From 057b0c18f21bcd827284b75803fc57be62a55549 Mon Sep 17 00:00:00 2001 From: Abdessamad Derraz <3028866+Abdess@users.noreply.github.com> Date: Tue, 11 Aug 2026 00:54:36 +0200 Subject: [PATCH] chore: widen the build triggers and pin set A pack is the platform baseline plus what its cores need, so a profile change alters pack contents; build.yml did not watch emulators/. Its release notes read git log -15 on a depth-1 clone, which returns one commit, and its test step ran a single module out of nineteen. validate.yml ignored install.sh and install.ps1, so a PR touching only a bootstrap skipped the test that pins them to install.py. checkout and setup-python were pinned to v6 in two workflows and v7 in the others; jsonschema was imported by validate_schemas.py and declared nowhere, and requires-python claimed 3.10 while both bootstraps accept 3.8. --- .github/workflows/build.yml | 20 ++++++++++++++------ .github/workflows/validate.yml | 18 +++++++++++------- .github/workflows/watch.yml | 4 ++-- pyproject.toml | 12 +++++++++++- 4 files changed, 38 insertions(+), 16 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 2c285f42..418b57e9 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -3,7 +3,9 @@ name: Build & Release on: push: branches: [main] - paths: ["bios/**", "platforms/**"] + # A pack is the platform baseline plus what its cores need, so a profile + # change alters pack contents just as a platform list does. + paths: ["bios/**", "platforms/**", "emulators/**"] workflow_dispatch: inputs: force_release: @@ -24,16 +26,20 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 + # The release notes are built from `git log -15`, which returns a single + # commit on the default shallow clone. + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + with: + fetch-depth: 0 - - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 with: python-version: "3.12" - run: pip install pyyaml - name: Run tests - run: python -m unittest tests.test_e2e -v + run: python -m unittest discover tests - name: Rate limit if: github.event.inputs.force_release != 'true' @@ -90,11 +96,13 @@ jobs: if: steps.rate.outputs.skip != 'true' run: | DATE=$(date +%Y.%m.%d) - EXISTING=$(gh release list --repo "${{ github.repository }}" --json tagName -q ".[].tagName" | grep -c "^v${DATE}" || true) + EXISTING=$(gh release list --repo "${{ github.repository }}" \ + --json tagName -q ".[].tagName" | grep -c "^v${DATE}" || true) TAG="v${DATE}" [ "$EXISTING" -gt 0 ] && TAG="v${DATE}.$((EXISTING+1))" - CHANGES=$(git log --oneline -15 --no-merges -- bios/ platforms/ | sed 's/^/- /') + CHANGES=$(git log --oneline -15 --no-merges \ + -- bios/ platforms/ emulators/ | sed 's/^/- /') TOTAL=$(python3 -c "import json; print(json.load(open('database.json'))['total_files'])") SIZE=$(python3 -c "import json; print(f'{json.load(open(\"database.json\"))[\"total_size\"]/1024/1024:.0f}')") PACKS=$(ls dist/*.zip dist/*.zip.001 2>/dev/null | while read f; do echo "- **$(basename $f)** ($(du -m "$f" | cut -f1) MB)"; done) diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 96213bb0..bfc79db6 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -9,7 +9,11 @@ on: - "schemas/**" - "scripts/**" - "tests/**" + # The bootstraps pin install.py's SHA-256 and a test enforces the pin, + # so editing one without the other has to fail the PR. - "install.py" + - "install.sh" + - "install.ps1" permissions: contents: read @@ -23,11 +27,11 @@ jobs: validate-bios: runs-on: ubuntu-latest steps: - - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: fetch-depth: 0 - - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 with: python-version: "3.12" @@ -67,9 +71,9 @@ jobs: validate-configs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 with: python-version: "3.12" @@ -82,9 +86,9 @@ jobs: run-tests: runs-on: ubuntu-latest steps: - - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 with: python-version: "3.12" @@ -99,7 +103,7 @@ jobs: permissions: pull-requests: write steps: - - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: fetch-depth: 0 diff --git a/.github/workflows/watch.yml b/.github/workflows/watch.yml index c3a0de7e..70d7033e 100644 --- a/.github/workflows/watch.yml +++ b/.github/workflows/watch.yml @@ -17,11 +17,11 @@ jobs: scrape-and-update: runs-on: ubuntu-latest steps: - - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: fetch-depth: 0 - - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6 + - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 with: python-version: "3.12" diff --git a/pyproject.toml b/pyproject.toml index f655f75b..668a4e52 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -2,10 +2,20 @@ name = "retrobios" version = "1.0.0" description = "BIOS collection manager for retrogaming platforms" -requires-python = ">=3.10" +# install.py is the only entry point a user runs before cloning, and both +# bootstraps accept 3.8. Nothing here needs a newer runtime, so the floor +# stays where the bootstraps put it. +requires-python = ">=3.8" dependencies = [ "pyyaml", ] +# jsonschema is tooling, not a runtime dependency: scripts/validate_schemas.py +# and the CI contract check are the only callers, and no user path imports it. +[project.optional-dependencies] +dev = [ + "jsonschema>=4.23", +] + [project.urls] Repository = "https://github.com/Abdess/retrobios"