Skip to content

CI: update checkout, setup-python, setup-uv, codecov - #127

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#127
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock / requirements*.txt, neither of which exists in this
    repo (no committed lockfile, by design). Caching has therefore silently
    never worked. Bumped from v5 to v9.0.0: v6.0.0 added
    pyproject.toml to the default glob, which is committed and changes
    exactly when a dependency does — so caching now works with no lockfile
    needed.

  2. Node.js 20 deprecation: actions/checkout@v4, actions/setup-python@v5,
    and the old setup-uv pin all still targeted the deprecated Node 20
    runtime. Bumped checkout and setup-python to v7, and setup-uv's
    v7.0.0 also carries the Node 20 → Node 24 runtime bump.
    codecov/codecov-action@v4 bumped to v7; its v5 rewrite dropped the
    singular file: input in favor of files: (plural) — renamed
    accordingly in test.yml so the coverage upload doesn't silently no-op.
    No actions/cache usage exists in this repo's workflows.

prune-cache left at its new default (off): audobject's runtime dependencies
(asttokens, audeer, oyaml, packaging) have no large pre-built binary
wheels like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.

Test plan

  • All four changed workflow YAML files validated with
    uv run --isolated --with pyyaml python3 -c "import yaml; yaml.safe_load(open('FILE'))"
  • CI passes on this PR (checkout/setup-python/setup-uv/codecov-action
    bumps exercised across the full test matrix)

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, and audeering/audmetric#94.

🤖 Generated with Claude Code

setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.

Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.

Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.

Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-ai Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates CI workflows to use newer GitHub Actions versions that run on the Node.js 24 runtime, fixes uv caching by leveraging the updated default cache glob including pyproject.toml, and updates Codecov configuration to the new multi-file input API so coverage uploads work correctly.

Sequence diagram for updated CI workflow with uv caching and Codecov

sequenceDiagram
    actor Developer
    participant GitHubActionsRunner as GitHubActionsRunner
    participant actions_checkout as actions_checkout_v7
    participant actions_setup_python as actions_setup_python_v7
    participant setup_uv as setup_uv_v9_0_0
    participant TestSuite as pytest
    participant codecov_action as codecov_action_v7

    Developer->>GitHubActionsRunner: push commit
    GitHubActionsRunner->>actions_checkout: uses actions/checkout@v7
    actions_checkout-->>GitHubActionsRunner: repository checked out

    GitHubActionsRunner->>actions_setup_python: uses actions/setup-python@v7
    actions_setup_python-->>GitHubActionsRunner: Python environment ready

    GitHubActionsRunner->>setup_uv: uses astral-sh/setup-uv@v9.0.0
    setup_uv-->>GitHubActionsRunner: cache resolved using pyproject.toml

    GitHubActionsRunner->>TestSuite: run pytest
    TestSuite-->>GitHubActionsRunner: coverage.xml generated

    GitHubActionsRunner->>codecov_action: uses codecov/codecov-action@v7
    codecov_action-->>GitHubActionsRunner: upload using files input
    GitHubActionsRunner-->>Developer: CI results and coverage reported
Loading

File-Level Changes

Change Details Files
Upgrade core GitHub Actions (checkout, setup-python, setup-uv) across all workflows to versions that support the Node.js 24 runtime and correct uv caching behavior.
  • Bump actions/checkout from v4 to v7 in test, doc, linter, and publish workflows.
  • Bump actions/setup-python from v5 to v7 in all workflows that set up Python.
  • Bump astral-sh/setup-uv from v5 to v9.0.0 so that pyproject.toml is included in the default cache-dependency-glob and uv caching becomes effective.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml
Update Codecov CI configuration to the new action major version and API to ensure coverage uploads execute correctly.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow.
  • Rename the Codecov input key from file to files to match the new action’s plural input syntax.
.github/workflows/test.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Since the same action versions and uv setup are repeated across multiple workflows (test, doc, linter, publish), consider extracting the common logic into a reusable workflow or composite action to keep these pins centralized and reduce the risk of version drift in future updates.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- Since the same action versions and uv setup are repeated across multiple workflows (test, doc, linter, publish), consider extracting the common logic into a reusable workflow or composite action to keep these pins centralized and reduce the risk of version drift in future updates.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@hagenw hagenw changed the title Fix CI caching; bump checkout/setup-python off Node.js 20 CI: update checkout, setup-python, setup-uv, codecov Aug 5, 2026
@ChristianGeng

Copy link
Copy Markdown
Member Author

Re: extracting a reusable workflow for the shared action pins — reasonable idea in the abstract, but out of scope for this PR, which is deliberately a minimal, uniform version bump across many repos rather than a refactor. Introducing a shared composite action now would mean redoing all sibling PRs (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60, audonnx#115, audinterface#206, audiofile#193, audmath#76, audmodel#63) to adopt it too. Worth raising separately if there's appetite for it.

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng merged commit fbc4585 into main Aug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:19
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20

Two related CI bugs, both caused by stale GitHub Action version pins:

1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
   keys on uv.lock/requirements*.txt, neither of which exists here (no
   committed lockfile, by design), so caching never actually worked.
   This repo's setup-uv pin was already a SHA
   (3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
   v7.1.0 — past the fix that matters here (v6.0.0 added
   pyproject.toml to the default glob) and past the Node 20 -> Node 24
   runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
   with the other repos in this cleanup.

2. Node.js 20 deprecation: actions/checkout and actions/setup-python
   bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
   codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
   singular `file:` input in favor of `files:`, renamed accordingly.
   No actions/cache usage exists in this repo's workflows.

Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Give each workflow its own uv cache to stop reservation races

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants