CI: update checkout, setup-python, setup-uv, codecov - #94
Conversation
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv (pinned via SHA 3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does -- so caching now works with no lockfile needed. Note the existing pin already sat at v7.1.0, past both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump (v7.0.0), so neither bug technically applied to this action here -- bumping to v9.0.0 anyway for consistency across the sibling repos in this cleanup, matching what was done for audformat's and audbackend's setup-uv pins after the fact (same SHA-pin situation). Also bumped actions/checkout and actions/setup-python from v4/v5 to v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20 is deprecated" warning entirely. codecov-action's v5 rewrite dropped the `file` input this workflow used; renamed to `files`, its replacement. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audmetric's runtime dependencies (audeer, numpy) have no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Same cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, and audeering/audiofile#193. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Reviewer's guide (collapsed on small PRs)Reviewer's GuideUpdates all CI workflows to use modern GitHub Actions runtimes and fixes uv/Codecov configuration so caching and coverage upload actually work. Sequence diagram for updated CI workflow actions and coverage uploadsequenceDiagram
participant GitHubActionsRunner as GitHubActionsRunner
participant actions_checkout_v7 as actions_checkout_v7
participant actions_setup_python_v7 as actions_setup_python_v7
participant astral_sh_setup_uv_v9 as astral_sh_setup_uv_v9_0_0
participant test_commands as test_commands
participant codecov_action_v7 as codecov_codecov_action_v7
GitHubActionsRunner->>actions_checkout_v7: uses actions/checkout@v7
actions_checkout_v7-->>GitHubActionsRunner: repository checked out
GitHubActionsRunner->>actions_setup_python_v7: uses actions/setup-python@v7
actions_setup_python_v7-->>GitHubActionsRunner: Python environment ready
GitHubActionsRunner->>astral_sh_setup_uv_v9: uses astral-sh/setup-uv@v9.0.0
astral_sh_setup_uv_v9-->>GitHubActionsRunner: uv installed with pyproject.toml cache
GitHubActionsRunner->>test_commands: run uv sync / tests
test_commands-->>GitHubActionsRunner: test results and coverage file
GitHubActionsRunner->>codecov_action_v7: uses codecov/codecov-action@v7 with files
codecov_action_v7-->>GitHubActionsRunner: coverage uploaded to Codecov
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue, and left some high level feedback:
- Since you’re moving
setup-uvfrom a SHA pin to a tagged release (v9.0.0), consider whether you want to standardize on either tag- or SHA-based pinning across workflows for supply-chain consistency and document that choice in the repo’s CI conventions. - You’re already updating GitHub Actions to newer Node runtimes; you may also want to revisit
actions/setup-node@v4withnode-version: '16.0'inpublish.yml, as Node 16 is EOL and may eventually break or lose support in the Actions ecosystem.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- Since you’re moving `setup-uv` from a SHA pin to a tagged release (`v9.0.0`), consider whether you want to standardize on either tag- or SHA-based pinning across workflows for supply-chain consistency and document that choice in the repo’s CI conventions.
- You’re already updating GitHub Actions to newer Node runtimes; you may also want to revisit `actions/setup-node@v4` with `node-version: '16.0'` in `publish.yml`, as Node 16 is EOL and may eventually break or lose support in the Actions ecosystem.
## Individual Comments
### Comment 1
<location path=".github/workflows/doc.yml" line_range="27" />
<code_context>
- name: Install uv
- uses: astral-sh/setup-uv@3259c6206f993105e3a61b142c2d97bf4b9ef83d
+ uses: astral-sh/setup-uv@v9.0.0
- name: Install package
</code_context>
<issue_to_address>
**🚨 issue (security):** Switching from a pinned SHA to a version tag for setup-uv weakens reproducibility and security.
Using a commit SHA ensured a fixed, reviewable version of `astral-sh/setup-uv`. Tags like `@v9.0.0` can be retagged or change upstream, reducing determinism and supply-chain safety. Please pin to the commit SHA for `v9.0.0` (or the desired version) to keep the workflow reproducible while upgrading.
