Email notifications, ffmpeg 8 corruption false positive, Pillow CVEs (v2.8.0) #805
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Tests | |
| on: | |
| push: | |
| branches: [ '**' ] # Run on all branches (version numbers) | |
| pull_request: | |
| branches: [ '**' ] # Run on all pull requests | |
| permissions: | |
| contents: read | |
| jobs: | |
| test: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| matrix: | |
| python-version: ["3.10", "3.11", "3.12"] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Python ${{ matrix.python-version }} | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '20' | |
| - name: Install system dependencies | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y ffmpeg imagemagick libmagic1 | |
| - name: Install Python dependencies | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install -r requirements-test.txt | |
| - name: Install Node dependencies and build frontend | |
| run: | | |
| npm install | |
| npm run build | |
| - name: Run tests with pytest | |
| env: | |
| SECRET_KEY: test-secret-key-for-github-actions | |
| run: | | |
| pytest -m "not real_media" --cov=pixelprobe --cov-report=xml --cov-report=term | |
| - name: Upload coverage to Codecov | |
| uses: codecov/codecov-action@v5 | |
| with: | |
| file: ./coverage.xml | |
| flags: unittests | |
| name: codecov-umbrella | |
| fail_ci_if_error: false | |
| # The ffmpeg/ImageMagick stderr parsers fail soft (zero events, no | |
| # exceptions), so only running them against the image's actual tool | |
| # versions catches regressions from a base-image bump. | |
| image-integration: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 45 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Build Docker image | |
| run: docker build -t pixelprobe-ci . | |
| # -p no:timeout disables the per-test timeout marks (they assume fast | |
| # local hardware); the job-level timeout-minutes is the hang backstop. | |
| - name: Run real-media parser tests inside the image | |
| run: | | |
| docker run --rm -e SECRET_KEY=ci-test-secret pixelprobe-ci \ | |
| bash -c "pip install --no-cache-dir -r requirements-test.txt && \ | |
| pip uninstall -y chardet 2>/dev/null; \ | |
| pytest tests/test_real_media_samples.py -v -p no:cacheprovider -p no:timeout -o addopts=''" | |
| - name: Verify tool versions in image | |
| run: | | |
| docker run --rm pixelprobe-ci bash -c "ffmpeg -version | head -1 && magick -version | head -1 && python --version" |