CI: update checkout, setup-python, setup-uv, codecov - #539
Conversation
actions/checkout, actions/setup-python, actions/cache, and codecov/codecov-action were all still pinned to majors that run on the deprecated Node.js 20 runtime. Bumped to v7 (v6 for actions/cache), clearing the warning entirely. codecov-action's v5 rewrite dropped the `file` input this workflow used; renamed to `files`, its replacement. astral-sh/setup-uv is left untouched here, unlike the equivalent fix in audeer/opensmile-python/audb: it's already SHA-pinned to v7.1.0 (not v5 like those repos), which already runs on Node.js 24 and whose default cache-dependency-glob already includes pyproject.toml (added in v6.0.0) -- so neither the dead-caching bug nor the Node 20 warning applies to setup-uv here. No prune-cache decision needed for the same reason: its config isn't touched.
Reviewer's guide (collapsed on small PRs)Reviewer's GuideUpdates GitHub Actions workflow dependencies to Node.js 24–compatible majors and adjusts Codecov config for the v5+ API, eliminating Node 20 deprecation warnings while keeping existing behavior intact. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've left some high level feedback:
- Since you’re already SHA-pinning
astral-sh/setup-uv, consider pinning the other GitHub Actions to specific commit SHAs instead of major tags (e.g.,actions/checkout@v7→actions/checkout@<sha>) to keep behavior stable and improve supply-chain security.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- Since you’re already SHA-pinning `astral-sh/setup-uv`, consider pinning the other GitHub Actions to specific commit SHAs instead of major tags (e.g., `actions/checkout@v7` → `actions/checkout@<sha>`) to keep behavior stable and improve supply-chain security.Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
I would also update it to v9.0.0 so we are in line with the other repos. |
Was left untouched in the previous commit since it was already SHA-pinned to v7.1.0, past the two fixes this PR is otherwise about (pyproject.toml in the default cache glob since v6.0.0, Node 24 runtime since v7.0.0). Hagen asked for it anyway, to keep the pin in line with audeer/opensmile-python/audb, which all now use the same v9.0.0 tag. This does change one default: prune-cache flips from true (v7.1.0) to false (v9.0.0). Checked audformat's dependencies (audeer, audiofile, iso639-lang, iso3166, oyaml, pandas, pyarrow, pyyaml) -- no large binary wheels -- so left at the new default, same call as audeer/opensmile-python/audb.
|
Done in a577fa2 — bumped One thing worth flagging: this does change one default, |
|
Re: SHA-pinning suggestion — going the other way here intentionally. audformat's `setup-uv` was the outlier (SHA-pinned while everything else uses floating major tags), and Hagen's asked to bring it in line with the floating-tag convention used across audeer/opensmile-python/audb/audformat rather than move the rest toward SHA pins. Consistent floating major tags across all four repos keeps the maintenance story simple (one version bump PR touches all of them the same way); full SHA-pinning would trade that for supply-chain hardening this org hasn't adopted elsewhere. Appreciate the flag, but leaving as-is for this PR. |
* Fix CI caching; bump checkout/setup-python off Node.js 20 Two related CI bugs, both caused by stale GitHub Action version pins: 1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does, so caching now works with no lockfile needed. 2. Node.js 20 deprecation: actions/checkout and actions/setup-python bumped to v7, clearing the "Node.js 20 is deprecated" warning. codecov/codecov-action bumped to v7; its v5 rewrite dropped the singular `file:` input in favor of `files:`, renamed accordingly. actions/cache (where used, for test-data caching) bumped to v6 for the same reason. Left `prune-cache` at its new default (off): no large pre-built binary wheels like torch in this repo's dependency tree, so pruning would save ~0 disk space while costing avoidable re-downloads. Part of the same CI cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, and audeering/audresample#83. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 Two related CI bugs, both caused by stale GitHub Action version pins: 1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does, so caching now works with no lockfile needed. 2. Node.js 20 deprecation: actions/checkout and actions/setup-python bumped to v7, clearing the "Node.js 20 is deprecated" warning. codecov/codecov-action bumped to v7; its v5 rewrite dropped the singular `file:` input in favor of `files:`, renamed accordingly. actions/cache (where used, for test-data caching) bumped to v6 for the same reason. Left `prune-cache` at its new default (off): no large pre-built binary wheels like torch in this repo's dependency tree, so pruning would save ~0 disk space while costing avoidable re-downloads. Part of the same CI cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, and audeering/audresample#83. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Bump mamba-org/setup-micromamba off Node.js 20 too Left this untouched in the first commit since it wasn't one of the four actions this rollout targets, but it still triggers its own "Node.js 20 is deprecated" warning (v2 targets Node 20). v3.0.0 updated it to run on Node 24, so bump it too -- otherwise the PR's own claim of clearing the Node.js 20 warning entirely isn't actually true for this repo. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 setup-uv's cache keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv from the floating tag v5 -> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does -- so caching now works with no lockfile needed. v7.0.0 also carries the Node 20 -> Node 24 runtime bump. Also bumped actions/checkout and actions/setup-python from v4/v5 to v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20 is deprecated" warning entirely. codecov-action's v5 rewrite dropped the `file` input this workflow used; renamed to `files`, its replacement. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audmath's only runtime dependency is numpy, with no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Same cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, and audeering/audiofile#193. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 setup-uv's cache keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv (pinned via SHA 3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does -- so caching now works with no lockfile needed. Note the existing pin already sat at v7.1.0, past both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump (v7.0.0), so neither bug technically applied to this action here -- bumping to v9.0.0 anyway for consistency across the sibling repos in this cleanup, matching what was done for audformat's and audbackend's setup-uv pins after the fact (same SHA-pin situation). Also bumped actions/checkout and actions/setup-python from v4/v5 to v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20 is deprecated" warning entirely. codecov-action's v5 rewrite dropped the `file` input this workflow used; renamed to `files`, its replacement. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audmetric's runtime dependencies (audeer, numpy) have no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Same cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, and audeering/audiofile#193. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 setup-uv's cache keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does -- so caching now works with no lockfile needed. v7.0.0 also moved the action off the deprecated Node.js 20 runtime. Also bumped actions/checkout and actions/setup-python from v4/v5 to v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20 is deprecated" warning entirely. codecov-action's v5 rewrite dropped the `file` input this workflow used; renamed to `files`, its replacement, in test.yml so the coverage upload doesn't silently no-op. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audobject's runtime dependencies (asttokens, audeer, oyaml, packaging) have no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Same cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, audeering/audiofile#193, and audeering/audmath#76, audeering/audmetric#94. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 Two related CI bugs, both caused by stale GitHub Action version pins: 1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is committed and changes exactly when a dependency does, so caching now works with no lockfile needed. 2. Node.js 20 deprecation: actions/checkout and actions/setup-python bumped to v7, clearing the "Node.js 20 is deprecated" warning. codecov/codecov-action bumped to v7; its v5 rewrite dropped the singular `file:` input in favor of `files:`, renamed accordingly. actions/cache (where used, for test-data caching) bumped to v6 for the same reason. Left `prune-cache` at its new default (off): no large pre-built binary wheels like torch in this repo's dependency tree, so pruning would save ~0 disk space while costing avoidable re-downloads. Part of the same CI cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, and audeering/audresample#83. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Bump mamba-org/setup-micromamba off Node.js 20 too Left this untouched in the first commit since it wasn't one of the four actions this rollout targets, but it still triggers its own "Node.js 20 is deprecated" warning (v1 targets Node 20). v3.0.0 updated it to run on Node 24, so bump it too -- otherwise the PR's own claim of clearing the Node.js 20 warning entirely isn't actually true for this repo. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
* Fix CI caching; bump checkout/setup-python off Node.js 20 Two related CI bugs, both caused by stale GitHub Action version pins: 1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob keys on uv.lock/requirements*.txt, neither of which exists here (no committed lockfile, by design), so caching never actually worked. This repo's setup-uv pin was already a SHA (3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag v7.1.0 — past the fix that matters here (v6.0.0 added pyproject.toml to the default glob) and past the Node 20 -> Node 24 runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency with the other repos in this cleanup. 2. Node.js 20 deprecation: actions/checkout and actions/setup-python bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning. codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the singular `file:` input in favor of `files:`, renamed accordingly. No actions/cache usage exists in this repo's workflows. Left `prune-cache` at its new default (off): audplot's dependency tree (audmath, audmetric, matplotlib, pandas, seaborn) has no large pre-built binary wheels like torch, so pruning would save ~0 disk space while costing avoidable re-downloads. Part of the same CI cleanup as audeering/audeer#206, audeering/opensmile-python#132, audeering/audb#591, audeering/audformat#539, audeering/audbackend#307, audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115, audeering/audinterface#206, audeering/audiofile#193, audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63, and audeering/audobject#127. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Give each workflow its own uv cache to stop reservation races Documentation, Linter, Test, and Publish jobs sometimes land on an identical setup-uv cache key (same OS + Python version + dependency-file hash), so whichever job finishes first saves the cache and the others get "Failed to save: Unable to reserve cache with key ..., another job may be creating this cache." Harmless -- the losing job's save would have been byte-identical anyway -- but requested clean, warning-free CI across the board. Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so each workflow gets its own cache entry instead of racing to share one. Trade-off: workflows no longer share a warm cache with each other, so each pays its own first-run cost independently instead of one job seeding it for the rest. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: cgeng <cgeng@audeering.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
The Test matrix declares ubuntu-latest with Python 3.10 twice -- once plain, once with requirements: 'minimum'. Same OS and same Python version means the same setup-uv cache key, so those two legs race with each other inside Test, where the previous commit cannot reach them. Measured twice on this repo, both times on a run whose keys were fresh: main 2e77f55, run 30999457855 build (ubuntu-latest, 3.10) saved 3.10.20 build (ubuntu-latest, 3.10, minimum) Failed to save: Unable to reserve cache with key setup-uv-2-...-3.10.20-... PR #539 a577fa2, run 30996727386 same pair, same key, same warning -- the loser was again the minimum leg Order is not fixed: on the 2026-05-12 push to main the minimum leg won and the plain leg lost. The plain leg is the natural saver, since the minimum leg downgrades several dependencies after uv sync, so let the variant stop saving. GitHub renders the expression as true or false, which the boolean input accepts. Note that the run on this branch could not reproduce the warning: every key was already present in the main scope, so setup-uv reported "Cache hit occurred on key ..., not saving cache." and no job attempted a save. The race only surfaces on the first run after a key rotation, which is exactly what the two runs cited above were. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* Let only Test save the shared uv cache
astral-sh/setup-uv derives its cache key from arch, runner, Python
version and the dependency hash, so every job running the same OS with
the same Python version lands on the same key. When one push starts
several such jobs, they all try to reserve that key at save time; the
first to finish wins and the rest log
Failed to save: Unable to reserve cache with key setup-uv-2-...,
another job may be creating this cache.
The failure is save-time only and harmless: the losing job would have
written identical content, and every job still restores the cache
normally. It is log noise.
Giving each workflow its own cache via cache-suffix would silence it
too, but that stores the same bytes several times over and was
rejected in audeering/audeer#207 in favour of a single saver.
Documentation, Linter and Publish therefore stop saving; Test keeps
the default and is the sole writer of the shared key.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* Let one ubuntu-3.10 Test leg save the cache
The Test matrix declares ubuntu-latest with Python 3.10 twice -- once
plain, once with requirements: 'minimum'. Same OS and same Python
version means the same setup-uv cache key, so those two legs race with
each other inside Test, where the previous commit cannot reach them.
Measured twice on this repo, both times on a run whose keys were fresh:
main 2e77f55, run 30999457855
build (ubuntu-latest, 3.10) saved 3.10.20
build (ubuntu-latest, 3.10, minimum) Failed to save: Unable to
reserve cache with key
setup-uv-2-...-3.10.20-...
PR #539 a577fa2, run 30996727386
same pair, same key, same warning -- the loser was again the
minimum leg
Order is not fixed: on the 2026-05-12 push to main the minimum leg won
and the plain leg lost.
The plain leg is the natural saver, since the minimum leg downgrades
several dependencies after uv sync, so let the variant stop saving.
GitHub renders the expression as true or false, which the boolean
input accepts.
Note that the run on this branch could not reproduce the warning: every
key was already present in the main scope, so setup-uv reported "Cache
hit occurred on key ..., not saving cache." and no job attempted a
save. The race only surfaces on the first run after a key rotation,
which is exactly what the two runs cited above were.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
actions/checkout,actions/setup-python,actions/cache, andcodecov/codecov-actionwere all still pinned to majors that run on the deprecated Node.js 20 runtime. Bumped tov7(v6foractions/cache), clearing the warning entirely.codecov-action'sv5rewrite dropped thefileinput this workflow used; renamed tofiles, its replacement.astral-sh/setup-uvis deliberately left untouched here, unlike the equivalent fix in audeer/opensmile-python/audb: it's already SHA-pinned tov7.1.0(notv5like those repos), which already runs on Node.js 24, and whose defaultcache-dependency-globalready includespyproject.toml(added inv6.0.0) -- so neither the dead-caching bug nor the Node 20 warning applies tosetup-uvhere. Noprune-cachedecision needed for the same reason: its config isn't touched.Part of the same CI-action-version cleanup already applied in audeering/audeer#206, audeering/opensmile-python#132, and audeering/audb#591.