Skip to content

Merge pull request #67 from bioio-devs/dependabot/github_actions/extr… #354

Merge pull request #67 from bioio-devs/dependabot/github_actions/extr…

Merge pull request #67 from bioio-devs/dependabot/github_actions/extr… #354

Workflow file for this run

name: CI
on:
push:
branches:
- main
tags:
- "v*"
pull_request:
branches:
- main
schedule:
# <minute [0,59]> <hour [0,23]> <day of the month [1,31]>
# <month of the year [1,12]> <day of the week [0,6]>
# https://pubs.opengroup.org/onlinepubs/9699919799/utilities/crontab.html#tag_20_25_07
# Run every Monday at 10:24:00 PST
# (Since these CRONs are used by a lot of people -
# let's be nice to the servers and schedule it _not_ on the hour)
- cron: "24 18 * * 1"
workflow_dispatch:
jobs:
# Check that all files listed in manifest make it into build
check-manifest:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-python@v6
with:
python-version: "3.x"
- run: pip install check-manifest && check-manifest
# Shared lint workflow
lint:
uses: ./.github/workflows/shared_lint.yml
# Shared test workflow
test:
needs: [lint]
uses: ./.github/workflows/shared_test.yml
# Publish to PyPI if test, lint, and manifest checks passed
publish:
if: "success() && startsWith(github.ref, 'refs/tags/')"
needs: [check-manifest, lint, test]
runs-on: ubuntu-latest
environment: release
permissions:
id-token: write # IMPORTANT: this permission is mandatory for trusted publishing
steps:
- uses: actions/checkout@v6
- name: Set up Python
uses: actions/setup-python@v6
with:
python-version: "3.11"
- name: Install Dependencies
run: |
python -m pip install --upgrade pip
pip install build wheel
- name: Build Package
run: |
python -m build
- name: Publish to PyPI
uses: pypa/gh-action-pypi-publish@release/v1
# GitHub does not provide a "all status checks must pass" option
# in branch protection settings. Instead, you have to specify exactly
# what status checks want to require to pass before merging. However,
# naming each individual check would be effectively impossible.
# Therefore, by creating this stage in every repo in the org we can
# require "Report Result" to pass before merging and this stage can
# represent the result of the other checks where it only passes if
# all the other checks pass.
results:
if: ${{ always() && github.event_name == 'pull_request' }}
needs: [check-manifest, lint, test]
runs-on: ubuntu-latest
name: Report Result
steps:
- run: exit 1
# see https://stackoverflow.com/a/67532120/4907315
if: >-
${{
contains(needs.*.result, 'failure')
|| contains(needs.*.result, 'cancelled')
}}