name: Run Tests & Linting on: [push, pull_request] jobs: test: runs-on: ubuntu-latest steps: - name: Checkout Code uses: actions/checkout@v3 - name: Set up Python uses: actions/setup-python@v4 with: python-version: "3.11" - name: Install Dependencies run: | python -m pip install --upgrade pip pip install -r requirements-dev.txt - name: Run Tests run: pytest tests/ -v --cov=app --cov-report=xml --cov-report=term - name: Upload Coverage to Codecov uses: codecov/codecov-action@v3 with: file: ./coverage.xml fail_ci_if_error: false - name: Run Linter (Flake8) run: flake8 app/ --max-line-length=120 --extend-ignore=E203,W503 continue-on-error: false - name: Run Code Formatter (Black) run: black --check app/ --line-length=120 continue-on-error: false - name: Run Type Checker (Mypy) run: mypy app/ --ignore-missing-imports continue-on-error: true - name: Run Linter (Pylint) run: pylint app/ --max-line-length=120 --disable=C0111,C0103,R0903 continue-on-error: true - name: Run Security Linter (Bandit) - Full Report run: | echo "Running Bandit security scan..." bandit -r app/ -f json -o bandit-report.json || true continue-on-error: true - name: Run Security Linter (Bandit) - Fail on High/Medium run: | echo "Running Bandit security scan (fail on high/medium severity)..." bandit -r app/ -ll continue-on-error: false - name: Upload Bandit Report uses: actions/upload-artifact@v4 if: always() with: name: bandit-report path: bandit-report.json