-
Notifications
You must be signed in to change notification settings - Fork 329
135 lines (133 loc) · 4.84 KB
/
Copy pathcoverage.yml
File metadata and controls
135 lines (133 loc) · 4.84 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
name: Coverage
on:
push:
branches:
- main
pull_request:
schedule:
- cron: 0 0 * * *
permissions: # least privilege; jobs needing OIDC override this
contents: read
jobs:
Coverage:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Setup Python environment
uses: actions/setup-python@v6
with:
python-version: '3.11'
- name: Setup virtual environment
run: |
python -m venv venv
source venv/bin/activate
python -m pip install --upgrade pip
- name: Install Requirements
run: |
python -m pip install --upgrade pip
pip install coverage pytest
pip install -r requirements.txt
pip install -r test/requirements.txt
pip install .
- name: Generate Unit Test Coverage
run: |
coverage run --rcfile=.coveragerc -m pytest test/unit/
coverage xml
- name: Upload coverage artifact
uses: actions/upload-artifact@v4
with:
name: unit-coverage
path: coverage.xml
# Separate job so the whole thing can be gated: fork PRs cannot assume the
# OIDC role, so they run the unit tests above but skip the upload here.
CoverageUpload:
needs: Coverage
# Skip on fork PRs: they cannot assume the OIDC role.
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
permissions: # required for OIDC
id-token: write
contents: read
steps:
- uses: actions/checkout@v7
- name: Download coverage artifact
uses: actions/download-artifact@v4
with:
name: unit-coverage
- name: Configure AWS credentials (OIDC)
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: arn:aws:iam::082972943155:role/oidc-github-dropbox-dropbox-sdk-python-repo
aws-region: us-west-2
- name: Get Codecov token from AWS Secrets Manager
uses: aws-actions/aws-secretsmanager-get-secrets@v3
with:
secret-ids: |
CODECOV_TOKEN,codecov-token-dropbox-sdk-python
parse-json-secrets: false
- name: Publish Coverage
uses: codecov/codecov-action@v7
with:
token: ${{ env.CODECOV_TOKEN }}
flags: unit
fail_ci_if_error: true
IntegrationCoverage:
# Skip on fork PRs: they cannot assume the OIDC role.
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
permissions: # required for OIDC
id-token: write
contents: read
steps:
- uses: actions/checkout@v7
- name: Setup Python environment
uses: actions/setup-python@v6
with:
python-version: '3.11'
- name: Setup virtual environment
run: |
python -m venv venv
source venv/bin/activate
python -m pip install --upgrade pip
- name: Install Requirements
run: |
python -m pip install --upgrade pip
pip install coverage pytest
pip install -r requirements.txt
pip install -r test/requirements.txt
pip install .
- name: Configure AWS credentials (OIDC)
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: arn:aws:iam::082972943155:role/oidc-github-dropbox-dropbox-sdk-python-repo
aws-region: us-west-2
- name: Get integration credentials from AWS Secrets Manager
uses: aws-actions/aws-secretsmanager-get-secrets@v3
with:
secret-ids: |
CREDS,api-sdk-integration-test-creds
parse-json-secrets: true
- name: Get Codecov token from AWS Secrets Manager
uses: aws-actions/aws-secretsmanager-get-secrets@v3
with:
secret-ids: |
CODECOV_TOKEN,codecov-token-dropbox-sdk-python
parse-json-secrets: false
- name: Generate Coverage
env:
SCOPED_USER_CLIENT_ID: ${{ env.CREDS_SCOPED_USER_CLIENT_ID }}
SCOPED_USER_CLIENT_SECRET: ${{ env.CREDS_SCOPED_USER_CLIENT_SECRET }}
SCOPED_USER_REFRESH_TOKEN: ${{ env.CREDS_SCOPED_USER_REFRESH_TOKEN }}
SCOPED_TEAM_CLIENT_ID: ${{ env.CREDS_SCOPED_TEAM_CLIENT_ID }}
SCOPED_TEAM_CLIENT_SECRET: ${{ env.CREDS_SCOPED_TEAM_CLIENT_SECRET }}
SCOPED_TEAM_REFRESH_TOKEN: ${{ env.CREDS_SCOPED_TEAM_REFRESH_TOKEN }}
DROPBOX_SHARED_LINK: ${{ env.CREDS_DROPBOX_SHARED_LINK }}
run: |
coverage run --rcfile=.coveragerc -m pytest test/integration/test_dropbox.py
coverage xml
- name: Publish Coverage
uses: codecov/codecov-action@v7
with:
token: ${{ env.CODECOV_TOKEN }}
flags: integration
fail_ci_if_error: true