Skip to content

Merge dev: CI hardening, dependency floors, workflow tests - #99

Merged
JE-Chen merged 9 commits into
mainfrom
dev
Sep 24, 2026
Merged

JE-Chen merged 9 commits into
mainfrom
dev

Conversation

@JE-Chen

@JE-Chen JE-Chen commented Sep 24, 2026

Copy link
Copy Markdown
Member

Summary

Promotes current dev work to main for a stable release.

  • Pin CI actions (checkout, setup-python) by commit SHA; move to Node 24 action versions.
  • Restrict persisted checkout credentials to the publish job that pushes.
  • Add Dependabot config to track GitHub Actions on dev.
  • Raise dependency floors: cryptography>=50.0.1, sphinx>=8.1.3.
  • Add tests/test_workflow_actions.py covering workflow actions.
  • Record the dependency-floor merges and CI lock in docs/updates/.

Notes

  • main's released versions (stable 0.0.48 / dev 0.0.50) are preserved by the merge; the publish workflow bumps the patch on merge.
  • Merges cleanly against origin/main (verified, no conflicts).

dependabot Bot and others added 8 commits September 23, 2026 04:48
Updates the requirements on [cryptography](https://github.com/pyca/cryptography) to permit the latest version.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@47.0.0...50.0.1)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Updates the requirements on [sphinx](https://github.com/sphinx-doc/sphinx) to permit the latest version.
- [Release notes](https://github.com/sphinx-doc/sphinx/releases)
- [Changelog](https://github.com/sphinx-doc/sphinx/blob/v8.1.3/CHANGES.rst)
- [Commits](sphinx-doc/sphinx@v7.4.7...v8.1.3)

---
updated-dependencies:
- dependency-name: sphinx
  dependency-version: 8.1.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…/cryptography-gte-50.0.1

Update cryptography requirement from >=47.0.0 to >=50.0.1
…/sphinx-gte-8.1.3

Update sphinx requirement from >=7.4.7 to >=8.1.3
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 27 complexity · 0 duplication

Metric Results
Complexity 27
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@sonarqubecloud

Copy link
Copy Markdown

@JE-Chen
JE-Chen merged commit cf31a73 into main Sep 24, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant