Skip to content

build(ci): pin the tools these workflows install at runtime #369

build(ci): pin the tools these workflows install at runtime

build(ci): pin the tools these workflows install at runtime #369

Workflow file for this run

name: Build PyPI
on:
workflow_call:
inputs:
ref:
description: "Branch, tag or SHA to build. Empty = the caller's ref."
required: false
type: string
default: ""
artifact-name:
description: >
Name to upload the build output under. The release flow runs this
workflow twice in one run -- once on the branch, once on the tag -- and
upload-artifact rejects a duplicate name.
required: false
type: string
default: "dist"
workflow_dispatch:
push:
branches:
- main
pull_request:
types:
- opened
- reopened
- synchronize
permissions:
contents: read
jobs:
linting:
name: Reuse linting job
uses: ./.github/workflows/lint.yml
build:
needs: linting
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
reqstool-source: [pypi, main]
steps:
# Full history and tags: hatch-vcs derives the version from git state, so a
# shallow clone would build the wrong number rather than fail.
- name: Check out source repository
uses: actions/checkout@v7
with:
persist-credentials: false
fetch-depth: 0
fetch-tags: true
ref: ${{ inputs.ref || github.ref }}
- name: Set up Python
uses: actions/setup-python@v7
with:
python-version: "3.13"
- name: Install dependencies
# renovate: datasource=pypi depName=hatch
run: pip install hatch==1.18.0
- name: Build wheel (used by e2e tests via PIP_FIND_LINKS)
run: hatch build --target wheel
- name: Run tests
run: hatch run dev:pytest --junitxml=build/junit.xml --cov=reqstool_python_hatch_plugin --cov-report=xml:build/coverage.xml
- name: Build project
run: hatch build
- name: Self-apply own decorators to own src/tests
run: hatch run dev:python scripts/generate_annotations.py
# NOTE: all reqstool/.github refs below are pinned to the same commit -- keep
# these 4 in sync when bumping (install-reqstool, validate-reqstool,
# reqstool-status, and the validate-openspec job's workflow ref further down).
- name: Install reqstool
uses: reqstool/.github/.github/actions/install-reqstool@74cc3ac55a476258898db82c69a78eeaabb2fcbc # main 2026-06-24
with:
reqstool-source: ${{ matrix.reqstool-source }}
- name: Validate reqstool spec completeness
# not yet available in the latest PyPI release; supplementary to (not a
# replacement for) the `reqstool status --fail-if-incomplete` gate below, which
# is the actual required check, run unconditionally on both matrix legs
if: matrix.reqstool-source == 'main'
uses: reqstool/.github/.github/actions/validate-reqstool@74cc3ac55a476258898db82c69a78eeaabb2fcbc # main 2026-06-24
- name: Run reqstool status
# Required gate on both matrix legs -- fails the build unless every
# requirement is implemented and verified.
uses: reqstool/.github/.github/actions/reqstool-status@74cc3ac55a476258898db82c69a78eeaabb2fcbc # main 2026-06-24
with:
fail-if-incomplete: "true"
# Upload artifacts for later use
- name: Upload Artifacts
if: matrix.reqstool-source == 'pypi'
uses: actions/upload-artifact@v7
with:
name: ${{ inputs.artifact-name || 'dist' }}
path: dist/
validate-openspec:
uses: reqstool/.github/.github/workflows/common-validate-openspec.yml@74cc3ac55a476258898db82c69a78eeaabb2fcbc # main 2026-06-24