Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 5 additions & 3 deletions .github/workflows/doc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,10 @@ jobs:
python-version: [ '3.12' ]

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v5
uses: actions/setup-python@v7
with:
python-version: ${{ matrix.python-version }}

Expand All @@ -29,7 +29,9 @@ jobs:
sudo apt-get install --no-install-recommends --yes libsndfile1

- name: Install uv
uses: astral-sh/setup-uv@3259c6206f993105e3a61b142c2d97bf4b9ef83d
uses: astral-sh/setup-uv@v9.0.0
with:
cache-suffix: ${{ github.workflow }}

- name: Install package
run: |
Expand Down
8 changes: 5 additions & 3 deletions .github/workflows/linter.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,15 +12,17 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- name: Set up Python
uses: actions/setup-python@v5
uses: actions/setup-python@v7
with:
python-version: '3.12'

- name: Install uv
uses: astral-sh/setup-uv@3259c6206f993105e3a61b142c2d97bf4b9ef83d
uses: astral-sh/setup-uv@v9.0.0
with:
cache-suffix: ${{ github.workflow }}

- name: Install pre-commit hooks
run: |
Expand Down
8 changes: 5 additions & 3 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,12 +16,12 @@ jobs:
group: ${{ github.workflow }}-${{ github.ref }}

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
fetch-depth: 2

- name: Set up Python
uses: actions/setup-python@v5
uses: actions/setup-python@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 suggestion (security): Given this workflow publishes artifacts, consider extra caution with unpinned major action versions.

Because this workflow produces publishable artifacts, even minor changes in setup-python (e.g., different patch versions or environment details) can alter outputs. Consider pinning to a specific v7.x.y or SHA here, while leaving other workflows on the major tag if desired.

with:
python-version: '3.12'

Expand All @@ -31,7 +31,9 @@ jobs:
sudo apt-get -y install libsndfile1

- name: Install uv
uses: astral-sh/setup-uv@3259c6206f993105e3a61b142c2d97bf4b9ef83d
uses: astral-sh/setup-uv@v9.0.0
with:
cache-suffix: ${{ github.workflow }}

# PyPI package
- name: Build Python package
Expand Down
12 changes: 7 additions & 5 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,9 +16,9 @@ jobs:
python-version: [ '3.10', '3.11', '3.12', '3.13', '3.14' ]

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v5
uses: actions/setup-python@v7
with:
python-version: ${{ matrix.python-version }}
- name: Setup Ubuntu
Expand All @@ -27,7 +27,9 @@ jobs:
sudo apt-get -y install libsndfile1
if: matrix.os == 'ubuntu-latest'
- name: Install uv
uses: astral-sh/setup-uv@3259c6206f993105e3a61b142c2d97bf4b9ef83d
uses: astral-sh/setup-uv@v9.0.0
with:
cache-suffix: ${{ github.workflow }}
- name: Install package
run: |
uv sync
Expand All @@ -43,8 +45,8 @@ jobs:
# https://github.com/actions/runner-images/issues/7776
MPLBACKEND: Agg
- name: Upload coverage to Codecov
uses: codecov/codecov-action@v4
uses: codecov/codecov-action@v7
with:
token: ${{ secrets.CODECOV_TOKEN }}
file: ./coverage.xml
files: ./coverage.xml
if: matrix.os == 'ubuntu-latest'