99 lines
3.0 KiB
YAML

name: CI
on:
push:
branches: [main, master]
pull_request:
branches: [main, master]
env:
GIT_SSL_NO_VERIFY: "true"
jobs:
lint:
runs-on: ubuntu-latest
steps:
- name: Checkout code
run: |
git config --global --add safe.directory /home/runner/work/*/* 2>/dev/null || true
git clone https://git.example.com/jarianc/youtube-cli /tmp/youtube-cli
cd /tmp/youtube-cli
git checkout $GITHUB_SHA || git checkout $CI_COMMIT_SHA || true
cp -r /tmp/youtube-cli/. /__w/youtube-cli/youtube-cli/
- name: Install dependencies
working-directory: /__w/youtube-cli/youtube-cli
run: |
python3 -m pip install --upgrade pip
pip3 install ruff mypy
pip3 install -e ".[dev]"
- name: Run ruff
working-directory: /__w/youtube-cli/youtube-cli
run: ruff check .
- name: Run mypy
working-directory: /__w/youtube-cli/youtube-cli
run: mypy youtube_tui/
test:
runs-on: ubuntu-latest
steps:
- name: Checkout code
run: |
git config --global --add safe.directory /home/runner/work/*/* 2>/dev/null || true
git clone https://git.example.com/jarianc/youtube-cli /tmp/youtube-cli
cd /tmp/youtube-cli
git checkout $GITHUB_SHA || git checkout $CI_COMMIT_SHA || true
cp -r /tmp/youtube-cli/. /__w/youtube-cli/youtube-cli/
- name: Install dependencies
working-directory: /__w/youtube-cli/youtube-cli
run: |
python3 -m pip install --upgrade pip
pip3 install -e ".[dev]"
pip3 install -r requirements-api.txt
- name: Run pytest
working-directory: /__w/youtube-cli/youtube-cli
run: python3 -m pytest tests/ web/server/tests/ -v --tb=short
docker-build:
runs-on: ubuntu-latest
steps:
- name: Checkout code
run: |
git clone https://git.example.com/jarianc/youtube-cli /tmp/youtube-cli
cd /tmp/youtube-cli
git checkout $GITHUB_SHA || git checkout $CI_COMMIT_SHA || true
cp -r /tmp/youtube-cli/. /__w/youtube-cli/youtube-cli/
- name: Build Docker image
working-directory: /__w/youtube-cli/youtube-cli
run: |
docker build -t youtube-cli:test --no-cache .
security:
runs-on: ubuntu-latest
steps:
- name: Checkout code
run: |
git clone https://git.example.com/jarianc/youtube-cli /tmp/youtube-cli
cd /tmp/youtube-cli
git checkout $GITHUB_SHA || git checkout $CI_COMMIT_SHA || true
cp -r /tmp/youtube-cli/. /__w/youtube-cli/youtube-cli/
- name: Run bandit (Python SAST)
working-directory: /__w/youtube-cli/youtube-cli
run: |
pip3 install bandit
bandit -r youtube_cli/ youtube_tui/ web/server/ -ll
build-result:
needs: [lint, test, docker-build, security]
runs-on: ubuntu-latest
if: always()
steps:
- name: Summary
run: echo "All CI checks completed"