Skip to content

Bump step-security/harden-runner from 2.19.4 to 2.20.1 #43

Bump step-security/harden-runner from 2.19.4 to 2.20.1

Bump step-security/harden-runner from 2.19.4 to 2.20.1 #43

Workflow file for this run

name: CI
on:
pull_request:
branches: [main]
push:
branches: [main]
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
unit:
name: Unit (Python ${{ matrix.python-version }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
python-version: ["3.10", "3.11", "3.12", "3.13"]
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Set up Python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version: ${{ matrix.python-version }}
cache: pip
cache-dependency-path: pyproject.toml
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -e ".[dev]"
pip install pre-commit
- name: Preflight (S0 toolchain contract)
run: python scripts/preflight.py
- name: Pre-commit hooks
run: pre-commit run --all-files
- name: Unit tests
run: pytest tests/unit -q
integration:
name: Integration (Aerospike CE)
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
with:
egress-policy: audit
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Checkout LMCache (dev, L2 plugin APIs)
uses: actions/checkout@v4
with:
repository: LMCache/LMCache
ref: dev
path: LMCache
- name: Set up Python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version: "3.12"
cache: pip
cache-dependency-path: pyproject.toml
- name: Install dependencies
run: |
python -m pip install --upgrade pip wheel
# LMCache build-system pins setuptools 77–80 (see LMCache/pyproject.toml).
pip install "setuptools>=77.0.3,<81.0.0"
# CPU-only torch keeps the hosted runner under ~7 GiB RAM (lmcache pulls torch).
pip install "torch" --index-url https://download.pytorch.org/whl/cpu
# torch CPU can downgrade setuptools; restore LMCache's range before editable install.
pip install "setuptools>=77.0.3,<81.0.0" --force-reinstall
# PyPI 0.4.x lacks L2StoreResult; install dev (pure Python on CI via NO_NATIVE_EXT).
NO_NATIVE_EXT=1 pip install -e ./LMCache --no-build-isolation
pip install -e . --no-deps
pip install "aerospike>=14.0.0,<19.0.0"
pip install pytest pytest-asyncio
- name: Start Aerospike CE (Docker)
run: |
chmod +x scripts/start_aerospike_ce.sh scripts/stop_aerospike_ce.sh
./scripts/start_aerospike_ce.sh
docker ps --filter "name=lmcache-aerospike-ci"
cat .aerospike-ci.env
- name: Integration tests
run: |
set -a
source .aerospike-ci.env
set +a
pytest tests/integration -v --tb=short
- name: Stop Aerospike CE
if: always()
run: ./scripts/stop_aerospike_ce.sh