Skip to content

Bump step-security/harden-runner from 2.19.3 to 2.19.4 #15

Bump step-security/harden-runner from 2.19.3 to 2.19.4

Bump step-security/harden-runner from 2.19.3 to 2.19.4 #15

Workflow file for this run

name: CI
on:
pull_request:
branches: [main]
push:
branches: [main]
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
unit:
name: Unit (Python ${{ matrix.python-version }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
python-version: ["3.10", "3.11", "3.12", "3.13"]
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- name: Set up Python
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: ${{ matrix.python-version }}
cache: pip
cache-dependency-path: pyproject.toml
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
pip install pre-commit
- name: Preflight (S0 toolchain contract)
run: python scripts/preflight.py
- name: Pre-commit hooks
run: pre-commit run --all-files
- name: Unit tests
run: pytest tests/unit -q
integration:
name: Integration (Aerospike CE)
runs-on: ubuntu-latest
timeout-minutes: 25
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@9af89fc71515a100421586dfdb3dc9c984fbf411 # v2.19.4
with:
egress-policy: audit
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
- name: Set up Python
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: "3.12"
cache: pip
cache-dependency-path: pyproject.toml
- name: Install dependencies
run: |
python -m pip install --upgrade pip
# CPU-only torch keeps the hosted runner under ~7 GiB RAM (lmcache pulls torch).
pip install "torch" --index-url https://download.pytorch.org/whl/cpu
pip install -e .
pip install pytest pytest-asyncio
- name: Start Aerospike CE (Docker)
run: |
chmod +x scripts/start_aerospike_ce.sh scripts/stop_aerospike_ce.sh
./scripts/start_aerospike_ce.sh
docker ps --filter "name=lmcache-aerospike-ci"
cat .aerospike-ci.env
- name: Integration tests
run: |
set -a
source .aerospike-ci.env
set +a
pytest tests/integration -v --tb=short
- name: Stop Aerospike CE
if: always()
run: ./scripts/stop_aerospike_ce.sh