fix: auto-fix ruff errors, ignore B008 and BLE001 #12
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [ main, feat/* ] | |
| pull_request: | |
| branches: [ main ] | |
| jobs: | |
| lint: | |
| name: Lint & Format | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: '3.12' | |
| - name: Install dependencies | |
| run: | | |
| pip install ruff black | |
| - name: Run ruff | |
| run: ruff check app/ --ignore B008 | |
| - name: Run black | |
| run: black --check app/ | |
| test: | |
| name: Tests | |
| runs-on: ubuntu-latest | |
| needs: lint | |
| services: | |
| postgres: | |
| image: postgres:16-alpine | |
| env: | |
| POSTGRES_USER: fleetops | |
| POSTGRES_PASSWORD: fleetops | |
| POSTGRES_DB: fleetops | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd pg_isready | |
| --health-interval 5s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: '3.12' | |
| - name: Install dependencies | |
| run: pip install -r requirements.txt | |
| - name: Run tests | |
| env: | |
| DATABASE_URL: postgresql+asyncpg://fleetops:fleetops@localhost:5432/fleetops | |
| run: pytest tests/ --cov=app --cov-report=term-missing | |
| security: | |
| name: Security Scan | |
| runs-on: ubuntu-latest | |
| needs: lint | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup Python | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: '3.12' | |
| - name: Install security tools | |
| run: pip install bandit pip-audit | |
| - name: Run Bandit | |
| run: bandit -r app/ -ll | |
| - name: Run pip-audit | |
| run: | | |
| pip-audit -r requirements.txt \ | |
| --ignore-vuln PYSEC-2026-161 \ | |
| --ignore-vuln PYSEC-2026-248 \ | |
| --ignore-vuln PYSEC-2026-249 \ | |
| --ignore-vuln PYSEC-2026-1943 \ | |
| --ignore-vuln PYSEC-2026-1941 \ | |
| --ignore-vuln PYSEC-2026-2281 \ | |
| --ignore-vuln PYSEC-2026-2280 \ | |
| --ignore-vuln PYSEC-2026-1845 | |
| build: | |
| name: Build & Push Docker Image | |
| runs-on: ubuntu-latest | |
| needs: [ test, security ] | |
| if: github.ref == 'refs/heads/main' | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Configure AWS credentials | |
| uses: aws-actions/configure-aws-credentials@v4 | |
| with: | |
| aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} | |
| aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} | |
| aws-region: us-east-1 | |
| - name: Login to Amazon ECR | |
| id: login-ecr | |
| uses: aws-actions/amazon-ecr-login@v2 | |
| - name: Build and push image | |
| env: | |
| ECR_REGISTRY: ${{ steps.login-ecr.outputs.registry }} | |
| IMAGE_TAG: ${{ github.sha }} | |
| run: | | |
| docker build -t $ECR_REGISTRY/fleetops:$IMAGE_TAG . | |
| docker build -t $ECR_REGISTRY/fleetops:latest . | |
| docker push $ECR_REGISTRY/fleetops:$IMAGE_TAG | |
| docker push $ECR_REGISTRY/fleetops:latest |