CI: update checkout, setup-python, setup-uv, codecov - #206

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#206
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock/requirements*.txt, neither of which exists here (no
    committed lockfile, by design), so caching never actually worked. Bumped
    astral-sh/setup-uvv5 -> v9.0.0: v6.0.0 added pyproject.toml to
    the default glob, which is committed and changes exactly when a
    dependency does, so caching now works with no lockfile needed.

  2. Node.js 20 deprecation: actions/checkout and actions/setup-python
    bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
    codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
    singular file: input in favor of files:, renamed accordingly.
    actions/cache (used for the emodb test-data cache in doc/test
    workflows) bumped v4 -> v6 for the same reason.

prune-cache left at its new default (off): audinterface's dependency tree
(audeer, audformat, audiofile, audmath, audresample) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk space
while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Test plan

  • All workflow YAML files reviewed and diff-verified against the
    established pattern from sibling repos
  • CI passes on this PR

Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
the default glob, which is committed and changes exactly when a
dependency does, so caching now works with no lockfile needed.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped to v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped to v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
actions/cache (where used, for test-data caching) bumped to v6 for
the same reason.
Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-aiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates GitHub Actions workflows to modern action versions, fixing uv dependency caching and removing Node.js 20 deprecation warnings, plus adjusting Codecov config for the newer action API.

Flow diagram for updated CI workflows using new GitHub Actions versions

flowchart TD
GH[GitHub Actions workflow] --> DOC[doc.yml job]
GH --> LINT[linter.yml job]
GH --> PUBLISH[publish.yml job]
subgraph DocJob
DOC --> CkDoc[actions_checkout_v7]
CkDoc --> CacheDoc[actions_cache_v6 emodb]
CacheDoc --> PyDoc[actions_setup_python_v7]
PyDoc --> UvDoc[astral_sh_setup_uv_v9_0_0]
end
subgraph LinterJob
LINT --> CkLint[actions_checkout_v7]
CkLint --> PyLint[actions_setup_python_v7]
PyLint --> UvLint[astral_sh_setup_uv_v9_0_0]
end
subgraph PublishJob
PUBLISH --> CkPub[actions_checkout_v7]
CkPub --> PyPub[actions_setup_python_v7]
PyPub --> UvPub[astral_sh_setup_uv_v9_0_0]
end
UvDoc --> UvCache[uv cache keyed by pyproject.toml]
Loading

File-Level Changes

ChangeDetailsFiles
Modernize CI workflows by bumping core GitHub Actions and fixing uv caching and Codecov configuration.
  • Bump actions/checkout from v4 to v7 across all workflows to move off the Node.js 20 runtime.
  • Bump actions/setup-python from v5 to v7 in all workflows to align with the latest runtime and feature set.
  • Bump actions/cache from v4 to v6 in test and doc workflows for the emodb cache to match the supported runtime.
  • Bump astral-sh/setup-uv from v5 to v9.0.0 in all workflows so the default cache-dependency-glob includes pyproject.toml and uv caching becomes effective without a lockfile.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow and update the input from file: to files: ./coverage.xml to satisfy the new action interface.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider pinning astral-sh/setup-uv to the major version (e.g., @v9) rather than a specific patch (@v9.0.0) to automatically pick up compatible patch updates without needing manual bumps.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments- Consider pinning `astral-sh/setup-uv` to the major version (e.g., `@v9`) rather than a specific patch (`@v9.0.0`) to automatically pick up compatible patch updates without needing manual bumps.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@ChristianGeng

Copy link
Copy Markdown
MemberAuthor

Re: the version-pin suggestion — pinning astral-sh/setup-uv to the exact v9.0.0 tag rather than floating v9 is intentional here, not an oversight. This bump exists specifically to land the caching fix that landed in v6.0.0 (adding pyproject.toml to the default cache-dependency-glob), so pinning the exact version we verified against avoids silently picking up a future patch release we haven't tested. Same choice made across the sibling repos in this rollout (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60) — checkout/setup-python/codecov-action float on major tags by convention, setup-uv is pinned exact because this PR's whole point is a specific version's behavior change. Leaving as-is.

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng merged commit 66ba12f into mainAug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:08
ChristianGeng added a commit to audeering/audmath that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from the floating tag v5
-> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is
committed and changes exactly when a dependency does -- so caching
now works with no lockfile needed. v7.0.0 also carries the Node 20 ->
Node 24 runtime bump.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmath's only runtime
dependency is numpy, with no large pre-built binary wheels like torch,
so pruning would save ~0 disk space while costing avoidable
re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmetric that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup, matching what was done for audformat's and audbackend's
setup-uv pins after the fact (same SHA-pin situation).
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmetric's runtime
dependencies (audeer, numpy) have no large pre-built binary wheels
like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audobject that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
This repo's setup-uv pin was already a SHA
(3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
v7.1.0 — past the fix that matters here (v6.0.0 added
pyproject.toml to the default glob) and past the Node 20 -> Node 24
runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
with the other repos in this cleanup.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ChristianGeng@hagenw
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

CI: update checkout, setup-python, setup-uv, codecov - #206

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#206
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock/requirements*.txt, neither of which exists here (no
    committed lockfile, by design), so caching never actually worked. Bumped
    astral-sh/setup-uvv5 -> v9.0.0: v6.0.0 added pyproject.toml to
    the default glob, which is committed and changes exactly when a
    dependency does, so caching now works with no lockfile needed.

