Skip to content

chore(release): v4.6.1 #154

chore(release): v4.6.1

chore(release): v4.6.1 #154

name: Run Pytest on pushes to main branches or PRs to any branch
# Third-party GitHub Actions are pinned to a full 40-character commit SHA
# (with a `# vX.Y.Z` trailing comment for human readability). This protects
# against tag re-pointing supply-chain attacks: a tag like `v4` is mutable
# and can be silently rewritten to malicious code, but a commit SHA is not.
# Dependabot (see .github/dependabot.yml) recognises this pattern and keeps
# both the SHA and the version comment in sync when raising update PRs.
#
# Convention reference:
# https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions#using-third-party-actions
# Tooling that automates the pin/unpin cycle:
# https://github.com/mheap/pin-github-action
on:
# Allow this exact test job to be reused by other workflows (e.g. the PyPI
# publish workflow) so that a release is gated on the SAME tests that run on
# every PR and push - no duplicated, drift-prone test steps.
workflow_call:
pull_request:
branches:
- "*"
push:
branches:
- development
- staging
- live
jobs:
test:
runs-on: ubuntu-latest
# Runs tests on multiple python versions across the range we support
strategy:
matrix:
python-version: ["3.10", "3.11", "3.12", "3.13"]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python-version }}
- name: Cache pip
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ matrix.python-version }}-${{ hashFiles('pyproject.toml', 'requirements.txt') }}
restore-keys: |
${{ runner.os }}-pip-
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install .[dev]
- name: Run pytest
run: pytest -q