mirror of
https://github.com/apache/superset.git
synced 2026-07-28 17:42:40 +00:00
Adds a per-job/step Gantt chart (rendered as a mermaid diagram in the run summary) to the 15 substantive CI workflows -- the 13 setup-backend consumers plus superset-frontend.yml and docker.yml, the other two heaviest CI paths. Skips trivial bot/label/notification workflows that run in seconds and have nothing worth visualizing. For single-job (or single-heavy-job-in-a-linear-chain) workflows, the step is registered first, before checkout, so its post-processing hook -- which is what actually renders the timeline -- captures the full job including other steps' own cleanup. For workflows with multiple independent parallel jobs, added a dedicated `actions-timeline` terminal job (`needs: [...]`, `if: always()`) instead of duplicating the step into each parallel job: the action fetches every job of the whole run from the GitHub API regardless of which job it executes in, so one copy that runs after every sibling job completes produces one authoritative timeline, while N copies dropped into N parallel jobs would each race to render an incomplete gantt before their siblings finish. `expand-composite-actions: true` is set everywhere so setup-backend's internal steps (Python setup, uv install, apt package caching, dependency install) show up as their own bars rather than one opaque blob -- directly useful given the last two PRs' worth of composite-action changes. `actions: read` is added wherever needed to read job/step timing from the Actions API, either to the workflow's top-level `permissions:` (when the job in question has no job-level override) or directly into the relevant job's own `permissions:` block (when one already exists, since a job-level block replaces rather than merges with the workflow-level one).
121 lines
4.3 KiB
YAML
121 lines
4.3 KiB
YAML
# Python unit tests
|
|
name: Python-Unit
|
|
|
|
# Least-privilege default for GITHUB_TOKEN. Jobs that need more (e.g. OIDC for
|
|
# codecov uploads) opt in via their own job-level `permissions:` block.
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- "master"
|
|
- "[0-9].[0-9]*"
|
|
pull_request:
|
|
types: [synchronize, opened, reopened, ready_for_review]
|
|
|
|
# cancel previous workflow jobs for PRs
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
changes:
|
|
runs-on: ubuntu-26.04
|
|
timeout-minutes: 10
|
|
permissions:
|
|
contents: read
|
|
pull-requests: read
|
|
outputs:
|
|
python: ${{ steps.check.outputs.python }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
- name: Check for file changes
|
|
id: check
|
|
uses: ./.github/actions/change-detector/
|
|
with:
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
unit-tests:
|
|
needs: changes
|
|
if: needs.changes.outputs.python == 'true'
|
|
runs-on: ubuntu-26.04
|
|
timeout-minutes: 30
|
|
permissions:
|
|
id-token: write
|
|
strategy:
|
|
matrix:
|
|
# Full version spread on push (master/release) + nightly; current only
|
|
# on PRs to cut runner cost (cross-version breaks are caught at merge).
|
|
python-version: ${{ github.event_name == 'pull_request' && fromJSON('["current"]') || fromJSON('["current", "next"]') }}
|
|
env:
|
|
PYTHONPATH: ${{ github.workspace }}
|
|
# Promotes the SQLAlchemy 2.0 deprecation warnings already locked in as
|
|
# errors via pytest.ini's `filterwarnings` to actually run in CI, so a
|
|
# regression on those fails the build instead of relying on a
|
|
# contributor remembering to set this locally. See the migration
|
|
# battleplan: https://github.com/apache/superset/discussions/40273
|
|
SQLALCHEMY_WARN_20: "1"
|
|
steps:
|
|
- name: "Checkout ${{ github.ref }} ( ${{ github.sha }} )"
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
submodules: recursive
|
|
- name: Setup Python
|
|
uses: ./.github/actions/setup-backend/
|
|
with:
|
|
python-version: ${{ matrix.python-version }}
|
|
- name: Python unit tests
|
|
env:
|
|
SUPERSET_TESTENV: true
|
|
SUPERSET_SECRET_KEY: not-a-secret
|
|
run: |
|
|
pytest --durations-min=0.5 --cov-report= --cov=superset ./tests/common ./tests/unit_tests --cache-clear --maxfail=50
|
|
- name: Python 100% coverage unit tests
|
|
env:
|
|
SUPERSET_TESTENV: true
|
|
SUPERSET_SECRET_KEY: not-a-secret
|
|
run: |
|
|
pytest --durations-min=0.5 --cov=superset/sql/ ./tests/unit_tests/sql/ --cache-clear --cov-fail-under=100
|
|
pytest --durations-min=0.5 --cov=superset/semantic_layers/ ./tests/unit_tests/semantic_layers/ --cache-clear --cov-fail-under=100
|
|
- name: Upload code coverage
|
|
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
|
|
with:
|
|
flags: python,unit
|
|
verbose: true
|
|
use_oidc: true
|
|
slug: apache/superset
|
|
|
|
# Stable required-status-check anchor. `unit-tests` is a matrix job gated on
|
|
# change detection, so on non-Python PRs it is skipped and never produces its
|
|
# `unit-tests (current)` context (a job-level skip happens before matrix
|
|
# expansion). This always-running job reports a single context that branch
|
|
# protection can require: it passes when unit-tests succeeded or was skipped,
|
|
# and fails only on a real failure.
|
|
unit-tests-required:
|
|
needs: [changes, unit-tests]
|
|
if: always()
|
|
runs-on: ubuntu-26.04
|
|
timeout-minutes: 5
|
|
permissions:
|
|
contents: read
|
|
actions: read
|
|
steps:
|
|
- uses: Kesin11/actions-timeline@7bf79990b7c09f5dfb570ac30b814ca597bd538e # v3.1.1
|
|
with:
|
|
expand-composite-actions: true
|
|
|
|
- name: Check unit-tests result
|
|
env:
|
|
RESULT: ${{ needs.unit-tests.result }}
|
|
run: |
|
|
if [ "$RESULT" != "success" ] && [ "$RESULT" != "skipped" ]; then
|
|
echo "unit-tests did not pass (result: $RESULT)"
|
|
exit 1
|
|
fi
|
|
echo "unit-tests result: $RESULT"
|