Enhance validation script and CI workflow for code quality checks - Added support for a --fix option in validate.sh to apply Ruff auto-fixes for formatting and linting. - Updated GitHub Actions workflow to include separate steps for installing development and runtime dependencies. - Introduced dedicated steps for code formatting and linting checks using Ruff, along with type checking and security analysis using mypy and Bandit.
102 lines
3.1 KiB
YAML
102 lines
3.1 KiB
YAML
name: Quality gate
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
pull_request:
|
|
branches:
|
|
- main
|
|
types: [ opened, synchronize, reopened ]
|
|
|
|
jobs:
|
|
sonar:
|
|
name: SonarQube Analysis
|
|
runs-on: ubuntu-latest
|
|
permissions: write-all
|
|
steps:
|
|
- name: ⬇️ Checkout Code
|
|
uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
persist-credentials: false
|
|
|
|
- name: Generate App Token
|
|
id: generate-app-token
|
|
uses: actions/create-github-app-token@v1
|
|
with:
|
|
app-id: ${{ secrets.APP_ID }}
|
|
private-key: ${{ secrets.APP_PRIVATE_KEY }}
|
|
owner: 'Aignosi'
|
|
repositories: 'sientia-dataops-library'
|
|
|
|
- name: Prepare requirements.txt
|
|
id: prepare-requirements
|
|
run: |
|
|
sed -e "s|git+ssh://git@github.com/|git+https://github.com/|g" \
|
|
-e "s|git@github.com:|git+https://github.com/|g" \
|
|
requirements.txt > requirements_prepared.txt
|
|
echo "PROCESSED_REQUIREMENTS_FILE=requirements_prepared.txt" >> $GITHUB_OUTPUT
|
|
|
|
- name: Configure Git to use App Token
|
|
env:
|
|
GH_APP_TOKEN: ${{ steps.generate-app-token.outputs.token }}
|
|
run: |
|
|
git config --global url."https://oauth2:${GH_APP_TOKEN}@github.com/".insteadOf "https://github.com/"
|
|
|
|
- name: 🔧 Setup Python
|
|
uses: actions/setup-python@v4
|
|
with:
|
|
python-version: "3.11"
|
|
|
|
- name: 🗄️ Cache Python dependencies
|
|
uses: actions/cache@v3
|
|
with:
|
|
path: ~/.cache/pip
|
|
key: ${{ runner.os }}-pip-${{ hashFiles(steps.prepare-requirements.outputs.PROCESSED_REQUIREMENTS_FILE) }}
|
|
restore-keys: |
|
|
${{ runner.os }}-pip-
|
|
|
|
- name: 📦 Install Development Dependencies
|
|
run: |
|
|
python -m pip install --upgrade pip
|
|
pip install -r requirements-dev.txt
|
|
|
|
- name: 📦 Install Runtime Dependencies
|
|
run: |
|
|
pip install -r ${{ steps.prepare-requirements.outputs.PROCESSED_REQUIREMENTS_FILE }}
|
|
|
|
- name: 📝 Code Formatting Check (Ruff)
|
|
run: |
|
|
echo "Checking code formatting..."
|
|
ruff format --check laborious/ tests/
|
|
continue-on-error: false
|
|
|
|
- name: 🔎 Code Linting (Ruff)
|
|
run: |
|
|
echo "Running linting checks..."
|
|
ruff check laborious/ tests/
|
|
continue-on-error: false
|
|
|
|
- name: 🏷️ Type Checking (mypy)
|
|
run: |
|
|
echo "Running type checks..."
|
|
mypy laborious/
|
|
continue-on-error: true
|
|
|
|
- name: 🔒 Security Analysis (Bandit)
|
|
run: |
|
|
echo "Running security analysis..."
|
|
bandit -r laborious/ -ll -q
|
|
continue-on-error: true
|
|
|
|
- name: 🧪 Run Tests with Pytest
|
|
run: |
|
|
pytest tests --junitxml=pytest.xml --cov=orchestrator --cov-report=xml --cov-report=term
|
|
|
|
- name: Run SonarQube Analysis
|
|
uses: SonarSource/sonarqube-scan-action@v5
|
|
env:
|
|
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
|
|
SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}
|