Skip to content

CI: update checkout, setup-python, setup-uv, codecov - #89

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#89
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock/requirements*.txt, neither of which exists here (no
    committed lockfile, by design), so caching never actually worked. This
    repo's setup-uv pin was already a SHA
    (3259c6206f993105e3a61b142c2d97bf4b9ef83d), which resolves to tag
    v7.1.0 — already past the fix that matters here (v6.0.0 added
    pyproject.toml to the default glob) and past the Node 20 -> Node 24
    runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
    with the other repos in this cleanup.

  2. Node.js 20 deprecation: actions/checkout and actions/setup-python
    bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
    codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
    singular file: input in favor of files:, renamed accordingly. No
    actions/cache usage exists in this repo's workflows.

prune-cache left at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large pre-built
binary wheels like torch, so pruning would save ~0 disk space while
costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.

Test plan

  • All workflow YAML files reviewed and diff-verified against the
    established pattern from sibling repos
  • CI passes on this PR

Two related CI bugs, both caused by stale GitHub Action version pins:

1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
   keys on uv.lock/requirements*.txt, neither of which exists here (no
   committed lockfile, by design), so caching never actually worked.
   This repo's setup-uv pin was already a SHA
   (3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
   v7.1.0 — past the fix that matters here (v6.0.0 added
   pyproject.toml to the default glob) and past the Node 20 -> Node 24
   runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
   with the other repos in this cleanup.

2. Node.js 20 deprecation: actions/checkout and actions/setup-python
   bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
   codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
   singular `file:` input in favor of `files:`, renamed accordingly.
   No actions/cache usage exists in this repo's workflows.

Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-ai Bot commented Aug 5, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates all CI workflows to use latest major versions of core GitHub Actions and fixes uv and Codecov integration so caching and coverage upload behave as expected while removing Node.js 20 deprecation warnings.

File-Level Changes

Change Details Files
Modernize core GitHub Actions to clear Node.js 20 deprecation warnings and align with current ecosystem defaults.
  • Bumped actions/checkout from v4 to v7 across all workflows.
  • Bumped actions/setup-python from v5 to v7 across all workflows.
  • Kept workflow structure, job matrices, and environment variables unchanged aside from the action version pins.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml
Fix uv-based dependency caching and align uv setup with versions used in sibling repositories.
  • Replaced SHA pin of astral-sh/setup-uv (3259c6...) with tag v9.0.0 in all workflows.
  • Implicitly picks up improved default cache-dependency-glob behavior, so caching works without a committed lockfile.
  • Left prune-cache at the default (off), relying on uv’s standard behavior for this dependency tree.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml
Update Codecov integration to the latest action major version and new input schema.
  • Bumped codecov/codecov-action from v4 to v7 in test workflow.
  • Renamed deprecated file input to files to match the v5+ schema while preserving the same coverage artifact path.
  • Kept token-based authentication and conditionals (Linux-only upload) unchanged.
.github/workflows/test.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path=".github/workflows/publish.yml" line_range="24" />
<code_context>

     - name: Set up Python ${{ matrix.python-version }}
-      uses: actions/setup-python@v5
+      uses: actions/setup-python@v7
       with:
         python-version: ${{ matrix.python-version }}
</code_context>
<issue_to_address>
**🚨 suggestion (security):** Given this workflow publishes artifacts, consider extra caution with unpinned major action versions.

Because this workflow produces publishable artifacts, even minor changes in `setup-python` (e.g., different patch versions or environment details) can alter outputs. Consider pinning to a specific `v7.x.y` or SHA here, while leaving other workflows on the major tag if desired.
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.


- name: Set up Python
uses: actions/setup-python@v5
uses: actions/setup-python@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 suggestion (security): Given this workflow publishes artifacts, consider extra caution with unpinned major action versions.

Because this workflow produces publishable artifacts, even minor changes in setup-python (e.g., different patch versions or environment details) can alter outputs. Consider pinning to a specific v7.x.y or SHA here, while leaving other workflows on the major tag if desired.

@hagenw hagenw changed the title Fix CI caching; bump checkout/setup-python off Node.js 20 CI: update checkout, setup-python, setup-uv, codecov Aug 5, 2026
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng

Copy link
Copy Markdown
Member Author

Re: pinning more tightly on publish.yml specifically — keeping the same floating major tag (actions/setup-python@v7) as every other workflow in this repo and across the rest of this rollout (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60, audonnx#115, audinterface#206, audiofile#193, audmath#76, audmetric#94, audmodel#63, audobject#127) is intentional — one consistent pinning policy across all workflows and all repos, rather than a special case for publish. setup-python's own outputs (interpreter selection) aren't part of what gets published (that's uv build's job), so patch-level drift here doesn't affect build artifact reproducibility. Leaving as-is.

@ChristianGeng
ChristianGeng merged commit 9c55318 into main Aug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants