name: CI on: push: branches-ignore: - main pull_request: permissions: contents: read packages: write jobs: lint-and-test: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - uses: actions/setup-python@v7 with: python-version: "3.14" cache: pip - run: pip install -e ".[dev]" - run: python -m ruff check steward/ tests/ - run: python -m pytest tests/ -v docker-build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v7 - name: Set up QEMU uses: docker/setup-qemu-action@v4 - name: Set up Docker Buildx uses: docker/setup-buildx-action@v4 - name: Log in to GHCR # Only log in when pushing (not on PRs from forks) if: github.event_name == 'push' uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Docker metadata id: meta uses: docker/metadata-action@v6 with: images: ghcr.io/${{ github.repository }} tags: | # feature-branch push → ghcr.io/…/steward:my-feature-branch type=ref,event=branch # pull-request → ghcr.io/…/steward:pr-42 type=ref,event=pr # always → ghcr.io/…/steward:sha-abc1234 type=sha,prefix=sha- - name: Build and push uses: docker/build-push-action@v7 with: context: . platforms: linux/amd64,linux/arm64 # Push on branch pushes; only validate (no push) on PRs push: ${{ github.event_name == 'push' }} tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }}