CI: update checkout, setup-python, setup-uv, codecov - #60
Conversation
Two related CI bugs, both caused by stale GitHub Action version pins: 1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does, so caching now works with no lockfile needed. 2. Node.js 20 deprecation: actions/checkout and actions/setup-python bumped to v7, clearing the "Node.js 20 is deprecated" warning. codecov/codecov-action bumped to v7; its v5 rewrite dropped the singular `file:` input in favor of `files:`, renamed accordingly. actions/cache (where used, for test-data caching) bumped to v6 for the same reason. Left `prune-cache` at its new default (off): no large pre-built binary wheels like torch in this repo's dependency tree, so pruning would save ~0 disk space while costing avoidable re-downloads. Part of the same CI cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, and audeering/audresample#83. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Reviewer's GuideUpdates CI workflows to use newer GitHub Actions (checkout, setup-python, cache, codecov, setup-uv) and fixes CI caching and Codecov configuration while keeping behavior aligned with sibling repositories. Flow diagram for updated CI doc workflow actionsflowchart LR
trigger["doc workflow trigger"] --> checkout_v7["actions/checkout@v7"]
checkout_v7 --> cache_v6_air["actions/cache@v6 (air)"]
cache_v6_air --> cache_v6_cough["actions/cache@v6 (cough-speech-sneeze)"]
cache_v6_cough --> cache_v6_emodb["actions/cache@v6 (emodb)"]
cache_v6_emodb --> cache_v6_micirp["actions/cache@v6 (micirp)"]
cache_v6_micirp --> cache_v6_musan["actions/cache@v6 (musan)"]
cache_v6_musan --> setup_python_v7["actions/setup-python@v7"]
setup_python_v7 --> setup_uv_v9["astral-sh/setup-uv@v9.0.0"]
setup_uv_v9 --> build_docs["build docs and run CI tasks"]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 3 issues, and left some high level feedback:
- Since you’re touching all workflows, consider centralizing the repeated dataset cache configuration (paths/keys for air, cough-speech-sneeze, emodb, micirp, musan) via a reusable workflow or shared variables to avoid drift if versions or locations change in the future.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- Since you’re touching all workflows, consider centralizing the repeated dataset cache configuration (paths/keys for air, cough-speech-sneeze, emodb, micirp, musan) via a reusable workflow or shared variables to avoid drift if versions or locations change in the future.
## Individual Comments
### Comment 1
<location path=".github/workflows/doc.yml" line_range="19" />
<code_context>
steps:
- - uses: actions/checkout@v4
+ - uses: actions/checkout@v7
with:
# Ensure a dynamic version is assigned
</code_context>
<issue_to_address>
**issue (bug_risk):** Using actions/checkout@v7 may fail since this major version does not exist yet.
The latest published major for `actions/checkout` is `v4`, so `@v7` will currently resolve to nothing and the workflow will fail with an `Unable to resolve action` error. Unless you’re targeting a different action, please use `@v4` or another existing tag to keep the pipeline working.
</issue_to_address>
### Comment 2
<location path=".github/workflows/doc.yml" line_range="26" />
<code_context>
- name: Cache air
- uses: actions/cache@v4
+ uses: actions/cache@v6
with:
path: ~/audb/air/1.4.2
</code_context>
<issue_to_address>
**issue (bug_risk):** actions/cache@v6 is not a currently published major and will break the workflow.
actions/cache is only released up to v4. Using `@v6` will fail to resolve the action and break this step. If you want the latest stable, stick with `@v4` or choose a specific known tag.
</issue_to_address>
### Comment 3
<location path=".github/workflows/doc.yml" line_range="56" />
<code_context>
- name: Set up Python ${{ matrix.python-version }}
- uses: actions/setup-python@v5
+ uses: actions/setup-python@v7
with:
python-version: ${{ matrix.python-version }}
</code_context>
<issue_to_address>
**issue (bug_risk):** actions/setup-python@v7 is not available and will prevent jobs from starting.
The latest published major version is `actions/setup-python@v5`. Using `@v7` will fail because that version does not exist. Please use `@v5` or another valid released tag so the workflow continues to run.
</issue_to_address>Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
issue (bug_risk): Using actions/checkout@v7 may fail since this major version does not exist yet.
