mirror of
https://github.com/domainaware/parsedmarc.git
synced 2026-08-19 13:43:20 +00:00
Port mailsuite's tag-triggered release pipeline: - Add release.yml: pushing a version tag runs the full CI suite (python-tests.yml via workflow_call), then builds the package (the tag must match the version in parsedmarc/constants.py, checked with `hatch version`), publishes to PyPI via Trusted Publishing, creates the GitHub Release with notes from the tag's CHANGELOG.md section and the built distributions attached, pushes the multi-arch Docker image, and deploys the Sphinx docs - Add docs.yml: reusable docs build/deploy to GitHub Pages, also runnable on demand (workflow_dispatch) for documentation-only changes between releases - docker.yml: add a workflow_call trigger with a push_image input, since a GitHub Release created with the workflow's own GITHUB_TOKEN emits no `release: published` event; release.yml calls it directly instead - Remove the legacy build.sh / publish-docs.sh manual process - AGENTS.md: CRITICAL rule that releases require explicit maintainer permission, plus docs for the new release flow and its one-time repo/PyPI configuration prerequisites - Bump the mailsuite floor to >=2.3.0 (raises the transitive mail-parser floor to >=4.6.2 and cryptography to >=50.0.0) Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
106 lines
2.9 KiB
YAML
106 lines
2.9 KiB
YAML
name: Python tests
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
branches: [ master ]
|
|
pull_request:
|
|
branches: [ master ]
|
|
workflow_call:
|
|
|
|
jobs:
|
|
lint-docs-build:
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- uses: actions/checkout@v5
|
|
- name: Set up Python
|
|
uses: actions/setup-python@v6
|
|
with:
|
|
python-version: "3.13"
|
|
- name: Install Python dependencies
|
|
run: |
|
|
python -m pip install --upgrade pip
|
|
# postgresql extra included so pyright can resolve the optional
|
|
# psycopg import in parsedmarc/postgres.py
|
|
pip install .[build,postgresql]
|
|
- name: Check code style
|
|
run: |
|
|
ruff check .
|
|
ruff format --check .
|
|
- name: Check types
|
|
run: |
|
|
pyright
|
|
- name: Test building documentation
|
|
run: |
|
|
cd docs
|
|
make html
|
|
- name: Test building packages
|
|
run: |
|
|
hatch build
|
|
|
|
test:
|
|
needs: lint-docs-build
|
|
runs-on: ubuntu-latest
|
|
|
|
services:
|
|
elasticsearch:
|
|
image: elasticsearch:8.19.7
|
|
env:
|
|
discovery.type: single-node
|
|
cluster.name: parsedmarc-cluster
|
|
discovery.seed_hosts: elasticsearch
|
|
bootstrap.memory_lock: true
|
|
xpack.security.enabled: false
|
|
xpack.license.self_generated.type: basic
|
|
ports:
|
|
- 9200:9200
|
|
- 9300:9300
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
python-version: ["3.10", "3.11", "3.12", "3.13", "3.14"]
|
|
|
|
steps:
|
|
- uses: actions/checkout@v5
|
|
- name: Set up Python ${{ matrix.python-version }}
|
|
uses: actions/setup-python@v6
|
|
with:
|
|
python-version: ${{ matrix.python-version }}
|
|
- name: Install system dependencies
|
|
run: |
|
|
sudo apt-get -q update
|
|
sudo apt-get -qy install libemail-outlook-message-perl
|
|
- name: Install Python dependencies
|
|
run: |
|
|
python -m pip install --upgrade pip
|
|
pip install .[build]
|
|
- name: Run unit tests
|
|
run: |
|
|
python -m pytest --cov --cov-report=xml --junitxml=junit.xml -o junit_family=legacy tests/
|
|
- name: Test sample DMARC reports
|
|
run: |
|
|
pip install -e .
|
|
parsedmarc --debug -c ci.ini samples/aggregate/*
|
|
parsedmarc --debug -c ci.ini samples/failure/*
|
|
- name: Test building packages
|
|
run: |
|
|
hatch build
|
|
- name: Upload coverage to Codecov
|
|
uses: codecov/codecov-action@v5
|
|
with:
|
|
token: ${{ secrets.CODECOV_TOKEN }}
|
|
fail_ci_if_error: false
|
|
- name: Upload test results to Codecov
|
|
# Feeds Codecov Test Analytics (flaky-test detection, per-test
|
|
# history). Runs even on test failure so failed cases still get
|
|
# reported. Uses the same CODECOV_TOKEN as the coverage upload.
|
|
if: ${{ !cancelled() }}
|
|
uses: codecov/test-results-action@v1
|
|
with:
|
|
token: ${{ secrets.CODECOV_TOKEN }}
|
|
files: ./junit.xml
|