  2. Node.js 20 deprecation: actions/checkout and actions/setup-python
    bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
    codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
    singular file: input in favor of files:, renamed accordingly.
    actions/cache (used for the emodb test-data cache in doc/test
    workflows) bumped v4 -> v6 for the same reason.

prune-cache left at its new default (off): audinterface's dependency tree
(audeer, audformat, audiofile, audmath, audresample) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk space
while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Test plan

  • All workflow YAML files reviewed and diff-verified against the
    established pattern from sibling repos
  • CI passes on this PR

Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
the default glob, which is committed and changes exactly when a
dependency does, so caching now works with no lockfile needed.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped to v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped to v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
actions/cache (where used, for test-data caching) bumped to v6 for
the same reason.
Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-aiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates GitHub Actions workflows to modern action versions, fixing uv dependency caching and removing Node.js 20 deprecation warnings, plus adjusting Codecov config for the newer action API.

Flow diagram for updated CI workflows using new GitHub Actions versions

flowchart TD
GH[GitHub Actions workflow] --> DOC[doc.yml job]
GH --> LINT[linter.yml job]
GH --> PUBLISH[publish.yml job]
subgraph DocJob
DOC --> CkDoc[actions_checkout_v7]
CkDoc --> CacheDoc[actions_cache_v6 emodb]
CacheDoc --> PyDoc[actions_setup_python_v7]
PyDoc --> UvDoc[astral_sh_setup_uv_v9_0_0]
end
subgraph LinterJob
LINT --> CkLint[actions_checkout_v7]
CkLint --> PyLint[actions_setup_python_v7]
PyLint --> UvLint[astral_sh_setup_uv_v9_0_0]
end
subgraph PublishJob
PUBLISH --> CkPub[actions_checkout_v7]
CkPub --> PyPub[actions_setup_python_v7]
PyPub --> UvPub[astral_sh_setup_uv_v9_0_0]
end
UvDoc --> UvCache[uv cache keyed by pyproject.toml]
Loading

File-Level Changes

ChangeDetailsFiles
Modernize CI workflows by bumping core GitHub Actions and fixing uv caching and Codecov configuration.
  • Bump actions/checkout from v4 to v7 across all workflows to move off the Node.js 20 runtime.
  • Bump actions/setup-python from v5 to v7 in all workflows to align with the latest runtime and feature set.
  • Bump actions/cache from v4 to v6 in test and doc workflows for the emodb cache to match the supported runtime.
  • Bump astral-sh/setup-uv from v5 to v9.0.0 in all workflows so the default cache-dependency-glob includes pyproject.toml and uv caching becomes effective without a lockfile.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow and update the input from file: to files: ./coverage.xml to satisfy the new action interface.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider pinning astral-sh/setup-uv to the major version (e.g., @v9) rather than a specific patch (@v9.0.0) to automatically pick up compatible patch updates without needing manual bumps.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments- Consider pinning `astral-sh/setup-uv` to the major version (e.g., `@v9`) rather than a specific patch (`@v9.0.0`) to automatically pick up compatible patch updates without needing manual bumps.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@ChristianGeng

Copy link
Copy Markdown
MemberAuthor

Re: the version-pin suggestion — pinning astral-sh/setup-uv to the exact v9.0.0 tag rather than floating v9 is intentional here, not an oversight. This bump exists specifically to land the caching fix that landed in v6.0.0 (adding pyproject.toml to the default cache-dependency-glob), so pinning the exact version we verified against avoids silently picking up a future patch release we haven't tested. Same choice made across the sibling repos in this rollout (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60) — checkout/setup-python/codecov-action float on major tags by convention, setup-uv is pinned exact because this PR's whole point is a specific version's behavior change. Leaving as-is.

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng merged commit 66ba12f into mainAug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:08
ChristianGeng added a commit to audeering/audmath that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from the floating tag v5
-> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is
committed and changes exactly when a dependency does -- so caching
now works with no lockfile needed. v7.0.0 also carries the Node 20 ->
Node 24 runtime bump.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmath's only runtime
dependency is numpy, with no large pre-built binary wheels like torch,
so pruning would save ~0 disk space while costing avoidable
re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmetric that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup, matching what was done for audformat's and audbackend's
setup-uv pins after the fact (same SHA-pin situation).
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmetric's runtime
dependencies (audeer, numpy) have no large pre-built binary wheels
like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audobject that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
This repo's setup-uv pin was already a SHA
(3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
v7.1.0 — past the fix that matters here (v6.0.0 added
pyproject.toml to the default glob) and past the Node 20 -> Node 24
runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
with the other repos in this cleanup.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ChristianGeng@hagenw
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

CI: update checkout, setup-python, setup-uv, codecov - #206

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#206
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock/requirements*.txt, neither of which exists here (no
    committed lockfile, by design), so caching never actually worked. Bumped
    astral-sh/setup-uvv5 -> v9.0.0: v6.0.0 added pyproject.toml to
    the default glob, which is committed and changes exactly when a
    dependency does, so caching now works with no lockfile needed.

  2. Node.js 20 deprecation: actions/checkout and actions/setup-python
    bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
    codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
    singular file: input in favor of files:, renamed accordingly.
    actions/cache (used for the emodb test-data cache in doc/test
    workflows) bumped v4 -> v6 for the same reason.

prune-cache left at its new default (off): audinterface's dependency tree
(audeer, audformat, audiofile, audmath, audresample) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk space
while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Test plan

  • All workflow YAML files reviewed and diff-verified against the
    established pattern from sibling repos
  • CI passes on this PR

Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
the default glob, which is committed and changes exactly when a
dependency does, so caching now works with no lockfile needed.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped to v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped to v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
actions/cache (where used, for test-data caching) bumped to v6 for
the same reason.
Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-aiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates GitHub Actions workflows to modern action versions, fixing uv dependency caching and removing Node.js 20 deprecation warnings, plus adjusting Codecov config for the newer action API.

Flow diagram for updated CI workflows using new GitHub Actions versions

flowchart TD
GH[GitHub Actions workflow] --> DOC[doc.yml job]
GH --> LINT[linter.yml job]
GH --> PUBLISH[publish.yml job]
subgraph DocJob
DOC --> CkDoc[actions_checkout_v7]
CkDoc --> CacheDoc[actions_cache_v6 emodb]
CacheDoc --> PyDoc[actions_setup_python_v7]
PyDoc --> UvDoc[astral_sh_setup_uv_v9_0_0]
end
subgraph LinterJob
LINT --> CkLint[actions_checkout_v7]
CkLint --> PyLint[actions_setup_python_v7]
PyLint --> UvLint[astral_sh_setup_uv_v9_0_0]
end
subgraph PublishJob
PUBLISH --> CkPub[actions_checkout_v7]
CkPub --> PyPub[actions_setup_python_v7]
PyPub --> UvPub[astral_sh_setup_uv_v9_0_0]
end
UvDoc --> UvCache[uv cache keyed by pyproject.toml]
Loading

File-Level Changes

ChangeDetailsFiles
Modernize CI workflows by bumping core GitHub Actions and fixing uv caching and Codecov configuration.
  • Bump actions/checkout from v4 to v7 across all workflows to move off the Node.js 20 runtime.
  • Bump actions/setup-python from v5 to v7 in all workflows to align with the latest runtime and feature set.
  • Bump actions/cache from v4 to v6 in test and doc workflows for the emodb cache to match the supported runtime.
  • Bump astral-sh/setup-uv from v5 to v9.0.0 in all workflows so the default cache-dependency-glob includes pyproject.toml and uv caching becomes effective without a lockfile.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow and update the input from file: to files: ./coverage.xml to satisfy the new action interface.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider pinning astral-sh/setup-uv to the major version (e.g., @v9) rather than a specific patch (@v9.0.0) to automatically pick up compatible patch updates without needing manual bumps.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments- Consider pinning `astral-sh/setup-uv` to the major version (e.g., `@v9`) rather than a specific patch (`@v9.0.0`) to automatically pick up compatible patch updates without needing manual bumps.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@ChristianGeng

Copy link
Copy Markdown
MemberAuthor

Re: the version-pin suggestion — pinning astral-sh/setup-uv to the exact v9.0.0 tag rather than floating v9 is intentional here, not an oversight. This bump exists specifically to land the caching fix that landed in v6.0.0 (adding pyproject.toml to the default cache-dependency-glob), so pinning the exact version we verified against avoids silently picking up a future patch release we haven't tested. Same choice made across the sibling repos in this rollout (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60) — checkout/setup-python/codecov-action float on major tags by convention, setup-uv is pinned exact because this PR's whole point is a specific version's behavior change. Leaving as-is.

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng merged commit 66ba12f into mainAug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:08
ChristianGeng added a commit to audeering/audmath that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from the floating tag v5
-> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is
committed and changes exactly when a dependency does -- so caching
now works with no lockfile needed. v7.0.0 also carries the Node 20 ->
Node 24 runtime bump.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmath's only runtime
dependency is numpy, with no large pre-built binary wheels like torch,
so pruning would save ~0 disk space while costing avoidable
re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmetric that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup, matching what was done for audformat's and audbackend's
setup-uv pins after the fact (same SHA-pin situation).
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmetric's runtime
dependencies (audeer, numpy) have no large pre-built binary wheels
like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audobject that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
This repo's setup-uv pin was already a SHA
(3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
v7.1.0 — past the fix that matters here (v6.0.0 added
pyproject.toml to the default glob) and past the Node 20 -> Node 24
runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
with the other repos in this cleanup.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ChristianGeng@hagenw
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

CI: update checkout, setup-python, setup-uv, codecov - #206

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#206
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock/requirements*.txt, neither of which exists here (no
    committed lockfile, by design), so caching never actually worked. Bumped
    astral-sh/setup-uvv5 -> v9.0.0: v6.0.0 added pyproject.toml to
    the default glob, which is committed and changes exactly when a
    dependency does, so caching now works with no lockfile needed.

  2. Node.js 20 deprecation: actions/checkout and actions/setup-python
    bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
    codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
    singular file: input in favor of files:, renamed accordingly.
    actions/cache (used for the emodb test-data cache in doc/test
    workflows) bumped v4 -> v6 for the same reason.

prune-cache left at its new default (off): audinterface's dependency tree
(audeer, audformat, audiofile, audmath, audresample) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk space
while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Test plan

  • All workflow YAML files reviewed and diff-verified against the
    established pattern from sibling repos
  • CI passes on this PR

Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
the default glob, which is committed and changes exactly when a
dependency does, so caching now works with no lockfile needed.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped to v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped to v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
actions/cache (where used, for test-data caching) bumped to v6 for
the same reason.
Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-aiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates GitHub Actions workflows to modern action versions, fixing uv dependency caching and removing Node.js 20 deprecation warnings, plus adjusting Codecov config for the newer action API.

Flow diagram for updated CI workflows using new GitHub Actions versions

flowchart TD
GH[GitHub Actions workflow] --> DOC[doc.yml job]
GH --> LINT[linter.yml job]
GH --> PUBLISH[publish.yml job]
subgraph DocJob
DOC --> CkDoc[actions_checkout_v7]
CkDoc --> CacheDoc[actions_cache_v6 emodb]
CacheDoc --> PyDoc[actions_setup_python_v7]
PyDoc --> UvDoc[astral_sh_setup_uv_v9_0_0]
end
subgraph LinterJob
LINT --> CkLint[actions_checkout_v7]
CkLint --> PyLint[actions_setup_python_v7]
PyLint --> UvLint[astral_sh_setup_uv_v9_0_0]
end
subgraph PublishJob
PUBLISH --> CkPub[actions_checkout_v7]
CkPub --> PyPub[actions_setup_python_v7]
PyPub --> UvPub[astral_sh_setup_uv_v9_0_0]
end
UvDoc --> UvCache[uv cache keyed by pyproject.toml]
Loading

File-Level Changes

ChangeDetailsFiles
Modernize CI workflows by bumping core GitHub Actions and fixing uv caching and Codecov configuration.
  • Bump actions/checkout from v4 to v7 across all workflows to move off the Node.js 20 runtime.
  • Bump actions/setup-python from v5 to v7 in all workflows to align with the latest runtime and feature set.
  • Bump actions/cache from v4 to v6 in test and doc workflows for the emodb cache to match the supported runtime.
  • Bump astral-sh/setup-uv from v5 to v9.0.0 in all workflows so the default cache-dependency-glob includes pyproject.toml and uv caching becomes effective without a lockfile.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow and update the input from file: to files: ./coverage.xml to satisfy the new action interface.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider pinning astral-sh/setup-uv to the major version (e.g., @v9) rather than a specific patch (@v9.0.0) to automatically pick up compatible patch updates without needing manual bumps.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments- Consider pinning `astral-sh/setup-uv` to the major version (e.g., `@v9`) rather than a specific patch (`@v9.0.0`) to automatically pick up compatible patch updates without needing manual bumps.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@ChristianGeng

Copy link
Copy Markdown
MemberAuthor

Re: the version-pin suggestion — pinning astral-sh/setup-uv to the exact v9.0.0 tag rather than floating v9 is intentional here, not an oversight. This bump exists specifically to land the caching fix that landed in v6.0.0 (adding pyproject.toml to the default cache-dependency-glob), so pinning the exact version we verified against avoids silently picking up a future patch release we haven't tested. Same choice made across the sibling repos in this rollout (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60) — checkout/setup-python/codecov-action float on major tags by convention, setup-uv is pinned exact because this PR's whole point is a specific version's behavior change. Leaving as-is.

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng merged commit 66ba12f into mainAug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:08
ChristianGeng added a commit to audeering/audmath that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from the floating tag v5
-> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is
committed and changes exactly when a dependency does -- so caching
now works with no lockfile needed. v7.0.0 also carries the Node 20 ->
Node 24 runtime bump.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmath's only runtime
dependency is numpy, with no large pre-built binary wheels like torch,
so pruning would save ~0 disk space while costing avoidable
re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmetric that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup, matching what was done for audformat's and audbackend's
setup-uv pins after the fact (same SHA-pin situation).
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmetric's runtime
dependencies (audeer, numpy) have no large pre-built binary wheels
like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audobject that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
This repo's setup-uv pin was already a SHA
(3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
v7.1.0 — past the fix that matters here (v6.0.0 added
pyproject.toml to the default glob) and past the Node 20 -> Node 24
runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
with the other repos in this cleanup.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ChristianGeng@hagenw
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

CI: update checkout, setup-python, setup-uv, codecov - #206

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#206
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock/requirements*.txt, neither of which exists here (no
    committed lockfile, by design), so caching never actually worked. Bumped
    astral-sh/setup-uvv5 -> v9.0.0: v6.0.0 added pyproject.toml to
    the default glob, which is committed and changes exactly when a
    dependency does, so caching now works with no lockfile needed.

  2. Node.js 20 deprecation: actions/checkout and actions/setup-python
    bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
    codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
    singular file: input in favor of files:, renamed accordingly.
    actions/cache (used for the emodb test-data cache in doc/test
    workflows) bumped v4 -> v6 for the same reason.

prune-cache left at its new default (off): audinterface's dependency tree
(audeer, audformat, audiofile, audmath, audresample) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk space
while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Test plan

  • All workflow YAML files reviewed and diff-verified against the
    established pattern from sibling repos
  • CI passes on this PR

Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
the default glob, which is committed and changes exactly when a
dependency does, so caching now works with no lockfile needed.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped to v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped to v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
actions/cache (where used, for test-data caching) bumped to v6 for
the same reason.
Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-aiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates GitHub Actions workflows to modern action versions, fixing uv dependency caching and removing Node.js 20 deprecation warnings, plus adjusting Codecov config for the newer action API.

Flow diagram for updated CI workflows using new GitHub Actions versions

flowchart TD
GH[GitHub Actions workflow] --> DOC[doc.yml job]
GH --> LINT[linter.yml job]
GH --> PUBLISH[publish.yml job]
subgraph DocJob
DOC --> CkDoc[actions_checkout_v7]
CkDoc --> CacheDoc[actions_cache_v6 emodb]
CacheDoc --> PyDoc[actions_setup_python_v7]
PyDoc --> UvDoc[astral_sh_setup_uv_v9_0_0]
end
subgraph LinterJob
LINT --> CkLint[actions_checkout_v7]
CkLint --> PyLint[actions_setup_python_v7]
PyLint --> UvLint[astral_sh_setup_uv_v9_0_0]
end
subgraph PublishJob
PUBLISH --> CkPub[actions_checkout_v7]
CkPub --> PyPub[actions_setup_python_v7]
PyPub --> UvPub[astral_sh_setup_uv_v9_0_0]
end
UvDoc --> UvCache[uv cache keyed by pyproject.toml]
Loading

