name: CI on: push: branches-ignore: - main pull_request: permissions: contents: read packages: write jobs: lint-and-test: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-python@v5 with: python-version: "3.12" cache: pip - run: pip install -e ".[dev]" - run: python -m ruff check steward/ tests/ - run: python -m pytest tests/ -v docker-build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Log in to GHCR # Only log in when pushing (not on PRs from forks) if: github.event_name == 'push' uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Docker metadata id: meta uses: docker/metadata-action@v5 with: images: ghcr.io/${{ github.repository }} tags: | # feature-branch push → ghcr.io/…/steward:my-feature-branch type=ref,event=branch # pull-request → ghcr.io/…/steward:pr-42 type=ref,event=pr # always → ghcr.io/…/steward:sha-abc1234 type=sha,prefix=sha- - name: Build and push uses: docker/build-push-action@v6 with: context: . # Push on branch pushes; only validate (no push) on PRs push: ${{ github.event_name == 'push' }} tags: ${{ steps.meta.outputs.tags }} labels: ${{ steps.meta.outputs.labels }}