The latest published major for actions/checkout is v4, so @v7 will currently resolve to nothing and the workflow will fail with an Unable to resolve action error. Unless you’re targeting a different action, please use @v4 or another existing tag to keep the pipeline working.
|
|
||
| - name: Cache air | ||
| uses: actions/cache@v4 | ||
| uses: actions/cache@v6 |
There was a problem hiding this comment.
issue (bug_risk): actions/cache@v6 is not a currently published major and will break the workflow.
actions/cache is only released up to v4. Using @v6 will fail to resolve the action and break this step. If you want the latest stable, stick with @v4 or choose a specific known tag.
|
|
||
| - name: Set up Python ${{ matrix.python-version }} | ||
| uses: actions/setup-python@v5 | ||
| uses: actions/setup-python@v7 |
There was a problem hiding this comment.
issue (bug_risk): actions/setup-python@v7 is not available and will prevent jobs from starting.
The latest published major version is actions/setup-python@v5. Using @v7 will fail because that version does not exist. Please use @v5 or another valid released tag so the workflow continues to run.
|
Re: the version-tag concerns — these aren't hypothetical, CI already ran on this diff and every flagged step passed: |
Left this untouched in the first commit since it wasn't one of the four actions this rollout targets, but it still triggers its own "Node.js 20 is deprecated" warning (v2 targets Node 20). v3.0.0 updated it to run on Node 24, so bump it too -- otherwise the PR's own claim of clearing the Node.js 20 warning entirely isn't actually true for this repo. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Pushed a follow-up commit bumping |
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 setup-uv's cache keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv from the floating tag v5 -> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does -- so caching now works with no lockfile needed. v7.0.0 also carries the Node 20 -> Node 24 runtime bump. Also bumped actions/checkout and actions/setup-python from v4/v5 to v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20 is deprecated" warning entirely. codecov-action's v5 rewrite dropped the `file` input this workflow used; renamed to `files`, its replacement. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audmath's only runtime dependency is numpy, with no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Same cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, and audeering/audiofile#193. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 setup-uv's cache keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv (pinned via SHA 3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does -- so caching now works with no lockfile needed. Note the existing pin already sat at v7.1.0, past both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump (v7.0.0), so neither bug technically applied to this action here -- bumping to v9.0.0 anyway for consistency across the sibling repos in this cleanup, matching what was done for audformat's and audbackend's setup-uv pins after the fact (same SHA-pin situation). Also bumped actions/checkout and actions/setup-python from v4/v5 to v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20 is deprecated" warning entirely. codecov-action's v5 rewrite dropped the `file` input this workflow used; renamed to `files`, its replacement. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audmetric's runtime dependencies (audeer, numpy) have no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Same cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, and audeering/audiofile#193. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 setup-uv's cache keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does -- so caching now works with no lockfile needed. v7.0.0 also moved the action off the deprecated Node.js 20 runtime. Also bumped actions/checkout and actions/setup-python from v4/v5 to v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20 is deprecated" warning entirely. codecov-action's v5 rewrite dropped the `file` input this workflow used; renamed to `files`, its replacement, in test.yml so the coverage upload doesn't silently no-op. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audobject's runtime dependencies (asttokens, audeer, oyaml, packaging) have no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Same cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, audeering/audiofile#193, and audeering/audmath#76, audeering/audmetric#94. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 Two related CI bugs, both caused by stale GitHub Action version pins: 1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. This repo's setup-uv pin was already a SHA (3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag v7.1.0 — past the fix that matters here (v6.0.0 added pyproject.toml to the default glob) and past the Node 20 -> Node 24 runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency with the other repos in this cleanup. 2. Node.js 20 deprecation: actions/checkout and actions/setup-python bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning. codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the singular `file:` input in favor of `files:`, renamed accordingly. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audplot's dependency tree (audmath, audmetric, matplotlib, pandas, seaborn) has no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Part of the same CI cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, audeering/audiofile#193, audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63, and audeering/audobject#127. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Summary
Two related CI bugs, both caused by stale GitHub Action version pins:
Dead uv caching:
astral-sh/setup-uv's defaultcache-dependency-globkeys on
uv.lock/requirements*.txt, neither of which exists here (nocommitted lockfile, by design), so caching never actually worked. Bumped
astral-sh/setup-uvv5->v9.0.0in publish.yml (the only workflowthat calls it directly; test.yml installs uv via
mamba-org/setup-micromamba, left untouched).Node.js 20 deprecation:
actions/checkoutandactions/setup-pythonbumped
v4/v5->v7, clearing the "Node.js 20 is deprecated" warning.codecov/codecov-actionbumpedv4->v7; itsv5rewrite dropped thesingular
file:input in favor offiles:, renamed accordingly.actions/cache(used for the air/cough-speech-sneeze/emodb/micirp/musantest-data caches across doc/publish/test workflows) bumped
v4->v6for the same reason.
prune-cacheleft at its new default (off): auglib's runtime dependencytree (audeer, audformat, audinterface, audmath, audobject, scipy) has no
large pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.
Test plan
established pattern from sibling repos