Skip to content

Fix CI caching; bump checkout/setup-python off Node.js 20 - #307

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 6, 2026
Merged

Fix CI caching; bump checkout/setup-python off Node.js 20#307
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock / requirements*.txt, neither of which exists in this
    repo (no committed lockfile, by design — it tests against latest
    resolvable deps). Caching has therefore silently never worked.

    This repo's setup-uv pin was a SHA (3259c6206f993105e3a61b142c2d97bf4b9ef83d),
    which resolves to tag v7.1.0 — already past the fix that matters here
    (v6.0.0 added pyproject.toml to the default glob, which is committed
    and changes exactly when a dependency does) and past the Node 20 → Node 24
    runtime bump (v7.0.0). So neither bug technically applied to this pin.
    Bumping to v9.0.0 anyway, for consistency with the sibling fixes below
    (matching what was done for audformat's setup-uv pin, which was in the
    same situation).

  2. Node.js 20 deprecation: actions/checkout@v4 and
    actions/setup-python@v5 still target the deprecated Node 20 runtime.
    Bumped both to v7. codecov/codecov-action@v4 also bumped to v7;
    its v5 rewrite dropped the singular file: input in favor of files:
    (plural) — renamed accordingly in test.yml so the coverage upload
    doesn't silently no-op. No actions/cache usage exists in this repo's
    workflows.

prune-cache left at its new default (off): audbackend's dependency tree
(audeer, minio, audformat, sphinx, pytest, stream-unzip) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk space
while costing avoidable re-downloads.

Test plan

  • All four changed workflow YAML files validated with
    python3 -c "import yaml; yaml.safe_load(open('FILE'))"
  • CI passes on this PR (checkout/setup-python/setup-uv/codecov-action
    bumps exercised across the full test matrix)

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591, and
audeering/audformat#539.

🤖 Generated with Claude Code

@sourcery-ai

sourcery-ai Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates all CI workflows to use Node 24-compatible GitHub Actions and fixes ineffective uv caching and Codecov configuration.

Flow diagram for updated CI workflow actions and caching

flowchart TD
    subgraph CI_Workflow
        A[Trigger workflow] --> B[actions_checkout_v7]
        B --> C[actions_setup_python_v7]
        C --> D[astral_sh_setup_uv_v9_0_0]
        D --> E[Run_tests_or_docs]
        E --> F[codecov_codecov_action_v7]
    end

    D --> G[Use_pyproject_toml_for_uv_cache]
    F --> H[Upload_coverage_with_files_input]
Loading

File-Level Changes

Change Details Files
Bump core GitHub Actions to Node 24-compatible versions across all workflows.
  • Update actions/checkout from v4 to v7 in test, doc, linter, and publish workflows.
  • Update actions/setup-python from v5 to v7 in all workflows using it.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml
Align uv setup with latest action version and working cache behavior.
  • Replace astral-sh/setup-uv pinned SHA with tag v9.0.0 across all workflows.
  • Rely on setup-uv’s updated default cache-dependency-glob that includes pyproject.toml for effective caching.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml
Update Codecov action usage to the v7 API and ensure coverage upload works.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow.
  • Rename Codecov input from file to files to match the new action API and avoid no-op uploads.
.github/workflows/test.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider pinning the updated GitHub Actions (checkout, setup-python, setup-uv, codecov-action) to immutable SHAs or at least major.minor versions rather than floating major tags to avoid unexpected behavior if upstream publishes a breaking change on the same major.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- Consider pinning the updated GitHub Actions (checkout, setup-python, setup-uv, codecov-action) to immutable SHAs or at least major.minor versions rather than floating major tags to avoid unexpected behavior if upstream publishes a breaking change on the same major.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@ChristianGeng

Copy link
Copy Markdown
Member Author

Re: SHA-pinning suggestion — leaving the floating major tags (checkout/setup-python/codecov-action@v7, setup-uv@v9.0.0) as-is. Same question came up on audformat#539, and the call there was to keep floating tags consistent across this whole rollout (audeer#206, opensmile-python#132, audb#591, audformat#539) rather than SHA-pin some repos and not others — one version-bump PR then updates all of them the same way. Full SHA-pinning would trade that for supply-chain hardening this org hasn't adopted elsewhere.

ChristianGeng added a commit to audeering/audinterface that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20

Two related CI bugs, both caused by stale GitHub Action version pins:

1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
   keys on uv.lock/requirements*.txt, neither of which exists here (no
   committed lockfile, by design), so caching never actually worked.
   Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
   the default glob, which is committed and changes exactly when a
   dependency does, so caching now works with no lockfile needed.

2. Node.js 20 deprecation: actions/checkout and actions/setup-python
   bumped to v7, clearing the "Node.js 20 is deprecated" warning.
   codecov/codecov-action bumped to v7; its v5 rewrite dropped the
   singular `file:` input in favor of `files:`, renamed accordingly.
   actions/cache (where used, for test-data caching) bumped to v6 for
   the same reason.

Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Give each workflow its own uv cache to stop reservation races

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/auglib that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20

Two related CI bugs, both caused by stale GitHub Action version pins:

1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
   keys on uv.lock/requirements*.txt, neither of which exists here (no
   committed lockfile, by design), so caching never actually worked.
   Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
   the default glob, which is committed and changes exactly when a
   dependency does, so caching now works with no lockfile needed.

