Skip to content

ci: restore CI with lint and test checks - #26

Merged
man4ish merged 1 commit into
mainfrom
ci/restore-ci
Oct 3, 2026
Merged

man4ish merged 1 commit into
mainfrom
ci/restore-ci

Conversation

@man4ish

@man4ish man4ish commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

CI was moved to .github/workflows_disabled, so pushes and PRs to main ran no checks.

Why the old workflow could not pass: pyproject.toml pins two private repositories by git URL, omnibioai-iam-client@v0.1.4 and omnibioai-usage-client@v0.1.0. A workflow's GITHUB_TOKEN cannot read other private repositories, so the install step failed and the tests never ran. The "missing httpx" errors were a symptom of that failed install.

New .github/workflows/ci.yml

  • Triggers: pushes and PRs to main.
  • Steps: installs -e ".[dev]", then runs ruff check . and pytest with the 95% coverage gate from pyproject.toml, on Python 3.11.
  • Private dependencies: the repository secret PRIVATE_DEPS_TOKEN, a fine-grained token with Contents: read on those two repositories only. It is used solely to rewrite those two dependency URLs. If it is unset, the job fails at once with an explicit error.
  • Permissions: read-only (contents: read). The existing publish workflow is unchanged.

Before merging: add the PRIVATE_DEPS_TOKEN secret under Settings → Secrets and variables → Actions. Until then this PR's CI fails at the install step, by design.

Verified locally: a fresh Python 3.11 environment with pip install -e ".[dev]" resolved both private dependencies at their pinned tags; ruff check . passes; 598 tests pass at 95.14% coverage.

🤖 Generated with Claude Code

https://claude.ai/code/session_016nxi4bp7DP1ancERNUUfzj


Generated by Claude Code

CI was moved to .github/workflows_disabled. Restored as-is it could not
pass: pyproject.toml pins two private repositories by git URL
(omnibioai-iam-client v0.1.4 and omnibioai-usage-client v0.1.0), and the
workflow's GITHUB_TOKEN cannot read other private repositories, so the
install step failed and the test suite never ran.

The new .github/workflows/ci.yml installs the package with its dev extras
and runs ruff and pytest (with the 95% coverage gate in pyproject.toml)
on Python 3.11 for pushes and pull requests to main. A repository secret,
PRIVATE_DEPS_TOKEN, is used only to rewrite the URLs of those two
dependencies; the job fails early with an explicit error if it is unset.
Permissions are read-only, and the publish workflows are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016nxi4bp7DP1ancERNUUfzj

man4ish commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator Author

The failing Lint & test (Python 3.11) check stops at its first guard, as intended: Repository secret PRIVATE_DEPS_TOKEN is not set. No code change will fix this; the secret has to be added.

Blocker: add the repository secret PRIVATE_DEPS_TOKEN (Settings → Secrets and variables → Actions). It should be a fine-grained token with Contents: read-only on omnibioai-iam-client and omnibioai-usage-client only. Once it exists, re-running this check should pass: locally, the same install, lint and tests pass, with 598 tests at 95.14% coverage.


Generated by Claude Code

@man4ish
man4ish merged commit ef63210 into main Oct 3, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants