Skip to content

Commit 2209ddc

Browse files
authored
Merge pull request #98 from OpenRailAssociation/switch-uv-ruff-ty
chore: switch to uv/ruff/ty
2 parents 324807f + 7bce426 commit 2209ddc

20 files changed

Lines changed: 1077 additions & 1560 deletions

‎.github/actions/poetrybuild/action.yaml‎

Lines changed: 0 additions & 30 deletions
This file was deleted.
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# SPDX-FileCopyrightText: 2025 DB Systel GmbH
2+
#
3+
# SPDX-License-Identifier: Apache-2.0
4+
5+
name: "Reusable uv build workflow"
6+
description: "Reusable workflow to set up Python and install dependencies via uv. The Python version and additional uv arguments can be configured via inputs."
7+
inputs:
8+
python:
9+
default: "3.14"
10+
description: "Value for 'python-version'"
11+
required: false
12+
type: string
13+
uv_args:
14+
default: ""
15+
description: "Additional arguments for the uv install step'"
16+
required: false
17+
type: string
18+
runs:
19+
using: "composite"
20+
steps:
21+
- name: Set up Python
22+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
23+
with:
24+
python-version: ${{ inputs.python }}
25+
- name: Install uv
26+
uses: astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57 # v8.0.0
27+
with:
28+
enable-cache: true
29+
- name: Setup project
30+
run: |
31+
uv_args="${UV_ARGS}"
32+
uv sync --locked --all-extras --dev $uv_args
33+
env:
34+
UV_ARGS: ${{ inputs.uv_args }}
35+
shell: bash

‎.github/workflows/publish.yaml‎

Lines changed: 18 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,11 +8,25 @@ on:
88
types: [published]
99

1010
jobs:
11-
build:
11+
pypi-publish:
1212
runs-on: ubuntu-latest
13+
environment:
14+
name: pypi
15+
url: https://pypi.org/p/purl-tools
16+
permissions:
17+
id-token: write
18+
contents: read
1319
steps:
1420
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
15-
- name: Build and publish to PyPI
16-
uses: JRubics/poetry-publish@4b3306307f536bbfcb559603629b3b4f6aef5ab8 # v2.1
1721
with:
18-
pypi_token: ${{ secrets.PYPI_TOKEN }}
22+
persist-credentials: false
23+
- name: Set up Python
24+
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
25+
- name: Install uv
26+
uses: astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57 # v8.0.0
27+
with:
28+
enable-cache: false # avoid cache-poisoning attacks
29+
- name: Build package
30+
run: uv build
31+
- name: Publish package to PyPI
32+
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0

‎.github/workflows/release-vulnerabilities.yaml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,9 @@ on:
88
schedule:
99
- cron: "35 9 * * 1" # run a check once a week
1010

11+
permissions:
12+
contents: read
13+
1114
jobs:
1215
osv-check:
1316
runs-on: ubuntu-latest

‎.github/workflows/test.yaml‎

Lines changed: 36 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -10,16 +10,19 @@ on:
1010
- main
1111
pull_request:
1212

13+
permissions:
14+
contents: read
15+
1316
jobs:
14-
# Test using the tool via poetry on different OSes and python versions
17+
# Test using the tool via uv on different OSes and python versions
1518
test-os-python-matrix:
1619
runs-on: ${{ matrix.os }}
1720
strategy:
1821
max-parallel: 10
1922
# do not abort the whole test job if one combination in the matrix fails
2023
fail-fast: false
2124
matrix:
22-
python-version: ["3.10", "3.11", "3.12", "3.13"]
25+
python-version: ["3.10", "3.11", "3.12", "3.13", "3.14"]
2326
os: [ubuntu-22.04]
2427
include:
2528
- python-version: "3.10"
@@ -29,73 +32,76 @@ jobs:
2932

3033
steps:
3134
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
32-
- uses: ./.github/actions/poetrybuild
35+
with:
36+
persist-credentials: false
37+
- uses: ./.github/actions/uvbuild
3338
with:
3439
python: ${{ matrix.python-version }}
35-
poetry_args: --only main
40+
uv_args: --no-dev
3641
- name: Execute purl-tools
37-
run: poetry run purl-tools --help
42+
run: uv run purl-tools --help
3843

3944
# Test building the package and installing it via pip3
4045
test-build-install:
4146
runs-on: ubuntu-24.04
4247
steps:
4348
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
44-
- name: Install poetry
45-
run: pipx install poetry
49+
with:
50+
persist-credentials: false
4651
- name: Set up Python
4752
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
4853
with:
4954
python-version: "3.14"
50-
cache: "poetry"
55+
- name: Install uv
56+
uses: astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57 # v8.0.0
57+
with:
58+
enable-cache: true
5159
- name: Build package
52-
run: poetry build
60+
run: uv build
5361
- name: Install package
5462
run: pip3 install dist/purl_tools-*.tar.gz
5563
- name: Run package
5664
run: |
5765
purl-tools --version
5866
purl-tools --help
5967
60-
# Formatting
61-
pylint:
68+
# Quality checks
69+
ruff:
6270
runs-on: ubuntu-24.04
6371
steps:
6472
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
65-
- uses: ./.github/actions/poetrybuild
66-
- name: Lint with pylint
67-
run: poetry run pylint --disable=fixme purltools/ tests/
68-
69-
formatting:
70-
runs-on: ubuntu-24.04
71-
steps:
72-
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
73-
- uses: ./.github/actions/poetrybuild
74-
- name: Test formatting with isort and black
75-
run: |
76-
poetry run isort --check purltools/ tests/
77-
poetry run black --check .
73+
with:
74+
persist-credentials: false
75+
- uses: ./.github/actions/uvbuild
76+
- name: Lint with ruff
77+
run: uv run ruff check
7878

79-
mypy:
79+
ty:
8080
runs-on: ubuntu-24.04
8181
steps:
8282
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
83-
- uses: ./.github/actions/poetrybuild
84-
- name: Test typing with mypy
85-
run: poetry run mypy
83+
with:
84+
persist-credentials: false
85+
- uses: ./.github/actions/uvbuild
86+
- name: Test typing with ty
87+
run: uv run ty check
8688

8789
pytest:
8890
runs-on: ubuntu-24.04
8991
steps:
9092
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
91-
- uses: ./.github/actions/poetrybuild
93+
with:
94+
persist-credentials: false
95+
- uses: ./.github/actions/uvbuild
9296
- name: Test with pytest
93-
run: poetry run pytest
97+
run: uv run pytest
9498

9599
# REUSE
96100
reuse:
97101
runs-on: ubuntu-latest
98102
steps:
99103
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
104+
with:
105+
persist-credentials: false
100106
- name: Check REUSE Compliance
101107
uses: fsfe/reuse-action@676e2d560c9a403aa252096d99fcab3e1132b0f5 # v6.0.0

0 commit comments

Comments
 (0)