Skip to content

windows: fix pynsist installer.cfg to generate launcher; add EntryPoi… #69

windows: fix pynsist installer.cfg to generate launcher; add EntryPoi…

windows: fix pynsist installer.cfg to generate launcher; add EntryPoi… #69

Workflow file for this run

name: Enhanced CI/CD Pipeline
on:
push:
branches: [ main, develop ]
tags: [ 'v*' ]
pull_request:
branches: [ main, develop ]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
PYTHON_VERSION: "3.11"
jobs:
# ============================================
# Code Quality & Security Checks
# ============================================
quality:
name: Code Quality & Security
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: Cache pip dependencies
uses: actions/cache@v4
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-quality-${{ hashFiles('pyproject.toml') }}
restore-keys: |
${{ runner.os }}-pip-quality-
- name: Install dependencies (dev extras)
run: |
python -m pip install --upgrade pip
pip install -e .[dev]
- name: Run Ruff linting (all source modules)
run: |
ruff check --output-format=github .
- name: Run Ruff formatting check
run: |
ruff format --check .
- name: Run MyPy type checking
run: |
mypy . --config-file=pyproject.toml || true # Allow type check failures for now
- name: Run Bandit security scan
run: |
bandit -r . -f json -o bandit-report.json --exclude=tests,venv,.venv,build,dist || true
- name: Upload security scan results
uses: actions/upload-artifact@v4
if: always()
with:
name: bandit-security-report
path: bandit-report.json
# ============================================
# Documentation Build
# ============================================
docs:
name: Documentation
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: Install documentation dependencies
run: |
python -m pip install --upgrade pip
pip install mkdocs mkdocs-material
- name: Build documentation
run: |
mkdocs build --strict
- name: Upload documentation
uses: actions/upload-artifact@v4
with:
name: documentation
path: site/
# ============================================
# Test Suite (Multi-platform)
# ============================================
test:
name: Test Suite
needs: quality
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]
python-version: ["3.11", "3.12"]
runs-on: ${{ matrix.os }}
timeout-minutes: 20
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
- name: Cache pip dependencies
uses: actions/cache@v4
with:
path: |
~/.cache/pip
~/Library/Caches/pip
%APPDATA%\pip\Cache
key: ${{ runner.os }}-pip-test-${{ matrix.python-version }}-${{ hashFiles('pyproject.toml') }}
restore-keys: |
${{ runner.os }}-pip-test-${{ matrix.python-version }}-
- name: Install system dependencies (Ubuntu)
if: runner.os == 'Linux'
run: |
sudo apt-get update
sudo apt-get install -y python3-tk
- name: Install dependencies (dev extras)
run: |
python -m pip install --upgrade pip
pip install -e .[dev]
- name: Create test data directory
run: |
mkdir -p tests/fixtures
- name: Run unit tests
run: pytest -v tests/unit/ --junitxml=pytest.xml
- name: Run integration tests
run: pytest -v -m "integration" tests/integration/
- name: Upload coverage reports to Codecov
uses: codecov/codecov-action@v4
if: matrix.os == 'ubuntu-latest' && matrix.python-version == '3.11'
with:
file: ./coverage.xml
flags: unittests
name: codecov-umbrella
token: ${{ secrets.CODECOV_TOKEN }}
continue-on-error: true # Don't fail if codecov is unavailable
- name: Upload test results
uses: actions/upload-artifact@v4
if: always()
with:
name: test-results-${{ matrix.os }}-py${{ matrix.python-version }}
path: |
pytest.xml
htmlcov/
coverage.xml
# ============================================
# Performance & ML Model Tests
# ============================================
performance:
name: Performance & ML Tests
needs: test
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: Cache pip dependencies
uses: actions/cache@v4
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-perf-${{ hashFiles('pyproject.toml') }}
- name: Install dependencies (dev extras)
run: |
python -m pip install --upgrade pip
pip install -e .[dev]
- name: Run performance benchmarks
run: pytest tests/performance/ -v --benchmark-only --benchmark-json=benchmark.json --benchmark-min-rounds=3
continue-on-error: true # Allow benchmark failures for v1.0.0
- name: Run ML model validation tests
run: pytest -v -m "ml" --timeout=300
- name: Upload benchmark results
uses: actions/upload-artifact@v4
with:
name: benchmark-results
path: benchmark.json
# ============================================
# Build & Package
# ============================================
build:
name: Build Package
needs: [quality, docs]
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 0 # Full history for setuptools_scm
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: ${{ env.PYTHON_VERSION }}
- name: Install build dependencies
run: |
python -m pip install --upgrade pip
pip install build twine hatchling
- name: Build package
run: |
python -m build
- name: Check package
run: |
twine check dist/*
- name: Upload build artifacts
uses: actions/upload-artifact@v4
with:
name: dist
path: dist/
# ============================================
# Container Build & Security Scan
# ============================================
container:
name: Container Security
needs: build
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build container image
uses: docker/build-push-action@v6
with:
context: .
push: false
load: true
tags: filantropia-solar:test
cache-from: type=gha
cache-to: type=gha,mode=max
target: final
- name: Run Trivy security scan
uses: aquasecurity/trivy-action@0.28.0
with:
image-ref: filantropia-solar:test
format: 'sarif'
output: 'trivy-results.sarif'
severity: 'CRITICAL,HIGH'
exit-code: '1'
trivyignores: '.trivyignore' # Use our ignore file for accepted risks
- name: Upload Trivy scan results
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: 'trivy-results.sarif'
continue-on-error: true
# ============================================
# SBOM generation
# ============================================
sbom:
name: SBOM
needs: build
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Generate SBOM (SPDX)
uses: anchore/sbom-action@v0
with:
path: .
format: spdx-json
output-file: sbom.spdx.json
- name: Upload SBOM
uses: actions/upload-artifact@v4
with:
name: sbom
path: sbom.spdx.json
# ============================================
# Release (GitHub only, on tags)
# ============================================
release:
name: GitHub Release
needs: [quality, test, performance, build, container, docs, sbom]
runs-on: ubuntu-latest
if: startsWith(github.ref, 'refs/tags/v')
timeout-minutes: 10
permissions:
contents: write # For GitHub releases
steps:
- name: Download build artifacts
uses: actions/download-artifact@v4
with:
name: dist
path: dist/
- name: Download SBOM artifact
uses: actions/download-artifact@v4
with:
name: sbom
path: sbom/
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
files: |
dist/*
sbom/*
generate_release_notes: true
make_latest: true