Spaces:
Running
Pin dependencies and add CI on pull requests
Browse filesTwo related gaps found while writing the "coming back after a month"
runbook:
- requirements.txt/requirements-dev.txt had no version pins at all.
A fresh `pip install` any time in the future would silently grab
whatever's newest on PyPI, with no way to tell "my change broke this"
from "an unrelated dependency update broke this." Pinned every package
to the version this codebase is actually tested against, with a range
up to its next breaking boundary (next major for a stable package, next
minor for a 0.x one). playwright and duckduckgo_search are pinned
tighter (patch-only): playwright ships in lockstep with a specific
browser revision - a mismatch is a real failure mode we already hit and
worked around in tests/conftest.py - and duckduckgo_search has a history
of breaking changes between versions. pytest-asyncio (dev-only) is
pinned the same way, for the same reason: its event-loop-scope semantics
bit us once already this project (see the `browser` fixture's comment).
Verified by installing from a clean venv and confirming the resolved
versions match exactly and all 97 tests still pass.
- Nothing ran the test suite until a change was already merged to main -
deploy-to-hf.yml's `test` job only triggers on push to main. Added
.github/workflows/test.yml, running the same suite on every pull
request, so a change gets feedback before merge instead of only at
deploy time.
- .github/workflows/test.yml +33 -0
- requirements-dev.txt +7 -2
- requirements.txt +24 -10
|
@@ -0,0 +1,33 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
name: Tests
|
| 2 |
+
|
| 3 |
+
# Runs the suite on every pull request targeting main, so a change gets
|
| 4 |
+
# feedback before merge instead of only at deploy time. deploy-to-hf.yml
|
| 5 |
+
# runs its own copy of this same gate right before every push to the Space
|
| 6 |
+
# (belt-and-suspenders: never trust a check that ran before the current
|
| 7 |
+
# state existed, the same principle behind that workflow's
|
| 8 |
+
# --force-with-lease push).
|
| 9 |
+
on:
|
| 10 |
+
pull_request:
|
| 11 |
+
branches:
|
| 12 |
+
- main
|
| 13 |
+
|
| 14 |
+
jobs:
|
| 15 |
+
test:
|
| 16 |
+
runs-on: ubuntu-latest
|
| 17 |
+
steps:
|
| 18 |
+
- name: Checkout
|
| 19 |
+
uses: actions/checkout@v4
|
| 20 |
+
|
| 21 |
+
- name: Set up Python
|
| 22 |
+
uses: actions/setup-python@v5
|
| 23 |
+
with:
|
| 24 |
+
python-version: "3.11"
|
| 25 |
+
|
| 26 |
+
- name: Install dependencies
|
| 27 |
+
run: pip install -r requirements-dev.txt
|
| 28 |
+
|
| 29 |
+
- name: Install Playwright's Chromium
|
| 30 |
+
run: playwright install --with-deps chromium
|
| 31 |
+
|
| 32 |
+
- name: Run tests
|
| 33 |
+
run: pytest
|
|
@@ -1,7 +1,12 @@
|
|
| 1 |
# Test-only dependencies. Install with:
|
| 2 |
# pip install -r requirements.txt -r requirements-dev.txt
|
| 3 |
# playwright install chromium # if not already present on the machine
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 4 |
-r requirements.txt
|
| 5 |
pytest>=8,<10
|
| 6 |
-
pytest-asyncio>=0.
|
| 7 |
-
respx>=0.
|
|
|
|
| 1 |
# Test-only dependencies. Install with:
|
| 2 |
# pip install -r requirements.txt -r requirements-dev.txt
|
| 3 |
# playwright install chromium # if not already present on the machine
|
| 4 |
+
#
|
| 5 |
+
# See the pinning note at the top of requirements.txt - same policy here.
|
| 6 |
+
# pytest-asyncio is pinned tighter (patch-only): its event-loop-scope
|
| 7 |
+
# semantics have changed in ways that mattered to us before (see
|
| 8 |
+
# tests/conftest.py's comment on the `browser` fixture).
|
| 9 |
-r requirements.txt
|
| 10 |
pytest>=8,<10
|
| 11 |
+
pytest-asyncio>=1.4.0,<1.5
|
| 12 |
+
respx>=0.23.1,<0.24
|
|
@@ -1,10 +1,24 @@
|
|
| 1 |
-
|
| 2 |
-
|
| 3 |
-
|
| 4 |
-
|
| 5 |
-
|
| 6 |
-
|
| 7 |
-
|
| 8 |
-
|
| 9 |
-
|
| 10 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
# Pinned to the versions this codebase is actually tested against (see
|
| 2 |
+
# CONTRIBUTING.md). Range = "current version, up to the next breaking
|
| 3 |
+
# boundary" - the next major for a stable (>=1.0) package, the next minor
|
| 4 |
+
# for a 0.x package (0.x minor bumps are semver's equivalent of a major).
|
| 5 |
+
#
|
| 6 |
+
# playwright and duckduckgo_search are pinned tighter (patch-only): playwright
|
| 7 |
+
# ships in lockstep with a specific browser revision (a version mismatch is a
|
| 8 |
+
# real, previously-hit failure mode - see tests/conftest.py's fallback
|
| 9 |
+
# executable_path logic), and duckduckgo_search has a history of breaking
|
| 10 |
+
# changes between versions.
|
| 11 |
+
#
|
| 12 |
+
# To bump a dependency: update the pin here, run `pytest`, and if you touch
|
| 13 |
+
# playwright specifically, re-run the full suite including
|
| 14 |
+
# tests/test_serp_playwright.py (it drives a real browser).
|
| 15 |
+
fastapi>=0.141.1,<0.142
|
| 16 |
+
uvicorn>=0.52.4,<0.53
|
| 17 |
+
pydantic>=2.13.5,<3
|
| 18 |
+
playwright>=1.62.0,<1.63
|
| 19 |
+
duckduckgo_search>=8.1.1,<8.2
|
| 20 |
+
beautifulsoup4>=4.15.0,<5
|
| 21 |
+
httpx>=0.28.1,<0.29
|
| 22 |
+
lxml>=6.1.2,<7
|
| 23 |
+
python-dotenv>=1.2.3,<2
|
| 24 |
+
fastmcp>=3.4.7,<4
|