Repository navigation
security: action.yml shell injection #63
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [ main ] | |
| pull_request: | |
| branches: [ main ] | |
| permissions: | |
| contents: write | |
| jobs: | |
| lint: | |
| name: Code Quality & Type Check | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Python 3.11 | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| - name: Install dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -e ".[dev]" | |
| - name: Verify Lockfile Integrity | |
| run: | | |
| pip install --require-hashes -r requirements.lock | |
| - name: Run Ruff Linter | |
| run: | | |
| ruff check . | |
| - name: Run Ruff Format Check | |
| run: | | |
| ruff format --check . | |
| - name: Run Mypy Strict Type Check | |
| run: | | |
| mypy promptdiff | |
| - name: Verify JSON Schema Sync | |
| run: | | |
| python -c "from promptdiff.core.models import DiffReport; import json, pathlib, sys; current = json.loads(pathlib.Path('examples/schema.json').read_text(encoding='utf-8')); expected = DiffReport.model_json_schema(); sys.exit(0 if current == expected else 1)" | |
| - name: Run pip-audit supply chain vulnerability scan | |
| run: | | |
| pip-audit . --desc --strict | |
| - name: Run Bandit Static Security Analysis | |
| run: | | |
| bandit -r promptdiff -ll | |
| test: | |
| name: Test (${{ matrix.os }} - Py${{ matrix.python-version }}) | |
| needs: [lint] | |
| runs-on: ${{ matrix.os }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, windows-latest, macos-latest] | |
| python-version: ["3.10", "3.11", "3.12", "3.13"] | |
| exclude: | |
| # Run full matrix on Ubuntu, spot-check primary versions on Windows & macOS to conserve CI minutes | |
| - os: windows-latest | |
| python-version: "3.10" | |
| - os: windows-latest | |
| python-version: "3.13" | |
| - os: macos-latest | |
| python-version: "3.10" | |
| - os: macos-latest | |
| python-version: "3.13" | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Python ${{ matrix.python-version }} | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| - name: Install dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -e ".[dev]" | |
| - name: Run test suite with coverage | |
| run: | | |
| pytest --junitxml=reports/junit.xml --cov=promptdiff --cov-report=xml:reports/coverage.xml --cov-report=term-missing --cov-fail-under=85 | |
| - name: Generate dynamic test and coverage badges | |
| if: matrix.os == 'ubuntu-latest' && matrix.python-version == '3.11' | |
| run: | | |
| mkdir -p .github/badges | |
| genbadge coverage -i reports/coverage.xml -o .github/badges/coverage.svg | |
| genbadge tests -i reports/junit.xml -o .github/badges/tests.svg | |
| - name: Commit updated badges | |
| if: github.ref == 'refs/heads/main' && matrix.os == 'ubuntu-latest' && matrix.python-version == '3.11' | |
| run: | | |
| git config --local user.email "action@github.com" | |
| git config --local user.name "GitHub Action" | |
| git add .github/badges/coverage.svg .github/badges/tests.svg | |
| git commit -m "chore(badges): update dynamic coverage and test badges [skip ci]" || echo "No badge changes" | |
| git push || echo "No push needed" | |
| - name: Test promptdiff regression CLI (Mock mode) | |
| run: promptdiff test examples/prompts/support_bot_v1.txt examples/prompts/support_bot_v2.txt --inputs examples/testcases.jsonl --eval "json_validity,latency,cost,similarity" --mock --export-markdown regression-report.md --export-html regression-report.html | |
| - name: Upload regression test report artifact | |
| uses: actions/upload-artifact@v4 | |
| if: matrix.os == 'ubuntu-latest' && matrix.python-version == '3.11' | |
| with: | |
| name: regression-report-py${{ matrix.python-version }} | |
| path: | | |
| regression-report.md | |
| regression-report.html | |
| build-package: | |
| name: Build & Validate Distribution Packages | |
| needs: [test] | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Python 3.11 | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| - name: Install build tools | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install build twine | |
| - name: Build sdist and wheel | |
| run: | | |
| python -m build | |
| - name: Validate distribution packages with Twine | |
| run: | | |
| twine check dist/* |