File-Level Changes

ChangeDetailsFiles
Modernize CI workflows by bumping core GitHub Actions and fixing uv caching and Codecov configuration.
  • Bump actions/checkout from v4 to v7 across all workflows to move off the Node.js 20 runtime.
  • Bump actions/setup-python from v5 to v7 in all workflows to align with the latest runtime and feature set.
  • Bump actions/cache from v4 to v6 in test and doc workflows for the emodb cache to match the supported runtime.
  • Bump astral-sh/setup-uv from v5 to v9.0.0 in all workflows so the default cache-dependency-glob includes pyproject.toml and uv caching becomes effective without a lockfile.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow and update the input from file: to files: ./coverage.xml to satisfy the new action interface.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider pinning astral-sh/setup-uv to the major version (e.g., @v9) rather than a specific patch (@v9.0.0) to automatically pick up compatible patch updates without needing manual bumps.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments- Consider pinning `astral-sh/setup-uv` to the major version (e.g., `@v9`) rather than a specific patch (`@v9.0.0`) to automatically pick up compatible patch updates without needing manual bumps.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@ChristianGeng

Copy link
Copy Markdown
MemberAuthor

Re: the version-pin suggestion — pinning astral-sh/setup-uv to the exact v9.0.0 tag rather than floating v9 is intentional here, not an oversight. This bump exists specifically to land the caching fix that landed in v6.0.0 (adding pyproject.toml to the default cache-dependency-glob), so pinning the exact version we verified against avoids silently picking up a future patch release we haven't tested. Same choice made across the sibling repos in this rollout (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60) — checkout/setup-python/codecov-action float on major tags by convention, setup-uv is pinned exact because this PR's whole point is a specific version's behavior change. Leaving as-is.

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng merged commit 66ba12f into mainAug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:08
ChristianGeng added a commit to audeering/audmath that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from the floating tag v5
-> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is
committed and changes exactly when a dependency does -- so caching
now works with no lockfile needed. v7.0.0 also carries the Node 20 ->
Node 24 runtime bump.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmath's only runtime
dependency is numpy, with no large pre-built binary wheels like torch,
so pruning would save ~0 disk space while costing avoidable
re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmetric that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup, matching what was done for audformat's and audbackend's
setup-uv pins after the fact (same SHA-pin situation).
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmetric's runtime
dependencies (audeer, numpy) have no large pre-built binary wheels
like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audobject that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
This repo's setup-uv pin was already a SHA
(3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
v7.1.0 — past the fix that matters here (v6.0.0 added
pyproject.toml to the default glob) and past the Node 20 -> Node 24
runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
with the other repos in this cleanup.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ChristianGeng@hagenw
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

CI: update checkout, setup-python, setup-uv, codecov - #206

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#206
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock/requirements*.txt, neither of which exists here (no
    committed lockfile, by design), so caching never actually worked. Bumped
    astral-sh/setup-uvv5 -> v9.0.0: v6.0.0 added pyproject.toml to
    the default glob, which is committed and changes exactly when a
    dependency does, so caching now works with no lockfile needed.

  2. Node.js 20 deprecation: actions/checkout and actions/setup-python
    bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
    codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
    singular file: input in favor of files:, renamed accordingly.
    actions/cache (used for the emodb test-data cache in doc/test
    workflows) bumped v4 -> v6 for the same reason.

prune-cache left at its new default (off): audinterface's dependency tree
(audeer, audformat, audiofile, audmath, audresample) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk space
while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Test plan

  • All workflow YAML files reviewed and diff-verified against the
    established pattern from sibling repos
  • CI passes on this PR

Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
the default glob, which is committed and changes exactly when a
dependency does, so caching now works with no lockfile needed.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped to v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped to v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
actions/cache (where used, for test-data caching) bumped to v6 for
the same reason.
Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-aiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates GitHub Actions workflows to modern action versions, fixing uv dependency caching and removing Node.js 20 deprecation warnings, plus adjusting Codecov config for the newer action API.

Flow diagram for updated CI workflows using new GitHub Actions versions

flowchart TD
GH[GitHub Actions workflow] --> DOC[doc.yml job]
GH --> LINT[linter.yml job]
GH --> PUBLISH[publish.yml job]
subgraph DocJob
DOC --> CkDoc[actions_checkout_v7]
CkDoc --> CacheDoc[actions_cache_v6 emodb]
CacheDoc --> PyDoc[actions_setup_python_v7]
PyDoc --> UvDoc[astral_sh_setup_uv_v9_0_0]
end
subgraph LinterJob
LINT --> CkLint[actions_checkout_v7]
CkLint --> PyLint[actions_setup_python_v7]
PyLint --> UvLint[astral_sh_setup_uv_v9_0_0]
end
subgraph PublishJob
PUBLISH --> CkPub[actions_checkout_v7]
CkPub --> PyPub[actions_setup_python_v7]
PyPub --> UvPub[astral_sh_setup_uv_v9_0_0]
end
UvDoc --> UvCache[uv cache keyed by pyproject.toml]
Loading

File-Level Changes

ChangeDetailsFiles
Modernize CI workflows by bumping core GitHub Actions and fixing uv caching and Codecov configuration.
  • Bump actions/checkout from v4 to v7 across all workflows to move off the Node.js 20 runtime.
  • Bump actions/setup-python from v5 to v7 in all workflows to align with the latest runtime and feature set.
  • Bump actions/cache from v4 to v6 in test and doc workflows for the emodb cache to match the supported runtime.
  • Bump astral-sh/setup-uv from v5 to v9.0.0 in all workflows so the default cache-dependency-glob includes pyproject.toml and uv caching becomes effective without a lockfile.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow and update the input from file: to files: ./coverage.xml to satisfy the new action interface.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider pinning astral-sh/setup-uv to the major version (e.g., @v9) rather than a specific patch (@v9.0.0) to automatically pick up compatible patch updates without needing manual bumps.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments- Consider pinning `astral-sh/setup-uv` to the major version (e.g., `@v9`) rather than a specific patch (`@v9.0.0`) to automatically pick up compatible patch updates without needing manual bumps.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@ChristianGeng

Copy link
Copy Markdown
MemberAuthor

Re: the version-pin suggestion — pinning astral-sh/setup-uv to the exact v9.0.0 tag rather than floating v9 is intentional here, not an oversight. This bump exists specifically to land the caching fix that landed in v6.0.0 (adding pyproject.toml to the default cache-dependency-glob), so pinning the exact version we verified against avoids silently picking up a future patch release we haven't tested. Same choice made across the sibling repos in this rollout (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60) — checkout/setup-python/codecov-action float on major tags by convention, setup-uv is pinned exact because this PR's whole point is a specific version's behavior change. Leaving as-is.

