Replace PAT with SDK Updater GitHub App #2726
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Coverage | |
| on: | |
| push: | |
| branches: | |
| - main | |
| pull_request: | |
| schedule: | |
| - cron: 0 0 * * * | |
| permissions: # least privilege; jobs needing OIDC override this | |
| contents: read | |
| jobs: | |
| Coverage: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Python environment | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version: '3.11' | |
| - name: Setup virtual environment | |
| run: | | |
| python -m venv venv | |
| source venv/bin/activate | |
| python -m pip install --upgrade pip | |
| - name: Install Requirements | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install coverage pytest | |
| pip install -r requirements.txt | |
| pip install -r test/requirements.txt | |
| pip install . | |
| - name: Generate Unit Test Coverage | |
| run: | | |
| coverage run --rcfile=.coveragerc -m pytest test/unit/ | |
| coverage xml | |
| - name: Upload coverage artifact | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: unit-coverage | |
| path: coverage.xml | |
| # Separate job so the whole thing can be gated: fork PRs cannot assume the | |
| # OIDC role, so they run the unit tests above but skip the upload here. | |
| CoverageUpload: | |
| needs: Coverage | |
| # Skip on fork PRs: they cannot assume the OIDC role. | |
| if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository | |
| runs-on: ubuntu-latest | |
| permissions: # required for OIDC | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Download coverage artifact | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: unit-coverage | |
| - name: Configure AWS credentials (OIDC) | |
| uses: aws-actions/configure-aws-credentials@v6 | |
| with: | |
| role-to-assume: arn:aws:iam::082972943155:role/oidc-github-dropbox-dropbox-sdk-python-repo | |
| aws-region: us-west-2 | |
| - name: Get Codecov token from AWS Secrets Manager | |
| uses: aws-actions/aws-secretsmanager-get-secrets@v3 | |
| with: | |
| secret-ids: | | |
| CODECOV_TOKEN,codecov-token-dropbox-sdk-python | |
| parse-json-secrets: false | |
| - name: Publish Coverage | |
| uses: codecov/codecov-action@v7 | |
| with: | |
| token: ${{ env.CODECOV_TOKEN }} | |
| flags: unit | |
| fail_ci_if_error: true | |
| IntegrationCoverage: | |
| # Skip on fork PRs: they cannot assume the OIDC role. | |
| if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository | |
| runs-on: ubuntu-latest | |
| permissions: # required for OIDC | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Python environment | |
| uses: actions/setup-python@v6 | |
| with: | |
| python-version: '3.11' | |
| - name: Setup virtual environment | |
| run: | | |
| python -m venv venv | |
| source venv/bin/activate | |
| python -m pip install --upgrade pip | |
| - name: Install Requirements | |
| run: | | |
| python -m pip install --upgrade pip | |
| pip install coverage pytest | |
| pip install -r requirements.txt | |
| pip install -r test/requirements.txt | |
| pip install . | |
| - name: Configure AWS credentials (OIDC) | |
| uses: aws-actions/configure-aws-credentials@v6 | |
| with: | |
| role-to-assume: arn:aws:iam::082972943155:role/oidc-github-dropbox-dropbox-sdk-python-repo | |
| aws-region: us-west-2 | |
| - name: Get integration credentials from AWS Secrets Manager | |
| uses: aws-actions/aws-secretsmanager-get-secrets@v3 | |
| with: | |
| secret-ids: | | |
| CREDS,api-sdk-integration-test-creds | |
| parse-json-secrets: true | |
| - name: Get Codecov token from AWS Secrets Manager | |
| uses: aws-actions/aws-secretsmanager-get-secrets@v3 | |
| with: | |
| secret-ids: | | |
| CODECOV_TOKEN,codecov-token-dropbox-sdk-python | |
| parse-json-secrets: false | |
| - name: Generate Coverage | |
| env: | |
| SCOPED_USER_CLIENT_ID: ${{ env.CREDS_SCOPED_USER_CLIENT_ID }} | |
| SCOPED_USER_CLIENT_SECRET: ${{ env.CREDS_SCOPED_USER_CLIENT_SECRET }} | |
| SCOPED_USER_REFRESH_TOKEN: ${{ env.CREDS_SCOPED_USER_REFRESH_TOKEN }} | |
| SCOPED_TEAM_CLIENT_ID: ${{ env.CREDS_SCOPED_TEAM_CLIENT_ID }} | |
| SCOPED_TEAM_CLIENT_SECRET: ${{ env.CREDS_SCOPED_TEAM_CLIENT_SECRET }} | |
| SCOPED_TEAM_REFRESH_TOKEN: ${{ env.CREDS_SCOPED_TEAM_REFRESH_TOKEN }} | |
| DROPBOX_SHARED_LINK: ${{ env.CREDS_DROPBOX_SHARED_LINK }} | |
| run: | | |
| coverage run --rcfile=.coveragerc -m pytest test/integration/test_dropbox.py | |
| coverage xml | |
| - name: Publish Coverage | |
| uses: codecov/codecov-action@v7 | |
| with: | |
| token: ${{ env.CODECOV_TOKEN }} | |
| flags: integration | |
| fail_ci_if_error: true |