mirror of
https://github.com/Akkudoktor-EOS/EOS.git
synced 2026-08-30 04:06:37 +00:00
Consolidates the currently applicable dependency updates into one PR, including the closed Dependabot backlog such as #1241, plus dependency surfaces that were not covered by the repository's previous pip-only Dependabot configuration. Cleanup of test warnings. Most importent: * GitPython + pypdf security hardening. * Uvicorn WebSocket close/backpressure/header fixes for server/dashboard reliability. * FastAPI dependency-memory/OpenAPI improvements for the API process. * Bokeh WebSocket/resource-leak/prefix fixes for EOSdash and proxied deployments. * cachebox cancellation/lock cleanup fixes for long-running/concurrent work. * pandas 3.0.5 avoiding the yanked 3.0.4 datetime/segfault build. * Ruff security-lint and pydocstyle correctness fixes, plus faster release builds via PGO. * platformdirs malformed-XDG and duplicate-directory fixes for deployment portability. * CI action modernization, regenerated uv.lock, and expanded Dependabot coverage. Runtime dependencies cachebox: 6.1.2 → 6.2.2 fastapi: 0.139.2 → 0.141.1 python-fasthtml: 0.14.9 → 0.14.11 MonsterUI: 1.0.46 → 1.0.47 bokeh: 3.9.1 → 3.9.2 uvicorn: 0.51.0 → 0.52.4 (build(deps): bump uvicorn from 0.51.0 to 0.52.3 #1241, refreshed to latest patch) pandas: 3.0.3 → 3.0.5 platformdirs: 4.11.0 → 4.11.3 Development/test dependencies pandas-stubs: 3.0.3.260530 → 3.0.5.260730 types-PyYAML: 6.0.12.20260518 → 6.0.12.20260724 GitPython: 3.1.53 → 3.1.58 (security/fix releases) coverage: 7.15.2 → 7.15.4 pypdf: 6.14.2 → 6.16.1 (includes security fixes) Pre-commit/tooling ruff-pre-commit: v0.15.21 → v0.16.3 synchronize pandas-stubs, types-docutils, and types-PyYAML pins with pyproject.toml CI / repository dependencies Python 3.13.9 → 3.13.15 in CI, Docker, .env, and local Docker Make targets actions/checkout → v7 in pytest, pre-commit, CodeQL, and release workflows actions/setup-python → v7 in pytest, pre-commit, and release workflows actions/upload-artifact → v7 in pytest workflow actions/stale: v9.1.0 → v11.0.0 (SHA-pinned) regenerate uv.lock from the final dependency pins so locked/frozen installs match pyproject.toml Future update coverage Expand Dependabot from pip-only to also monitor: GitHub Actions Docker The existing open docutils 0.23 update (#1085) is intentionally excluded because it has separate compatibility/ignore handling and should remain isolated. docker-build.yml was audited and is already using the newer action generations, so no changes were needed there. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
98 lines
3.3 KiB
YAML
98 lines
3.3 KiB
YAML
name: Bump Version
|
|
|
|
# Trigger the workflow on any push to main
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
|
|
permissions:
|
|
contents: write # Required for pushing commits and tags
|
|
pull-requests: write # Required to create a pull request
|
|
|
|
concurrency:
|
|
group: bump-version-main
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
bump-version:
|
|
runs-on: ubuntu-latest
|
|
name: Bump Version Workflow
|
|
|
|
steps:
|
|
# --- Step 1: Checkout the repository ---
|
|
- name: Checkout repo
|
|
uses: actions/checkout@v7
|
|
with:
|
|
fetch-depth: 0 # Needed to create tags and see full history
|
|
|
|
# --- Step 2: Set up Python ---
|
|
- name: Set up Python
|
|
uses: actions/setup-python@v7
|
|
with:
|
|
python-version: "3.11"
|
|
|
|
# --- Step 3: Calculate version dynamically ---
|
|
- name: Calculate version
|
|
id: calc
|
|
run: |
|
|
VERSION=$(python scripts/get_version.py)
|
|
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
|
|
echo "Computed version: $VERSION"
|
|
|
|
# --- Step 4: Skip workflow for development versions ---
|
|
- name: Skip if version contains 'dev'
|
|
if: contains(steps.calc.outputs.version, 'dev')
|
|
run: |
|
|
echo "Version contains 'dev'. Skipping release-related steps."
|
|
|
|
# --- Step 5: Tag release version ---
|
|
- name: Tag release version
|
|
id: tagging
|
|
if: "!contains(steps.calc.outputs.version, 'dev')"
|
|
run: |
|
|
git config user.name "github-actions"
|
|
git config user.email "actions@github.com"
|
|
TAG="v${{ steps.calc.outputs.version }}"
|
|
if git rev-parse --verify "$TAG" >/dev/null 2>&1; then
|
|
echo "Tag $TAG already exists. Skipping."
|
|
echo "tagged=false" >> "$GITHUB_OUTPUT"
|
|
else
|
|
git tag -a "$TAG" -m "Release ${{ steps.calc.outputs.version }}"
|
|
git push origin "$TAG"
|
|
echo "tagged=true" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
# --- Step 6: Create PR to bump to dev version ---
|
|
- name: Bump dev version and create PR
|
|
if: "!contains(steps.calc.outputs.version, 'dev')"
|
|
run: |
|
|
git config user.name "github-actions"
|
|
git config user.email "actions@github.com"
|
|
BRANCH="chore/bump-dev-version-${{ steps.calc.outputs.version }}"
|
|
# Skip if branch or PR already exists
|
|
if git ls-remote --exit-code --heads origin "$BRANCH" >/dev/null 2>&1; then
|
|
echo "Branch $BRANCH already exists. Skipping."
|
|
exit 0
|
|
fi
|
|
git checkout -b "$BRANCH"
|
|
VERSION_BASE=$(python scripts/bump_dev_version.py | tail -n1)
|
|
if [ -z "$VERSION_BASE" ]; then
|
|
echo "Error: bump_dev_version.py returned an empty version."
|
|
exit 1
|
|
fi
|
|
git add src/akkudoktoreos/core/version.py
|
|
if git diff --cached --quiet; then
|
|
echo "version.py not changed. Skipping."
|
|
else
|
|
git commit -m "chore: bump dev version to ${VERSION_BASE}"
|
|
git push origin "$BRANCH"
|
|
gh pr create \
|
|
--title "chore: bump dev version to ${VERSION_BASE}" \
|
|
--body "Automated dev version bump after release ${{ steps.calc.outputs.version }}." \
|
|
--base main \
|
|
--head "$BRANCH"
|
|
fi
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|