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng merged commit 66ba12f into mainAug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:08
ChristianGeng added a commit to audeering/audmath that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from the floating tag v5
-> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is
committed and changes exactly when a dependency does -- so caching
now works with no lockfile needed. v7.0.0 also carries the Node 20 ->
Node 24 runtime bump.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmath's only runtime
dependency is numpy, with no large pre-built binary wheels like torch,
so pruning would save ~0 disk space while costing avoidable
re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmetric that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup, matching what was done for audformat's and audbackend's
setup-uv pins after the fact (same SHA-pin situation).
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmetric's runtime
dependencies (audeer, numpy) have no large pre-built binary wheels
like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audobject that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
This repo's setup-uv pin was already a SHA
(3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
v7.1.0 — past the fix that matters here (v6.0.0 added
pyproject.toml to the default glob) and past the Node 20 -> Node 24
runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
with the other repos in this cleanup.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ChristianGeng@hagenw
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

CI: update checkout, setup-python, setup-uv, codecov - #206

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#206
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock/requirements*.txt, neither of which exists here (no
    committed lockfile, by design), so caching never actually worked. Bumped
    astral-sh/setup-uvv5 -> v9.0.0: v6.0.0 added pyproject.toml to
    the default glob, which is committed and changes exactly when a
    dependency does, so caching now works with no lockfile needed.

  2. Node.js 20 deprecation: actions/checkout and actions/setup-python
    bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
    codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
    singular file: input in favor of files:, renamed accordingly.
    actions/cache (used for the emodb test-data cache in doc/test
    workflows) bumped v4 -> v6 for the same reason.

prune-cache left at its new default (off): audinterface's dependency tree
(audeer, audformat, audiofile, audmath, audresample) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk space
while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Test plan

  • All workflow YAML files reviewed and diff-verified against the
    established pattern from sibling repos
  • CI passes on this PR

Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
the default glob, which is committed and changes exactly when a
dependency does, so caching now works with no lockfile needed.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped to v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped to v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
actions/cache (where used, for test-data caching) bumped to v6 for
the same reason.
Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-aiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates GitHub Actions workflows to modern action versions, fixing uv dependency caching and removing Node.js 20 deprecation warnings, plus adjusting Codecov config for the newer action API.

Flow diagram for updated CI workflows using new GitHub Actions versions

flowchart TD
GH[GitHub Actions workflow] --> DOC[doc.yml job]
GH --> LINT[linter.yml job]
GH --> PUBLISH[publish.yml job]
subgraph DocJob
DOC --> CkDoc[actions_checkout_v7]
CkDoc --> CacheDoc[actions_cache_v6 emodb]
CacheDoc --> PyDoc[actions_setup_python_v7]
PyDoc --> UvDoc[astral_sh_setup_uv_v9_0_0]
end
subgraph LinterJob
LINT --> CkLint[actions_checkout_v7]
CkLint --> PyLint[actions_setup_python_v7]
PyLint --> UvLint[astral_sh_setup_uv_v9_0_0]
end
subgraph PublishJob
PUBLISH --> CkPub[actions_checkout_v7]
CkPub --> PyPub[actions_setup_python_v7]
PyPub --> UvPub[astral_sh_setup_uv_v9_0_0]
end
UvDoc --> UvCache[uv cache keyed by pyproject.toml]
Loading

File-Level Changes

ChangeDetailsFiles
Modernize CI workflows by bumping core GitHub Actions and fixing uv caching and Codecov configuration.
  • Bump actions/checkout from v4 to v7 across all workflows to move off the Node.js 20 runtime.
  • Bump actions/setup-python from v5 to v7 in all workflows to align with the latest runtime and feature set.
  • Bump actions/cache from v4 to v6 in test and doc workflows for the emodb cache to match the supported runtime.
  • Bump astral-sh/setup-uv from v5 to v9.0.0 in all workflows so the default cache-dependency-glob includes pyproject.toml and uv caching becomes effective without a lockfile.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow and update the input from file: to files: ./coverage.xml to satisfy the new action interface.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider pinning astral-sh/setup-uv to the major version (e.g., @v9) rather than a specific patch (@v9.0.0) to automatically pick up compatible patch updates without needing manual bumps.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments- Consider pinning `astral-sh/setup-uv` to the major version (e.g., `@v9`) rather than a specific patch (`@v9.0.0`) to automatically pick up compatible patch updates without needing manual bumps.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@ChristianGeng

Copy link
Copy Markdown
MemberAuthor

Re: the version-pin suggestion — pinning astral-sh/setup-uv to the exact v9.0.0 tag rather than floating v9 is intentional here, not an oversight. This bump exists specifically to land the caching fix that landed in v6.0.0 (adding pyproject.toml to the default cache-dependency-glob), so pinning the exact version we verified against avoids silently picking up a future patch release we haven't tested. Same choice made across the sibling repos in this rollout (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60) — checkout/setup-python/codecov-action float on major tags by convention, setup-uv is pinned exact because this PR's whole point is a specific version's behavior change. Leaving as-is.

