chore(ci): add code quality, security scanning, and Dependabot

- Add code-quality.yml: Black formatting check, flake8 linting, bandit
  security scan
- Add dependabot.yml: weekly updates for pip deps and GitHub Actions
- Add requirements-dev.txt: single source of truth for CI dependencies
- Harden test.yml: add permissions, pip caching, use requirements-dev.txt
- Add Black/flake8/bandit config to pyproject.toml (line-length=88)
This commit is contained in:
Vito Sansevero
2026-02-07 08:30:00 -08:00
parent 5c5fe512c8
commit 224fcc7803
5 changed files with 107 additions and 1 deletions
+10
View File
@@ -0,0 +1,10 @@
version: 2
updates:
- package-ecosystem: "pip"
directory: "/"
schedule:
interval: "weekly"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
+62
View File
@@ -0,0 +1,62 @@
name: Code Quality
permissions:
contents: read
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python 3.10
uses: actions/setup-python@v5
with:
python-version: "3.10"
- name: Cache pip dependencies
uses: actions/cache@v4
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-quality-${{ hashFiles('requirements-dev.txt') }}
restore-keys: |
${{ runner.os }}-pip-quality-
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements-dev.txt
- name: Check formatting with Black
run: black --check --diff .
- name: Lint with flake8
run: |
# Fail on syntax errors and undefined names
flake8 . --count --select=E9,F63,F7,F82 --show-source --statistics
# Warnings as non-blocking
flake8 . --count --exit-zero --max-line-length=88 --statistics --exclude=reference/,.git,__pycache__,web/
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python 3.10
uses: actions/setup-python@v5
with:
python-version: "3.10"
- name: Install bandit
run: pip install bandit[toml]
- name: Security scan
run: bandit -r . -ll --exclude=./tests,./reference,./venv -q || true
+12 -1
View File
@@ -1,5 +1,8 @@
name: Tests
permissions:
contents: read
on:
pull_request:
branches: [main]
@@ -21,10 +24,18 @@ jobs:
with:
python-version: ${{ matrix.python-version }}
- name: Cache pip dependencies
uses: actions/cache@v4
with:
path: ~/.cache/pip
key: ${{ runner.os }}-pip-${{ matrix.python-version }}-${{ hashFiles('requirements-dev.txt') }}
restore-keys: |
${{ runner.os }}-pip-${{ matrix.python-version }}-
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install Pillow aiohttp watchdog
pip install -r requirements-dev.txt
- name: Run tests
run: python -m unittest discover tests/ -v
+12
View File
@@ -13,3 +13,15 @@ Repository = "https://github.com/ComfyAssets/ComfyUI_PromptManager"
PublisherId = "kiko9"
DisplayName = "ComfyUI_PromptManager"
Icon = "https://avatars.githubusercontent.com/u/213204677?s=200"
[tool.black]
line-length = 88
target-version = ["py310"]
[tool.flake8]
max-line-length = 88
extend-ignore = ["E203", "W503"]
exclude = ["reference/", ".git", "__pycache__", "web/", "venv/"]
[tool.bandit]
exclude_dirs = ["tests", "reference"]
+11
View File
@@ -0,0 +1,11 @@
# Runtime dependencies
watchdog>=2.1.0
Pillow>=8.0.0
aiohttp>=3.8.0
# Code quality
black>=24.0.0
flake8>=7.0.0
# Security scanning
bandit[toml]>=1.7.0