Modernize the CI and Release workflows, and reformat with black - #9
Merged
Merged
Conversation
The Makefile has linted and formatted with black for a while, but the code was still in yapf's style and the CI workflow still ran yapf. Reformat the package so the two agree, drop the [yapf] section from setup.cfg, and set flake8's line length and E203 to match black. No functional change. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Neither workflow has run in this repository's recorded history, and the last
release was 0.9.1 in May 2021. Everything they depend on has moved on:
actions/checkout@v1 -> v4 (v1 runs on a Node runtime GitHub
actions/setup-python@v1 -> v5 has removed, so it fails outright)
conda-incubator/setup-miniconda@v2 -> v3
codecov/codecov-action@v2 -> v4
pypa/gh-action-pypi-publish@master -> @release/v1, and repository_url is
spelled repository-url now
Python 3.7, 3.8 -> 3.11, 3.12 (3.7 and 3.8 are end of life
and conda-forge no longer builds for them)
The test environment had an empty `channels:`, so nothing came from conda-forge.
It now asks for conda-forge, and for black, which the linters need.
Lint with black rather than yapf, matching the Makefile and the rest of SEAMM.
The deploy job ran `conda list` in a job that sets up plain Python and no conda,
and installed the package before building it. Both dropped.
Added workflow_dispatch to CI. GitHub disables a scheduled workflow after 60
days without a commit, and disabling it stops the push and pull_request triggers
as well -- which is why the pull request for the bibtexparser pin got no CI at
all. Being able to run it by hand makes that easier to notice and recover from.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The previous commit changed the lint step in Release.yaml but not in CI.yaml: the two spell the flake8 invocation differently, and the edit matched only one of them, so CI went on calling yapf -- which the same commit had removed from the test environment. Hence "yapf: command not found". CI.yaml's lint job also has no matrix, so its name and Python version are written out rather than taken from one. Both were still on 3.8. Verified by running exactly what CI runs: black, flake8 and the tests are clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The bundled versioneer 0.18 called configparser.SafeConfigParser() and
ConfigParser.readfp(), both removed in Python 3.12, so the package could not be
built there at all:
AttributeError: module 'configparser' has no attribute 'SafeConfigParser'
That is why the workflows were pinned to Python 3.7 and 3.8, and it would also
stop anyone pip-installing a new release on a current Python.
The SEAMM packages carry the same versioneer 0.18 with exactly these two fixes
already applied; versioneer.py here is now byte-identical to the copy they build
with. `pip install .` succeeds on 3.12 and reports the version from git as
before.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There is no pypi_password secret on this repository or on the MolSSI organization, so the publish steps could never have worked. Rather than add an API token, use PyPI's trusted publishing: the job asks GitHub for a short-lived OIDC token and PyPI checks it against the publisher registered for the project. Nothing to store, nothing to rotate, and it cannot be used from anywhere else. The deploy job now requests `id-token: write` and the two publish steps no longer take a password. Also corrected skip_existing to skip-existing, which is how the action spells it now. This needs a one-time registration on PyPI (and, for the Test PyPI step, on test.pypi.org) naming owner MolSSI, repository reference_handler, workflow Release.yaml, and no environment. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Trusted publishing to test.pypi.org needs its own registration on that site, a separate one from PyPI's. Without it the step fails, and since it ran before the real publish it would block the release. For a package that releases rarely it is not worth the second registration. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two commits: a mechanical
blackreformat, then the workflow changes.Why
Neither workflow has ever run in this repository's recorded history -- the Actions API
reports one run in total, today's Dependency Graph update -- and the last release
was 0.9.1 in May 2021. The
schedule:trigger had GitHub disable the workflow after 60days without a commit, and disabling it stops the
pushandpull_requesttriggerstoo, which is why #8 got no CI at all.
Everything the workflows depend on has moved on since:
actions/checkout@v1@v4actions/setup-python@v1@v5conda-incubator/setup-miniconda@v2@v3codecov/codecov-action@v2@v4pypa/gh-action-pypi-publish@master@release/v1@v1actions run on a Node runtime GitHub has removed, so they do not warn -- theyfail. Python 3.7 and 3.8 are past end of life and conda-forge no longer builds for them.
repository_urlis spelledrepository-urlnow.Other fixes
devtools/conda-envs/test_env.yamlhad an emptychannels:, so nothing wascoming from conda-forge. It now asks for conda-forge, and for
black.blackrather thanyapf. The Makefile has linted and formatted with blackfor a while; only the workflow still ran yapf. The first commit brings the code into
line and drops the
[yapf]section fromsetup.cfg.deployjob ranconda listin a job that sets up plain Python and no conda, andinstalled the package before building it. Both dropped.
workflow_dispatchto CI, so it can be run by hand -- useful when GitHub hasdisabled it again.
The reformat is
make formatoutput and changes no behaviour; all 54 tests pass, andblack --checkandflake8are clean.Still needed before a release can publish
The repository and the MolSSI organization have no Actions secrets at all, so
secrets.pypi_passwordandsecrets.test_pypi_passwordare empty and the publish stepscannot work. The molssi-seamm packages use this same action and succeed because
pypi_passwordis an organization secret there.So one of:
pypi_password(andtest_pypi_password) as a secret on this repository or onthe MolSSI organization, from a PyPI API token -- matches how every SEAMM package
publishes; or
password:inputs, addpermissions: id-token: writeto the deploy job, and register the trusted publisheron PyPI. No long-lived token, but it diverges from the pattern used elsewhere.
🤖 Generated with Claude Code