Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 15 additions & 3 deletions .github/workflows/coverage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,30 @@ on:
- push
- pull_request

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build:

name: Coverage
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false

- name: Set up Python 3.x
uses: actions/setup-python@v6
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: '3.10'

- name: Install Dependencies
run: pip install tox

- name: Coverage
run: tox -e coverage
18 changes: 15 additions & 3 deletions .github/workflows/documentation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,30 @@ on:
- push
- pull_request

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build:

name: Documentation
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false

- name: Set up Python 3.x
uses: actions/setup-python@v6
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: '3.10'

- name: Install Dependencies
run: pip install tox

- name: Check Documentation
run: tox -e docs
70 changes: 70 additions & 0 deletions .github/workflows/github_workflows.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
name: GitHub Workflows

on:
- push
- pull_request
- workflow_dispatch

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
actionlint:
name: actionlint
runs-on: ubuntu-latest
timeout-minutes: 15

steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
persist-credentials: false

- name: Download and verify actionlint
# curl --fail makes an HTTP/network error a hard failure instead of silently
# producing a truncated file; --retry survives transient network blips.
# Verifying the published checksum also catches a corrupted-but-complete download.
# No --retry-delay, so curl backs off exponentially rather than spending every
# attempt within a few seconds.
env:
ACTIONLINT_VERSION: 1.7.12
run: |
set -euo pipefail
asset="actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
base_url="https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}"

curl --fail --silent --show-error --location --retry 5 --retry-connrefused --retry-max-time 300 --max-time 60 \
-o "$asset" "${base_url}/${asset}"
curl --fail --silent --show-error --location --retry 5 --retry-connrefused --retry-max-time 300 --max-time 30 \
-o checksums.txt "${base_url}/actionlint_${ACTIONLINT_VERSION}_checksums.txt"

grep " ${asset}\$" checksums.txt | sha256sum -c -
tar -xzf "$asset" actionlint

- name: Run actionlint
run: ./actionlint -color

zizmor:
name: zizmor
runs-on: ubuntu-latest
timeout-minutes: 15

steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 1
persist-credentials: false

- name: Install uv
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0

- name: Run zizmor
env:
ZIZMOR_VERSION: 1.30.1
run: uvx --from "zizmor==${ZIZMOR_VERSION}" zizmor --persona=auditor --collect=workflows .
18 changes: 15 additions & 3 deletions .github/workflows/lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,30 @@ on:
- push
- pull_request

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build:

name: Lint
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false

- name: Set up Python 3.x
uses: actions/setup-python@v6
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: '3.10'

- name: Install Dependencies
run: pip install tox

- name: Lint
run: tox -e style
23 changes: 19 additions & 4 deletions .github/workflows/publish_flask_jwt_extended.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,25 +7,40 @@ on:
release:
types: [created]

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false

jobs:
deploy:

name: Publish to PyPI
runs-on: ubuntu-latest
environment: pypi

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false

- name: Set up Python
uses: actions/setup-python@v6
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: '3.x'

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install setuptools wheel twine

- name: Build and publish
env:
TWINE_USERNAME: ${{ secrets.PYPI_USERNAME }}
TWINE_PASSWORD: ${{ secrets.PYPI_PASSWORD }}
run: |
# Switching to PyPI trusted publishing requires configuring a trusted
# publisher on the PyPI project first, so keep token-based uploads for now.
run: | # zizmor: ignore[use-trusted-publishing]
python setup.py sdist bdist_wheel
twine upload dist/*
18 changes: 15 additions & 3 deletions .github/workflows/type_check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,21 +4,33 @@ on:
- push
- pull_request

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build:

name: Type Check (Python ${{ matrix.python }})
runs-on: ubuntu-latest
strategy:
matrix:
python: ['3.10', '3.11', '3.12', '3.13', '3.14']

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false

- name: Setup Python
uses: actions/setup-python@v6
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: ${{ matrix.python }}

- name: Install Dependencies
run: pip install tox

- name: Type Check
run: tox -e mypy
20 changes: 17 additions & 3 deletions .github/workflows/unit_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,25 +4,39 @@ on:
- push
- pull_request

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build:

name: Unit Tests (Python ${{ matrix.python }})
runs-on: ubuntu-latest
strategy:
matrix:
python: ['3.10', '3.11', '3.12', '3.13', '3.14', 'pypy3.11']

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
with:
persist-credentials: false

- name: Setup Python
uses: actions/setup-python@v6
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: ${{ matrix.python }}

- name: Install Dependencies
run: pip install tox

- name: Run Tox Flask==3.x
run: tox -e py

- name: Run Tox Flask==2.1
run: tox -e flask21

- name: Run Tox Flask==2.x
run: tox -e flask2x