From 224fcc7803225d684cd63f83e9d68d930a94a363 Mon Sep 17 00:00:00 2001 From: Vito Sansevero Date: Sat, 7 Feb 2026 08:30:00 -0800 Subject: [PATCH] chore(ci): add code quality, security scanning, and Dependabot - Add code-quality.yml: Black formatting check, flake8 linting, bandit security scan - Add dependabot.yml: weekly updates for pip deps and GitHub Actions - Add requirements-dev.txt: single source of truth for CI dependencies - Harden test.yml: add permissions, pip caching, use requirements-dev.txt - Add Black/flake8/bandit config to pyproject.toml (line-length=88) --- .github/dependabot.yml | 10 +++++ .github/workflows/code-quality.yml | 62 ++++++++++++++++++++++++++++++ .github/workflows/test.yml | 13 ++++++- pyproject.toml | 12 ++++++ requirements-dev.txt | 11 ++++++ 5 files changed, 107 insertions(+), 1 deletion(-) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/code-quality.yml create mode 100644 requirements-dev.txt diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..645c171 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,10 @@ +version: 2 +updates: + - package-ecosystem: "pip" + directory: "/" + schedule: + interval: "weekly" + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" diff --git a/.github/workflows/code-quality.yml b/.github/workflows/code-quality.yml new file mode 100644 index 0000000..497004e --- /dev/null +++ b/.github/workflows/code-quality.yml @@ -0,0 +1,62 @@ +name: Code Quality + +permissions: + contents: read + +on: + push: + branches: [main] + pull_request: + branches: [main] + +jobs: + lint: + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@v4 + + - name: Set up Python 3.10 + uses: actions/setup-python@v5 + with: + python-version: "3.10" + + - name: Cache pip dependencies + uses: actions/cache@v4 + with: + path: ~/.cache/pip + key: ${{ runner.os }}-pip-quality-${{ hashFiles('requirements-dev.txt') }} + restore-keys: | + ${{ runner.os }}-pip-quality- + + - name: Install dependencies + run: | + python -m pip install --upgrade pip + pip install -r requirements-dev.txt + + - name: Check formatting with Black + run: black --check --diff . + + - name: Lint with flake8 + run: | + # Fail on syntax errors and undefined names + flake8 . --count --select=E9,F63,F7,F82 --show-source --statistics + # Warnings as non-blocking + flake8 . --count --exit-zero --max-line-length=88 --statistics --exclude=reference/,.git,__pycache__,web/ + + security: + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@v4 + + - name: Set up Python 3.10 + uses: actions/setup-python@v5 + with: + python-version: "3.10" + + - name: Install bandit + run: pip install bandit[toml] + + - name: Security scan + run: bandit -r . -ll --exclude=./tests,./reference,./venv -q || true diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 65b722d..637f627 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -1,5 +1,8 @@ name: Tests +permissions: + contents: read + on: pull_request: branches: [main] @@ -21,10 +24,18 @@ jobs: with: python-version: ${{ matrix.python-version }} + - name: Cache pip dependencies + uses: actions/cache@v4 + with: + path: ~/.cache/pip + key: ${{ runner.os }}-pip-${{ matrix.python-version }}-${{ hashFiles('requirements-dev.txt') }} + restore-keys: | + ${{ runner.os }}-pip-${{ matrix.python-version }}- + - name: Install dependencies run: | python -m pip install --upgrade pip - pip install Pillow aiohttp watchdog + pip install -r requirements-dev.txt - name: Run tests run: python -m unittest discover tests/ -v diff --git a/pyproject.toml b/pyproject.toml index 06f3b9d..2ddb2ed 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -13,3 +13,15 @@ Repository = "https://github.com/ComfyAssets/ComfyUI_PromptManager" PublisherId = "kiko9" DisplayName = "ComfyUI_PromptManager" Icon = "https://avatars.githubusercontent.com/u/213204677?s=200" + +[tool.black] +line-length = 88 +target-version = ["py310"] + +[tool.flake8] +max-line-length = 88 +extend-ignore = ["E203", "W503"] +exclude = ["reference/", ".git", "__pycache__", "web/", "venv/"] + +[tool.bandit] +exclude_dirs = ["tests", "reference"] diff --git a/requirements-dev.txt b/requirements-dev.txt new file mode 100644 index 0000000..c045ae3 --- /dev/null +++ b/requirements-dev.txt @@ -0,0 +1,11 @@ +# Runtime dependencies +watchdog>=2.1.0 +Pillow>=8.0.0 +aiohttp>=3.8.0 + +# Code quality +black>=24.0.0 +flake8>=7.0.0 + +# Security scanning +bandit[toml]>=1.7.0