2. Node.js 20 deprecation: actions/checkout and actions/setup-python
   bumped to v7, clearing the "Node.js 20 is deprecated" warning.
   codecov/codecov-action bumped to v7; its v5 rewrite dropped the
   singular `file:` input in favor of `files:`, renamed accordingly.
   actions/cache (where used, for test-data caching) bumped to v6 for
   the same reason.

Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Bump mamba-org/setup-micromamba off Node.js 20 too

Left this untouched in the first commit since it wasn't one of the four
actions this rollout targets, but it still triggers its own "Node.js 20
is deprecated" warning (v2 targets Node 20). v3.0.0 updated it to run on
Node 24, so bump it too -- otherwise the PR's own claim of clearing the
Node.js 20 warning entirely isn't actually true for this repo.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Give each workflow its own uv cache to stop reservation races

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmath that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20

setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from the floating tag v5
-> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is
committed and changes exactly when a dependency does -- so caching
now works with no lockfile needed. v7.0.0 also carries the Node 20 ->
Node 24 runtime bump.

Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.

Left `prune-cache` at its new default (off): audmath's only runtime
dependency is numpy, with no large pre-built binary wheels like torch,
so pruning would save ~0 disk space while costing avoidable
re-downloads.

Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Give each workflow its own uv cache to stop reservation races

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmetric that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20

setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup, matching what was done for audformat's and audbackend's
setup-uv pins after the fact (same SHA-pin situation).

Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.

Left `prune-cache` at its new default (off): audmetric's runtime
dependencies (audeer, numpy) have no large pre-built binary wheels
like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.

Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Give each workflow its own uv cache to stop reservation races

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audobject that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20

setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.

Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.

Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.

Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Give each workflow its own uv cache to stop reservation races

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audiofile that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20

Two related CI bugs, both caused by stale GitHub Action version pins:

1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
   keys on uv.lock/requirements*.txt, neither of which exists here (no
   committed lockfile, by design), so caching never actually worked.
   Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
   the default glob, which is committed and changes exactly when a
   dependency does, so caching now works with no lockfile needed.

2. Node.js 20 deprecation: actions/checkout and actions/setup-python
   bumped to v7, clearing the "Node.js 20 is deprecated" warning.
   codecov/codecov-action bumped to v7; its v5 rewrite dropped the
   singular `file:` input in favor of `files:`, renamed accordingly.
   actions/cache (where used, for test-data caching) bumped to v6 for
   the same reason.

Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Bump mamba-org/setup-micromamba off Node.js 20 too

Left this untouched in the first commit since it wasn't one of the four
actions this rollout targets, but it still triggers its own "Node.js 20
is deprecated" warning (v1 targets Node 20). v3.0.0 updated it to run on
Node 24, so bump it too -- otherwise the PR's own claim of clearing the
Node.js 20 warning entirely isn't actually true for this repo.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Give each workflow its own uv cache to stop reservation races

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20

Two related CI bugs, both caused by stale GitHub Action version pins:

1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
   keys on uv.lock/requirements*.txt, neither of which exists here (no
   committed lockfile, by design), so caching never actually worked.
   This repo's setup-uv pin was already a SHA
   (3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
   v7.1.0 — past the fix that matters here (v6.0.0 added
   pyproject.toml to the default glob) and past the Node 20 -> Node 24
   runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
   with the other repos in this cleanup.

2. Node.js 20 deprecation: actions/checkout and actions/setup-python
   bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
   codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
   singular `file:` input in favor of `files:`, renamed accordingly.
   No actions/cache usage exists in this repo's workflows.

Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Give each workflow its own uv cache to stop reservation races

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng ChristianGeng self-assigned this Aug 5, 2026
@codecov

codecov Bot commented Aug 5, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.0%. Comparing base (07ff03f) to head (2469a99).

Additional details and impacted files
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@ChristianGeng

Copy link
Copy Markdown
Member Author

@hagenw for review — but please merge #309 first, not this one.

This PR is only the action-version bump (checkout/setup-python/setup-uv/codecov-action, plus a per-workflow uv cache suffix). It deliberately no longer contains the MinIO work: that was split out into #309, because dropping the play.min.io dependency is a separate concern from bumping action versions.

The consequence is that this PR cannot go green on its own. Its test job still points at play.min.io, which is unreachable, so the Test workflow hangs until it is cancelled — I cancelled the current run rather than let it burn an hour of runner time. That is not a fault in this diff.

Suggested order:

  1. Merge CI: run minio tests on self-hosted MinIO #309 (self-hosted MinIO — green on Linux, Windows and macOS).
  2. Merge main into this branch, so it picks up the MinIO fix.
  3. This PR's CI then runs against a self-hosted MinIO and can actually go green.
  4. Merge this one.

Reviewing the diff here is fine at any point; it is only the merge that needs to wait.

cgeng and others added 2 commits August 6, 2026 11:53
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup (audeer#206, opensmile-python#132, audb#591,
audformat#539), matching what was done for audformat's setup-uv pin
after the fact.

Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.

Left `prune-cache` at its new default (off): audbackend's dependency
tree (audeer, minio, audformat, sphinx, pytest, stream-unzip) has no
large pre-built binary wheels like torch, so pruning would save
~0 disk space while costing avoidable re-downloads.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.

Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng force-pushed the fix/ci-action-versions branch from c934c08 to 2469a99 Compare August 6, 2026 09:54
@ChristianGeng
ChristianGeng merged commit 6b0d033 into main Aug 6, 2026
13 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 6, 2026 09:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants