CI: update checkout, setup-python, setup-uv, codecov - #89
Conversation
Two related CI bugs, both caused by stale GitHub Action version pins: 1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. This repo's setup-uv pin was already a SHA (3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag v7.1.0 — past the fix that matters here (v6.0.0 added pyproject.toml to the default glob) and past the Node 20 -> Node 24 runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency with the other repos in this cleanup. 2. Node.js 20 deprecation: actions/checkout and actions/setup-python bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning. codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the singular `file:` input in favor of `files:`, renamed accordingly. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audplot's dependency tree (audmath, audmetric, matplotlib, pandas, seaborn) has no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Part of the same CI cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, audeering/audiofile#193, audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63, and audeering/audobject#127. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Reviewer's guide (collapsed on small PRs)Reviewer's GuideUpdates all CI workflows to use latest major versions of core GitHub Actions and fixes uv and Codecov integration so caching and coverage upload behave as expected while removing Node.js 20 deprecation warnings. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path=".github/workflows/publish.yml" line_range="24" />
<code_context>
- name: Set up Python ${{ matrix.python-version }}
- uses: actions/setup-python@v5
+ uses: actions/setup-python@v7
with:
python-version: ${{ matrix.python-version }}
</code_context>
<issue_to_address>
**🚨 suggestion (security):** Given this workflow publishes artifacts, consider extra caution with unpinned major action versions.
Because this workflow produces publishable artifacts, even minor changes in `setup-python` (e.g., different patch versions or environment details) can alter outputs. Consider pinning to a specific `v7.x.y` or SHA here, while leaving other workflows on the major tag if desired.
</issue_to_address>Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
|
|
||
| - name: Set up Python | ||
| uses: actions/setup-python@v5 | ||
| uses: actions/setup-python@v7 |
There was a problem hiding this comment.
🚨 suggestion (security): Given this workflow publishes artifacts, consider extra caution with unpinned major action versions.
Because this workflow produces publishable artifacts, even minor changes in setup-python (e.g., different patch versions or environment details) can alter outputs. Consider pinning to a specific v7.x.y or SHA here, while leaving other workflows on the major tag if desired.
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Re: pinning more tightly on publish.yml specifically — keeping the same floating major tag ( |
Summary
Two related CI bugs, both caused by stale GitHub Action version pins:
Dead uv caching:
astral-sh/setup-uv's defaultcache-dependency-globkeys on
uv.lock/requirements*.txt, neither of which exists here (nocommitted lockfile, by design), so caching never actually worked. This
repo's
setup-uvpin was already a SHA(
3259c6206f993105e3a61b142c2d97bf4b9ef83d), which resolves to tagv7.1.0— already past the fix that matters here (v6.0.0addedpyproject.tomlto the default glob) and past the Node 20 -> Node 24runtime bump (
v7.0.0). Bumping tov9.0.0anyway, for consistencywith the other repos in this cleanup.
Node.js 20 deprecation:
actions/checkoutandactions/setup-pythonbumped
v4/v5->v7, clearing the "Node.js 20 is deprecated" warning.codecov/codecov-actionbumpedv4->v7; itsv5rewrite dropped thesingular
file:input in favor offiles:, renamed accordingly. Noactions/cacheusage exists in this repo's workflows.prune-cacheleft at its new default (off): audplot's dependency tree(audmath, audmetric, matplotlib, pandas, seaborn) has no large pre-built
binary wheels like torch, so pruning would save ~0 disk space while
costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.
Test plan
established pattern from sibling repos