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng merged commit 66ba12f into mainAug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:08
ChristianGeng added a commit to audeering/audmath that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from the floating tag v5
-> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is
committed and changes exactly when a dependency does -- so caching
now works with no lockfile needed. v7.0.0 also carries the Node 20 ->
Node 24 runtime bump.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmath's only runtime
dependency is numpy, with no large pre-built binary wheels like torch,
so pruning would save ~0 disk space while costing avoidable
re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmetric that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup, matching what was done for audformat's and audbackend's
setup-uv pins after the fact (same SHA-pin situation).
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmetric's runtime
dependencies (audeer, numpy) have no large pre-built binary wheels
like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audobject that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
This repo's setup-uv pin was already a SHA
(3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
v7.1.0 — past the fix that matters here (v6.0.0 added
pyproject.toml to the default glob) and past the Node 20 -> Node 24
runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
with the other repos in this cleanup.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ChristianGeng@hagenw
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

CI: update checkout, setup-python, setup-uv, codecov - #206

Merged
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions
Aug 5, 2026
Merged

CI: update checkout, setup-python, setup-uv, codecov#206
ChristianGeng merged 2 commits into
mainfrom
fix/ci-action-versions

Conversation

@ChristianGeng

Copy link
Copy Markdown
Member

Summary

Two related CI bugs, both caused by stale GitHub Action version pins:

  1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
    keys on uv.lock/requirements*.txt, neither of which exists here (no
    committed lockfile, by design), so caching never actually worked. Bumped
    astral-sh/setup-uvv5 -> v9.0.0: v6.0.0 added pyproject.toml to
    the default glob, which is committed and changes exactly when a
    dependency does, so caching now works with no lockfile needed.

  2. Node.js 20 deprecation: actions/checkout and actions/setup-python
    bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
    codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
    singular file: input in favor of files:, renamed accordingly.
    actions/cache (used for the emodb test-data cache in doc/test
    workflows) bumped v4 -> v6 for the same reason.

prune-cache left at its new default (off): audinterface's dependency tree
(audeer, audformat, audiofile, audmath, audresample) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk space
while costing avoidable re-downloads.

Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.

Test plan

  • All workflow YAML files reviewed and diff-verified against the
    established pattern from sibling repos
  • CI passes on this PR

Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
Bumped astral-sh/setup-uv to v9.0.0: v6.0.0 added pyproject.toml to
the default glob, which is committed and changes exactly when a
dependency does, so caching now works with no lockfile needed.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped to v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped to v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
actions/cache (where used, for test-data caching) bumped to v6 for
the same reason.
Left `prune-cache` at its new default (off): no large pre-built binary
wheels like torch in this repo's dependency tree, so pruning would
save ~0 disk space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307, and
audeering/audresample#83.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sourcery-ai

sourcery-aiBot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates GitHub Actions workflows to modern action versions, fixing uv dependency caching and removing Node.js 20 deprecation warnings, plus adjusting Codecov config for the newer action API.

Flow diagram for updated CI workflows using new GitHub Actions versions

flowchart TD
GH[GitHub Actions workflow] --> DOC[doc.yml job]
GH --> LINT[linter.yml job]
GH --> PUBLISH[publish.yml job]
subgraph DocJob
DOC --> CkDoc[actions_checkout_v7]
CkDoc --> CacheDoc[actions_cache_v6 emodb]
CacheDoc --> PyDoc[actions_setup_python_v7]
PyDoc --> UvDoc[astral_sh_setup_uv_v9_0_0]
end
subgraph LinterJob
LINT --> CkLint[actions_checkout_v7]
CkLint --> PyLint[actions_setup_python_v7]
PyLint --> UvLint[astral_sh_setup_uv_v9_0_0]
end
subgraph PublishJob
PUBLISH --> CkPub[actions_checkout_v7]
CkPub --> PyPub[actions_setup_python_v7]
PyPub --> UvPub[astral_sh_setup_uv_v9_0_0]
end
UvDoc --> UvCache[uv cache keyed by pyproject.toml]
Loading

File-Level Changes

ChangeDetailsFiles
Modernize CI workflows by bumping core GitHub Actions and fixing uv caching and Codecov configuration.
  • Bump actions/checkout from v4 to v7 across all workflows to move off the Node.js 20 runtime.
  • Bump actions/setup-python from v5 to v7 in all workflows to align with the latest runtime and feature set.
  • Bump actions/cache from v4 to v6 in test and doc workflows for the emodb cache to match the supported runtime.
  • Bump astral-sh/setup-uv from v5 to v9.0.0 in all workflows so the default cache-dependency-glob includes pyproject.toml and uv caching becomes effective without a lockfile.
  • Bump codecov/codecov-action from v4 to v7 in the test workflow and update the input from file: to files: ./coverage.xml to satisfy the new action interface.
.github/workflows/test.yml
.github/workflows/doc.yml
.github/workflows/linter.yml
.github/workflows/publish.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-aisourcery-aiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • Consider pinning astral-sh/setup-uv to the major version (e.g., @v9) rather than a specific patch (@v9.0.0) to automatically pick up compatible patch updates without needing manual bumps.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments- Consider pinning `astral-sh/setup-uv` to the major version (e.g., `@v9`) rather than a specific patch (`@v9.0.0`) to automatically pick up compatible patch updates without needing manual bumps.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@ChristianGeng

Copy link
Copy Markdown
MemberAuthor

Re: the version-pin suggestion — pinning astral-sh/setup-uv to the exact v9.0.0 tag rather than floating v9 is intentional here, not an oversight. This bump exists specifically to land the caching fix that landed in v6.0.0 (adding pyproject.toml to the default cache-dependency-glob), so pinning the exact version we verified against avoids silently picking up a future patch release we haven't tested. Same choice made across the sibling repos in this rollout (audeer#206, opensmile-python#132, audb#591, audformat#539, audbackend#307, audresample#83, auglib#60) — checkout/setup-python/codecov-action float on major tags by convention, setup-uv is pinned exact because this PR's whole point is a specific version's behavior change. Leaving as-is.

Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@ChristianGeng
ChristianGeng merged commit 66ba12f into mainAug 5, 2026
20 checks passed
@ChristianGeng
ChristianGeng deleted the fix/ci-action-versions branch August 5, 2026 13:08
ChristianGeng added a commit to audeering/audmath that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from the floating tag v5
-> v9.0.0: v6.0.0 added pyproject.toml to the default glob, which is
committed and changes exactly when a dependency does -- so caching
now works with no lockfile needed. v7.0.0 also carries the Node 20 ->
Node 24 runtime bump.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmath's only runtime
dependency is numpy, with no large pre-built binary wheels like torch,
so pruning would save ~0 disk space while costing avoidable
re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audmetric that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv (pinned via SHA
3259c6206f99, which resolves to tag v7.1.0) -> v9.0.0: v6.0.0 added
pyproject.toml to the default glob, which is committed and changes
exactly when a dependency does -- so caching now works with no
lockfile needed. Note the existing pin already sat at v7.1.0, past
both the caching fix (v6.0.0) and the Node 20 -> Node 24 runtime bump
(v7.0.0), so neither bug technically applied to this action here --
bumping to v9.0.0 anyway for consistency across the sibling repos in
this cleanup, matching what was done for audformat's and audbackend's
setup-uv pins after the fact (same SHA-pin situation).
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audmetric's runtime
dependencies (audeer, numpy) have no large pre-built binary wheels
like torch, so pruning would save ~0 disk space while costing
avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, and audeering/audiofile#193.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audobject that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
setup-uv's cache keys on uv.lock/requirements*.txt, neither of which
exists here (no committed lockfile, by design), so caching never
actually worked. Bumped astral-sh/setup-uv from v5 to v9.0.0: v6.0.0
added pyproject.toml to the default glob, which is committed and
changes exactly when a dependency does -- so caching now works with
no lockfile needed. v7.0.0 also moved the action off the deprecated
Node.js 20 runtime.
Also bumped actions/checkout and actions/setup-python from v4/v5 to
v7, and codecov/codecov-action from v4 to v7, clearing the "Node.js 20
is deprecated" warning entirely. codecov-action's v5 rewrite dropped
the `file` input this workflow used; renamed to `files`, its
replacement, in test.yml so the coverage upload doesn't silently
no-op. No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audobject's runtime
dependencies (asttokens, audeer, oyaml, packaging) have no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Same cleanup as audeering/audeer#206, audeering/opensmile-python#132,
audeering/audb#591, audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193, and
audeering/audmath#76, audeering/audmetric#94.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
ChristianGeng added a commit to audeering/audplot that referenced this pull request Aug 5, 2026
* Fix CI caching; bump checkout/setup-python off Node.js 20
Two related CI bugs, both caused by stale GitHub Action version pins:
1. Dead uv caching: astral-sh/setup-uv's default cache-dependency-glob
keys on uv.lock/requirements*.txt, neither of which exists here (no
committed lockfile, by design), so caching never actually worked.
This repo's setup-uv pin was already a SHA
(3259c6206f993105e3a61b142c2d97bf4b9ef83d) that resolves to tag
v7.1.0 — past the fix that matters here (v6.0.0 added
pyproject.toml to the default glob) and past the Node 20 -> Node 24
runtime bump (v7.0.0). Bumping to v9.0.0 anyway, for consistency
with the other repos in this cleanup.
2. Node.js 20 deprecation: actions/checkout and actions/setup-python
bumped v4/v5 -> v7, clearing the "Node.js 20 is deprecated" warning.
codecov/codecov-action bumped v4 -> v7; its v5 rewrite dropped the
singular `file:` input in favor of `files:`, renamed accordingly.
No actions/cache usage exists in this repo's workflows.
Left `prune-cache` at its new default (off): audplot's dependency tree
(audmath, audmetric, matplotlib, pandas, seaborn) has no large
pre-built binary wheels like torch, so pruning would save ~0 disk
space while costing avoidable re-downloads.
Part of the same CI cleanup as audeering/audeer#206,
audeering/opensmile-python#132, audeering/audb#591,
audeering/audformat#539, audeering/audbackend#307,
audeering/audresample#83, audeering/auglib#60, audeering/audonnx#115,
audeering/audinterface#206, audeering/audiofile#193,
audeering/audmath#76, audeering/audmetric#94, audeering/audmodel#63,
and audeering/audobject#127.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Give each workflow its own uv cache to stop reservation races
Documentation, Linter, Test, and Publish jobs sometimes land on an
identical setup-uv cache key (same OS + Python version + dependency-file
hash), so whichever job finishes first saves the cache and the others
get "Failed to save: Unable to reserve cache with key ..., another job
may be creating this cache." Harmless -- the losing job's save would
have been byte-identical anyway -- but requested clean, warning-free CI
across the board.
Added `cache-suffix: ${{ github.workflow }}` to every setup-uv step, so
each workflow gets its own cache entry instead of racing to share one.
Trade-off: workflows no longer share a warm cache with each other, so
each pays its own first-run cost independently instead of one job
seeding it for the rest.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: cgeng <cgeng@audeering.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@ChristianGeng@hagenw