Skip to content

fix(ci): one requirements file and one command for every local check - #432

Merged
TMHSDigital merged 1 commit into
mainfrom
fix/dev-requirements-run-all
Oct 5, 2026
Merged

TMHSDigital merged 1 commit into
mainfrom
fix/dev-requirements-run-all

Conversation

@TMHSDigital

Copy link
Copy Markdown
Owner

Closes #364.

Change

  • requirements-dev.txt:
    • includes -r scripts/site/requirements.txt (Jinja2), plus PyYAML==6.0.2, numpy==2.2.6 and Pillow==11.3.0 (was 11.2.1; 11.3.0 fixes CVE-2025-48379);
    • both inline pip install lines in validate.yml now install from it;
    • Dependabot gets a pip entry for /.
  • tests/run_all.py:
    • one command for every Validate check that doesn't need Blender: all tests/check_*.py and tests/test_*.py, tests/smoke/test_harness.py, build_claude_rules --check and build_plugin_dist --check;
    • also the landing build that check_site_links needs, and the committed-gallery-vs-generator check;
    • the inline validate.yml heredoc checks, extracted from the workflow at run time. This avoids a second copy that could drift, which is why I didn't move them into separate files;
    • -k filters by name.
  • .gitattributes: *.sh text eol=lf.
  • CONTRIBUTING: a new "Run the checks" step in Getting Started.

Evidence (fresh venv, Python 3.13, Windows)

  • pip install -r requirements-dev.txt installs Pillow 11.3.0, numpy 2.2.6 and PyYAML 6.0.2. tests/test_measure_hero_drift.py passes on Pillow 11.3.0.
  • python tests/run_all.py: 28 passed, 0 failed. That includes the three extracted heredoc checks (plugin manifest, Claude packaging, content counts).
  • Falsified: editing examples/gallery.json without regenerating makes run_all -k "gallery matches" FAIL and name the two stale pages. Restored, it passes.
  • validate.yml and dependabot.yml parse.

🤖 Generated with Claude Code

A contributor could not reproduce Validate without reading the YAML:
test deps were pinned inline (`pip install PyYAML==6.0.2`,
`numpy==2.2.6 Pillow==11.2.1`), invisible to Dependabot, and three
checks existed only as heredoc Python inside validate.yml. Pillow 11.2.1
also predates the 11.3.0 fix for CVE-2025-48379.

- requirements-dev.txt pins PyYAML, numpy and Pillow 11.3.0 (plus the
  site build's Jinja2); Validate installs from it and Dependabot watches
  it.
- tests/run_all.py runs every tests/check_*.py and test_*.py, the smoke
  harness tests, the generator --check modes, the landing build the link
  check needs, the gallery-drift check, and the inline validate.yml
  heredoc checks, extracted from the workflow at run time so there is
  still one copy of each. CONTRIBUTING documents it.
- .gitattributes keeps *.sh LF so Windows checkouts run under WSL bash.

Closes #364

Signed-off-by: TMHSDigital <154358121+TMHSDigital@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added the ci label Oct 5, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedpillow@​11.3.0802510010070
Addednumpy@​2.2.67510010010070
Addedpyyaml@​6.0.2100100100100100

View full report

@TMHSDigital

Copy link
Copy Markdown
Owner Author

CI evidence before merge: all checks pass ( 13 pass ). Blender Smoke on PR head: Blender 5.2.2 LTS / Blender 4.5.14 LTS. Summaries (happy path; falsifiers) per leg: 143 passed, 1 skipped, 0 failed;143 passed, 0 skipped, 0 failed;141 passed, 3 skipped, 0 failed;136 passed, 7 skipped, 0 failed;

@TMHSDigital
TMHSDigital merged commit 92d033b into main Oct 5, 2026
13 checks passed
@TMHSDigital
TMHSDigital deleted the fix/dev-requirements-run-all branch October 5, 2026 02:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dx: no requirements-dev.txt or single local 'run all checks' command; validators live inline in YAML; Pillow pin is outdated

1 participant