</issue_to_address>Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
|
|
||
| - name: Install uv | ||
| uses: astral-sh/setup-uv@3259c6206f993105e3a61b142c2d97bf4b9ef83d | ||
| uses: astral-sh/setup-uv@v9.0.0 |
There was a problem hiding this comment.
🚨 issue (security): Switching from a pinned SHA to a version tag for setup-uv weakens reproducibility and security.
Using a commit SHA ensured a fixed, reviewable version of astral-sh/setup-uv. Tags like @v9.0.0 can be retagged or change upstream, reducing determinism and supply-chain safety. Please pin to the commit SHA for v9.0.0 (or the desired version) to keep the workflow reproducible while upgrading.
|
Re: standardizing tag- vs SHA-pinning — the convention across this rollout is floating major tags for |
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 setup-uv's cache keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does -- so caching now works with no lockfile needed. v7.0.0 also moved the action off the deprecated Node.js 20 runtime. Also bumped actions/checkout and actions/setup-python from v4/v5 to v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20 is deprecated" warning entirely. codecov-action's v5 rewrite dropped the `file` input this workflow used; renamed to `files`, its replacement, in test.yml so the coverage upload doesn't silently no-op. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audobject's runtime dependencies (asttokens, audeer, oyaml, packaging) have no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Same cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, audeering/audiofile#193, and audeering/audmath#76, audeering/audmetric#94. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 Two related CI bugs, both caused by stale GitHub Action version pins: 1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. This repo's setup-uv pin was already a SHA (3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag v7.1.0 — past the fix that matters here (v6.0.0 added pyproject.toml to the default glob) and past the Node 20 -> Node 24 runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency with the other repos in this cleanup. 2. Node.js 20 deprecation: actions/checkout and actions/setup-python bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning. codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the singular `file:` input in favor of `files:`, renamed accordingly. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audplot's dependency tree (audmath, audmetric, matplotlib, pandas, seaborn) has no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Part of the same CI cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, audeering/audiofile#193, audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63, and audeering/audobject#127. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Summary
Two related CI bugs, both caused by stale GitHub Action version pins:
Dead uv caching:
astral-sh/setup-uv's defaultcache-dependency-globkeys on
uv.lock/requirements*.txt, neither of which exists in thisrepo (no committed lockfile, by design — it tests against latest
resolvable deps). Caching has therefore silently never worked.
This repo's
setup-uvpin was a SHA (3259c6206f993105e3a61b142c2d97bf4b9ef83d),which resolves to tag
v7.1.0— already past the fix that matters here(
v6.0.0addedpyproject.tomlto the default glob, which is committedand changes exactly when a dependency does) and past the Node 20 → Node 24
runtime bump (
v7.0.0). So neither bug technically applied to this pin.Bumping to
v9.0.0anyway, for consistency with the sibling fixes below(matching what was done for audformat's and audbackend's
setup-uvpins,which were in the same situation).
Node.js 20 deprecation:
actions/checkout@v4andactions/setup-python@v5still target the deprecated Node 20 runtime.Bumped both to
v7.codecov/codecov-action@v4also bumped tov7;its
v5rewrite dropped the singularfile:input in favor offiles:(plural) — renamed accordingly in
test.ymlso the coverage uploaddoesn't silently no-op. No
actions/cacheusage exists in this repo'sworkflows.
prune-cacheleft at its new default (off): audmetric's dependency tree(audeer, numpy) has no large pre-built binary wheels like torch, so pruning
would save ~0 disk space while costing avoidable re-downloads.
Test plan
uv run --isolated --with pyyaml python3 -c "import yaml; yaml.safe_load(open('FILE'))"bumps exercised across the full test matrix)
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
🤖 Generated with Claude Code