Skip to content

fix(manifest): attach ModelHarnessManifest on every mode's result (#50) #64

fix(manifest): attach ModelHarnessManifest on every mode's result (#50)

fix(manifest): attach ModelHarnessManifest on every mode's result (#50) #64

Workflow file for this run

name: Test
on:
push:
branches: ["main"]
pull_request:
jobs:
test:
name: "pytest / py${{ matrix.python-version }}"
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
python-version: ["3.11", "3.12", "3.13"]
steps:
- uses: actions/checkout@v7
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v6
with:
python-version: ${{ matrix.python-version }}
- name: Cache pip
uses: actions/cache@v5
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ matrix.python-version }}-${{ hashFiles('pyproject.toml') }}
restore-keys: |
${{ runner.os }}-pip-${{ matrix.python-version }}-
- name: Install package with dev extras
run: pip install -e ".[dev]"
- name: Run tests with coverage
run: pytest -q --cov=conclave --cov-report=term-missing --cov-fail-under=75
lint:
name: "ruff"
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Set up Python 3.12
uses: actions/setup-python@v6
with:
python-version: "3.12"
- name: Cache pip
uses: actions/cache@v5
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-ruff-${{ hashFiles('pyproject.toml') }}
- name: Install ruff
run: pip install ruff
- name: ruff check
run: ruff check .
- name: ruff format --check
run: ruff format --check .
audit:
name: "pip-audit"
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Set up Python 3.12
uses: actions/setup-python@v6
with:
python-version: "3.12"
- name: Cache pip
uses: actions/cache@v5
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-audit-${{ hashFiles('pyproject.toml') }}
# Install the project so its resolved runtime + dev deps are present in the
# environment, then audit that environment. conclave is security-positioned,
# so this gate is FAIL-CLOSED: a known vulnerability in any resolved
# dependency fails CI. The dep surface is tiny (httpx + a few well-maintained
# libs), so false-positive churn is low. If a transitive CVE with no fix
# blocks an unrelated PR, suppress it narrowly with
# `--ignore-vuln <GHSA/PYSEC id>` and a tracking note (see RELEASING.md).
- name: Install package with dev extras
run: pip install -e ".[dev]"
- name: Install pip-audit
run: pip install pip-audit
# `--skip-editable` drops the local editable `conclave` install (it is not on
# PyPI and cannot be audited); every real dependency is still audited.
- name: Audit resolved dependencies for known vulnerabilities
run: pip-audit --skip-editable