Skip to content

Modernize the tests-and-lint workflow and add Renovate #271

Description

@jaysonsantos

Part of the repository modernization effort.

Background

.github/workflows/tests-and-lint.yml uses old action versions and routes both jobs through two shell scripts.

Old action versions

Location Pinned version
.github/workflows/tests-and-lint.yml:18 actions/checkout@v2
.github/workflows/tests-and-lint.yml:20 actions/setup-python@v5
.github/workflows/tests-and-lint.yml:33 actions/checkout@v2
.github/workflows/tests-and-lint.yml:35 actions/setup-python@v2

Four call sites hold three different major versions. No update bot config exists in .github/. Nothing bumps these.

The STEP indirection is dead weight

.ci-before-script.sh:

#!/bin/bash
set -ex

python -m pip install --upgrade pip
pip install -r requirements_test.txt && pip install -e .

if [ "$STEP" != "tests" ]; then
    exit 0
fi

sudo apt-get update
sudo apt install memcached

.ci-runs-tests.sh:

#!/bin/bash
set -ex
env
if [ "$STEP" = "tests" ]; then
    py.test --version
    export PYTHONPATH=.
    pip install -e .
    py.test --cov=bmemcached
    exit 0
fi

if [ "$STEP" = "lint" ]; then
    flake8
    exit 0
fi

echo "Unknown step: $STEP"
exit 1

This pattern comes from .travis.yml:9-11. Travis needed an environment variable to branch a build matrix. GitHub Actions has two native jobs already. The workflow sets STEP=tests and STEP=lint inline at lines 25, 28, 40, and 43.

Three concrete costs:

  • pip install -e . runs twice. See .ci-before-script.sh:5 and .ci-runs-tests.sh:7.
  • env at .ci-runs-tests.sh:3 prints the whole environment to a public log.
  • sudo apt install memcached at .ci-before-script.sh:12 has no -y flag.

.travis.yml is dead

.travis.yml:13,15 call .travis-before-script.sh and .travis-runs-tests.sh. Neither file exists in the repository. A stale Travis badge stays at docs/intro.rst:80-81.

Missing hygiene

The workflow has no concurrency: group, no permissions: block, no timeout-minutes:, and no cache: pip. The coverage run at .ci-runs-tests.sh:8 writes to the log and drops the result.

No dependency update bot runs on this repository.

Verified: memcached and TLS work in CI

Run 34284112624 on main installs memcached 1.6.24-1ubuntu0.2 on Ubuntu 24.04. test/test_tls.py ran 48 of 48 tests with 0 skips. The run reports 261 passed.

The comment at flake.nix:16 about missing TLS applies to the nixpkgs build only. It does not apply to CI. Tests do not silently skip.

Proposed workflow

name: Tests and Lint

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]

concurrency:
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true

permissions:
  contents: read

jobs:
  tests:
    runs-on: ubuntu-latest
    timeout-minutes: 15
    strategy:
      fail-fast: false
      matrix:
        # Keep every version quoted. Unquoted 3.10 parses as the float 3.1.
        python-version: ["3.10", "3.11", "3.12", "3.13", "3.14"]

    steps:
      - uses: actions/checkout@v7

      - name: Set up Python ${{ matrix.python-version }}
        uses: actions/setup-python@v7
        with:
          python-version: ${{ matrix.python-version }}
          cache: pip

      - name: Install memcached
        run: sudo apt-get update && sudo apt-get install -y memcached

      - name: Install dependencies
        run: |
          python -m pip install --upgrade pip
          pip install -e .
          pip install --group test

      - name: Run tests
        run: pytest --cov=bmemcached --cov-report=xml --cov-report=term

      - name: Upload coverage report
        if: matrix.python-version == '3.12'
        uses: actions/upload-artifact@v4
        with:
          name: coverage-xml
          path: coverage.xml

  lint:
    runs-on: ubuntu-latest
    timeout-minutes: 5

    steps:
      - uses: actions/checkout@v7

      - name: Set up Python
        uses: actions/setup-python@v7
        with:
          python-version: "3.12"
          cache: pip

      - name: Run ruff
        run: |
          python -m pip install --upgrade pip
          pip install ruff
          ruff check .
          ruff format --check .

Two deliberate changes: max-parallel: 4 is gone, because the matrix holds five legs. fail-fast: false is new, so one failed version does not hide the other results.

