`,
# `build` and `test`. The jobs below report exactly those names; the per-version test jobs
# report under their own names, and `test` answers for all of them.
on:
push:
branches: ["main"]
pull_request:
branches: ["main"]
permissions:
contents: read
jobs:
lint:
name: lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: astral-sh/setup-uv@v6
with:
enable-cache: true
- run: uv sync --locked
# The models come from openapi/ and the sync client from the async one. A commit that
# edits either source without regenerating would ship code the repository cannot
# reproduce, so the check regenerates and compares.
- name: Generated code is up to date
run: |
uv run python scripts/generate_models.py --check
uv run python scripts/unasync.py --check
- run: uv run ruff check .
- run: uv run ruff format --check .
- run: uv run mypy
tests:
name: test (Python ${{ matrix.python-version }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
python-version: ["3.10", "3.11", "3.12", "3.13", "3.14"]
steps:
- uses: actions/checkout@v5
- uses: astral-sh/setup-uv@v6
with:
enable-cache: true
python-version: ${{ matrix.python-version }}
- run: uv sync --locked
- run: uv run pytest --cov --cov-report=term-missing
lowest-dependencies:
name: test (lowest dependencies)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: astral-sh/setup-uv@v6
with:
python-version: "3.10"
# The lower bounds in pyproject.toml are a promise to every consumer; this is what keeps
# them honest.
- run: uv sync --resolution lowest-direct
- run: uv run pytest
# The one `test` check the ruleset requires, standing for every test job above. It runs even
# when one of them failed, and passes only when all of them succeeded: a required check that
# is skipped counts as passing, so a plain `needs` would let a failure through.
test:
name: test
if: always()
needs: [tests, lowest-dependencies]
runs-on: ubuntu-latest
steps:
- name: Every test job passed
env:
RESULTS: ${{ toJSON(needs.*.result) }}
run: |
echo "test jobs: $RESULTS"
jq -e 'length > 0 and all(.[]; . == "success")' <<< "$RESULTS" > /dev/null
build:
name: build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: astral-sh/setup-uv@v6
- run: uv build
- run: uvx twine check --strict dist/*