Skip to content

security: action.yml shell injection #63

security: action.yml shell injection

security: action.yml shell injection #63

Workflow file for this run

name: CI
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
permissions:
contents: write
jobs:
lint:
name: Code Quality & Type Check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python 3.11
uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
- name: Verify Lockfile Integrity
run: |
pip install --require-hashes -r requirements.lock
- name: Run Ruff Linter
run: |
ruff check .
- name: Run Ruff Format Check
run: |
ruff format --check .
- name: Run Mypy Strict Type Check
run: |
mypy promptdiff
- name: Verify JSON Schema Sync
run: |
python -c "from promptdiff.core.models import DiffReport; import json, pathlib, sys; current = json.loads(pathlib.Path('examples/schema.json').read_text(encoding='utf-8')); expected = DiffReport.model_json_schema(); sys.exit(0 if current == expected else 1)"
- name: Run pip-audit supply chain vulnerability scan
run: |
pip-audit . --desc --strict
- name: Run Bandit Static Security Analysis
run: |
bandit -r promptdiff -ll
test:
name: Test (${{ matrix.os }} - Py${{ matrix.python-version }})
needs: [lint]
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]
python-version: ["3.10", "3.11", "3.12", "3.13"]
exclude:
# Run full matrix on Ubuntu, spot-check primary versions on Windows & macOS to conserve CI minutes
- os: windows-latest
python-version: "3.10"
- os: windows-latest
python-version: "3.13"
- os: macos-latest
python-version: "3.10"
- os: macos-latest
python-version: "3.13"
steps:
- uses: actions/checkout@v4
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
- name: Run test suite with coverage
run: |
pytest --junitxml=reports/junit.xml --cov=promptdiff --cov-report=xml:reports/coverage.xml --cov-report=term-missing --cov-fail-under=85
- name: Generate dynamic test and coverage badges
if: matrix.os == 'ubuntu-latest' && matrix.python-version == '3.11'
run: |
mkdir -p .github/badges
genbadge coverage -i reports/coverage.xml -o .github/badges/coverage.svg
genbadge tests -i reports/junit.xml -o .github/badges/tests.svg
- name: Commit updated badges
if: github.ref == 'refs/heads/main' && matrix.os == 'ubuntu-latest' && matrix.python-version == '3.11'
run: |
git config --local user.email "action@github.com"
git config --local user.name "GitHub Action"
git add .github/badges/coverage.svg .github/badges/tests.svg
git commit -m "chore(badges): update dynamic coverage and test badges [skip ci]" || echo "No badge changes"
git push || echo "No push needed"
- name: Test promptdiff regression CLI (Mock mode)
run: promptdiff test examples/prompts/support_bot_v1.txt examples/prompts/support_bot_v2.txt --inputs examples/testcases.jsonl --eval "json_validity,latency,cost,similarity" --mock --export-markdown regression-report.md --export-html regression-report.html
- name: Upload regression test report artifact
uses: actions/upload-artifact@v4
if: matrix.os == 'ubuntu-latest' && matrix.python-version == '3.11'
with:
name: regression-report-py${{ matrix.python-version }}
path: |
regression-report.md
regression-report.html
build-package:
name: Build & Validate Distribution Packages
needs: [test]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python 3.11
uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Install build tools
run: |
python -m pip install --upgrade pip
pip install build twine
- name: Build sdist and wheel
run: |
python -m build
- name: Validate distribution packages with Twine
run: |
twine check dist/*