Proposed renovate.json

Use Renovate, not Dependabot. Renovate groups update types into one pull request. Dependabot cannot do that.

Put this file at the repository root:

{
  "$schema": "https://docs.renovatebot.com/renovate-schema.json",
  "extends": [
    "config:recommended",
    ":semanticCommits",
    ":semanticCommitTypeAll(chore)"
  ],
  "timezone": "Europe/Berlin",
  "schedule": ["before 6am on monday"],
  "enabledManagers": [
    "github-actions",
    "pep621",
    "pip_requirements",
    "pre-commit",
    "nix"
  ],
  "pre-commit": {
    "enabled": true
  },
  "lockFileMaintenance": {
    "enabled": true
  },
  "packageRules": [
    {
      "description": "Group every patch and minor update into one pull request.",
      "matchUpdateTypes": ["minor", "patch", "digest"],
      "groupName": "all non-major updates",
      "groupSlug": "all-minor-patch"
    },
    {
      "description": "Keep each major update in its own pull request.",
      "matchUpdateTypes": ["major"],
      "dependencyDashboardApproval": true
    }
  ]
}

Behavior of this config:

  • Patch, minor, and digest updates land in one grouped pull request named all non-major updates.
  • Each major update gets its own pull request. It waits for approval on the dependency dashboard.
  • github-actions covers the action pins in this issue. pep621 covers pyproject.toml. pre-commit covers .pre-commit-config.yaml. nix covers flake.lock.
  • :semanticCommits produces conventional commit subjects. The repository uses commitizen. See .cz.yaml.

Two settings to check against Jayson's preference:

  • timezone is set to Europe/Berlin. Change it if that is wrong.
  • schedule runs once per week. Change it for a different cadence.

pip_requirements stays in enabledManagers for now. Remove it after the dependency-group issue deletes requirements_test.txt.

Warning: Renovate needs an app install

The Renovate GitHub App must be installed on this repository. Config alone does nothing.

Install it at https://github.com/apps/renovate. Grant access to jaysonsantos/python-binary-memcached.

The alternative is a self-hosted Renovate run in a GitHub Actions workflow. That needs a token with pull request write access.

Acceptance criteria

  • The workflow uses actions/checkout@v7 and actions/setup-python@v7 at every call site.
  • The workflow sets concurrency:, a top-level permissions: contents: read, and timeout-minutes: on both jobs.
  • Both setup-python steps set cache: pip.
  • The matrix reads ["3.10", "3.11", "3.12", "3.13", "3.14"]. Every version stays in quotes.
  • .ci-before-script.sh and .ci-runs-tests.sh are deleted. The workflow holds their steps inline.
  • .travis.yml is deleted. The Travis badge at docs/intro.rst:80-81 points at the GitHub Actions badge, or the badge is removed.
  • renovate.json exists at the repository root and matches the content above.
  • Patch and minor updates group into one pull request. Major updates stay separate.
  • The Renovate GitHub App is installed on this repository, or a self-hosted Renovate workflow exists.
  • The workflow uploads coverage.xml as an artifact.
  • CI passes on a test pull request.

Files to change

.github/workflows/tests-and-lint.yml, .ci-before-script.sh (delete), .ci-runs-tests.sh (delete), .travis.yml (delete), renovate.json (new), docs/intro.rst.

Order

The proposed workflow states the final state. It assumes the minimum-version issue, the ruff issue, and the test-dependency issue all landed. If this issue lands first, keep flake8 and requirements_test.txt in the steps. Change them in the later issues.

Activity

  1. added
    ciContinuous integration and release automation
    on Sep 8, 2026
  2. jaysonsantos commented on Sep 8, 2026

    @jaysonsantos
    OwnerAuthor

    Tracked in #277.

  3. changed the title [-]Modernize the tests-and-lint workflow and add Dependabot[/-] [+]Modernize the tests-and-lint workflow and add Renovate[/+] on Sep 8, 2026
  4. jaysonsantos commented on Sep 8, 2026

    @jaysonsantos
    OwnerAuthor

    Changed from Dependabot to Renovate per the owner. Renovate groups patch and minor updates into one pull request. Dependabot cannot group by update type. The issue body now holds the full renovate.json.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ciContinuous integration and release automationmodernizationRepo modernization effort

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions