diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index e2cfe21..12d20f4 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -14,27 +14,14 @@ concurrency: cancel-in-progress: true jobs: - lock: - runs-on: ubuntu-latest - timeout-minutes: 5 - steps: - - name: Check out repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - - name: Install uv - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 - with: - version: "0.12.19" - - - name: Lock files match pyproject.toml - run: make lock-check - + # Lowest and latest supported CPython; the universal lock already resolves + # every version between them, so the middle ones ran the identical suite. validate: runs-on: ubuntu-latest strategy: fail-fast: false matrix: - python-version: ["3.11", "3.12", "3.13", "3.14"] + python-version: ["3.11", "3.14"] timeout-minutes: 15 steps: - name: Check out repository @@ -49,33 +36,14 @@ jobs: - name: Set up Python ${{ matrix.python-version }} run: uv python install ${{ matrix.python-version }} - - name: Install dependencies and dev tools + - name: Install locked dev dependencies run: | uv venv --python ${{ matrix.python-version }} uv pip install -r requirements-dev.lock.txt - - name: Lint with ruff - run: .venv/bin/ruff check . - - - name: Run tests - run: .venv/bin/python -m pytest - - - name: Validate catalog - run: .venv/bin/python tools/validate_catalog.py - - - name: Verify public JSON exports - run: .venv/bin/python tools/export_catalog.py --check --target both + - name: Run all checks + run: make check PYTHON=.venv/bin/python - - name: Verify browsable README indexes - run: .venv/bin/python tools/render_readmes.py --check - - - name: Verify first-party content manifest - run: .venv/bin/python tools/build_content_manifest.py --check - - - name: Verify runnable examples - run: .venv/bin/python tools/verify_examples.py - - - name: Verify course folders - run: .venv/bin/python tools/verify_courses.py - - name: Verify learning-path contracts - run: .venv/bin/python tools/verify_paths.py + - name: Lock files match pyproject.toml + if: matrix.python-version == '3.11' + run: make lock-check diff --git a/CHANGELOG.md b/CHANGELOG.md index 7ada1d7..43692b8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,13 +10,16 @@ This file records notable catalog-contract and maintenance changes. by `make lock` (`uv pip compile --universal` from the Python 3.11 floor) instead of hand-maintained. All existing pins were kept; the Windows-only `colorama` and Python <3.13 `typing-extensions` transitive pins the manual - lock had missed are now included. A new `lock` CI job runs - `make lock-check` and fails when the locks drift from `pyproject.toml`. + lock had missed are now included. `make lock-check` re-resolves the + committed locks in place and fails on any diff; CI runs it on the 3.11 leg. - New `tests/test_dependency_pins.py`: every course/path `requirements.txt` must pin exactly the versions CI tests with. -- Validate matrix adds Python 3.14 and no longer cancels sibling versions - on the first failure; actions are pinned to commit SHAs, `setup-uv` moves - from v7 to v10.2.0, and CI pins uv 0.12.19. +- Validate is a single `make check` job (the same command as local) on the + Python floor and latest (3.11 + 3.14 — the universal lock resolves every + version between), no longer cancels sibling versions on the first failure, + SHA-pins actions, moves `setup-uv` v7 → v10.2.0, and pins uv 0.12.19. +- Removed the unused root `requirements.txt` and `requirements-dev.txt`; + dependencies are declared only in `pyproject.toml` and the two locks. - Removed `notify-site.yml`: its `WEBSITE_SYNC_TOKEN` secret was never configured, so all 32 runs skipped the dispatch step while reporting success, and the website builds from its own content pin regardless. diff --git a/Makefile b/Makefile index 19da60c..c43b2e6 100644 --- a/Makefile +++ b/Makefile @@ -64,15 +64,12 @@ paths: lock: $(compile_locks) -# Re-resolve copies of the committed locks in a scratch directory: uv keeps -# every committed pin that still satisfies pyproject.toml, so any diff means -# the locks drifted from the declared dependencies. +# uv keeps every committed pin that still satisfies pyproject.toml, so any +# diff after re-resolution means the locks drifted — the printed diff is the +# change to commit. lock-check: - @tmp=$$(mktemp -d) && \ - cp pyproject.toml requirements.lock.txt requirements-dev.lock.txt "$$tmp/" && \ - $(MAKE) --no-print-directory -C "$$tmp" -f "$(CURDIR)/Makefile" lock && \ - diff -u requirements.lock.txt "$$tmp/requirements.lock.txt" && \ - diff -u requirements-dev.lock.txt "$$tmp/requirements-dev.lock.txt" && \ - rm -rf "$$tmp" && echo "lock files match pyproject.toml" + @$(compile_locks) + @git diff --exit-code requirements.lock.txt requirements-dev.lock.txt || \ + { echo "lock files drifted from pyproject.toml — commit the regenerated files"; exit 1; } all: export render manifest check diff --git a/requirements-dev.txt b/requirements-dev.txt deleted file mode 100644 index 2137822..0000000 --- a/requirements-dev.txt +++ /dev/null @@ -1,5 +0,0 @@ --r requirements.txt -pytest==9.1.1 -jsonschema>=4.20.0 -pandas==2.3.3 -matplotlib==3.10.9 diff --git a/requirements.txt b/requirements.txt deleted file mode 100644 index 3d356f2..0000000 --- a/requirements.txt +++ /dev/null @@ -1,3 +0,0 @@ -PyYAML==6.0.3 -requests==2.34.2 -urllib3==2.8.0