Skip to content

Modernize the CI and Release workflows, and reformat with black - #9

Merged
paulsaxe merged 7 commits into
masterfrom
modernize-ci
Sep 20, 2026
Merged

paulsaxe merged 7 commits into
masterfrom
modernize-ci

Conversation

@paulsaxe

Copy link
Copy Markdown
Collaborator

Two commits: a mechanical black reformat, then the workflow changes.

Why

Neither workflow has ever run in this repository's recorded history -- the Actions API
reports one run in total, today's Dependency Graph update -- and the last release
was 0.9.1 in May 2021. The schedule: trigger had GitHub disable the workflow after 60
days without a commit, and disabling it stops the push and pull_request triggers
too, which is why #8 got no CI at all.

Everything the workflows depend on has moved on since:

was now
actions/checkout @v1 @v4
actions/setup-python @v1 @v5
conda-incubator/setup-miniconda @v2 @v3
codecov/codecov-action @v2 @v4
pypa/gh-action-pypi-publish @master @release/v1
Python 3.7, 3.8 3.11, 3.12

@v1 actions run on a Node runtime GitHub has removed, so they do not warn -- they
fail. Python 3.7 and 3.8 are past end of life and conda-forge no longer builds for them.
repository_url is spelled repository-url now.

Other fixes

  • devtools/conda-envs/test_env.yaml had an empty channels:, so nothing was
    coming from conda-forge. It now asks for conda-forge, and for black.
  • Lint with black rather than yapf. The Makefile has linted and formatted with black
    for a while; only the workflow still ran yapf. The first commit brings the code into
    line and drops the [yapf] section from setup.cfg.
  • The deploy job ran conda list in a job that sets up plain Python and no conda, and
    installed the package before building it. Both dropped.
  • Added workflow_dispatch to CI, so it can be run by hand -- useful when GitHub has
    disabled it again.

The reformat is make format output and changes no behaviour; all 54 tests pass, and
black --check and flake8 are clean.

Still needed before a release can publish

The repository and the MolSSI organization have no Actions secrets at all, so
secrets.pypi_password and secrets.test_pypi_password are empty and the publish steps
cannot work. The molssi-seamm packages use this same action and succeed because
pypi_password is an organization secret there.

So one of:

  1. add pypi_password (and test_pypi_password) as a secret on this repository or on
    the MolSSI organization, from a PyPI API token -- matches how every SEAMM package
    publishes; or
  2. switch to PyPI trusted publishing: drop the password: inputs, add
    permissions: id-token: write to the deploy job, and register the trusted publisher
    on PyPI. No long-lived token, but it diverges from the pattern used elsewhere.

🤖 Generated with Claude Code

paulsaxe and others added 7 commits September 20, 2026 18:08
The Makefile has linted and formatted with black for a while, but the code was
still in yapf's style and the CI workflow still ran yapf. Reformat the package
so the two agree, drop the [yapf] section from setup.cfg, and set flake8's line
length and E203 to match black.

No functional change.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Neither workflow has run in this repository's recorded history, and the last
release was 0.9.1 in May 2021. Everything they depend on has moved on:

  actions/checkout@v1             -> v4    (v1 runs on a Node runtime GitHub
  actions/setup-python@v1         -> v5     has removed, so it fails outright)
  conda-incubator/setup-miniconda@v2 -> v3
  codecov/codecov-action@v2       -> v4
  pypa/gh-action-pypi-publish@master -> @release/v1, and repository_url is
                                        spelled repository-url now
  Python 3.7, 3.8                 -> 3.11, 3.12 (3.7 and 3.8 are end of life
                                     and conda-forge no longer builds for them)

The test environment had an empty `channels:`, so nothing came from conda-forge.
It now asks for conda-forge, and for black, which the linters need.

Lint with black rather than yapf, matching the Makefile and the rest of SEAMM.

The deploy job ran `conda list` in a job that sets up plain Python and no conda,
and installed the package before building it. Both dropped.

Added workflow_dispatch to CI. GitHub disables a scheduled workflow after 60
days without a commit, and disabling it stops the push and pull_request triggers
as well -- which is why the pull request for the bibtexparser pin got no CI at
all. Being able to run it by hand makes that easier to notice and recover from.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The previous commit changed the lint step in Release.yaml but not in CI.yaml:
the two spell the flake8 invocation differently, and the edit matched only one
of them, so CI went on calling yapf -- which the same commit had removed from
the test environment. Hence "yapf: command not found".

CI.yaml's lint job also has no matrix, so its name and Python version are
written out rather than taken from one. Both were still on 3.8.

Verified by running exactly what CI runs: black, flake8 and the tests are clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The bundled versioneer 0.18 called configparser.SafeConfigParser() and
ConfigParser.readfp(), both removed in Python 3.12, so the package could not be
built there at all:

    AttributeError: module 'configparser' has no attribute 'SafeConfigParser'

That is why the workflows were pinned to Python 3.7 and 3.8, and it would also
stop anyone pip-installing a new release on a current Python.

The SEAMM packages carry the same versioneer 0.18 with exactly these two fixes
already applied; versioneer.py here is now byte-identical to the copy they build
with. `pip install .` succeeds on 3.12 and reports the version from git as
before.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There is no pypi_password secret on this repository or on the MolSSI
organization, so the publish steps could never have worked. Rather than add an
API token, use PyPI's trusted publishing: the job asks GitHub for a short-lived
OIDC token and PyPI checks it against the publisher registered for the project.
Nothing to store, nothing to rotate, and it cannot be used from anywhere else.

The deploy job now requests `id-token: write` and the two publish steps no
longer take a password. Also corrected skip_existing to skip-existing, which is
how the action spells it now.

This needs a one-time registration on PyPI (and, for the Test PyPI step, on
test.pypi.org) naming owner MolSSI, repository reference_handler, workflow
Release.yaml, and no environment.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Trusted publishing to test.pypi.org needs its own registration on that site, a
separate one from PyPI's. Without it the step fails, and since it ran before the
real publish it would block the release. For a package that releases rarely it
is not worth the second registration.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@paulsaxe
paulsaxe merged commit e2f9c6e into master Sep 20, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant