From 0f2be99b98438dd0c6ab2496da85a69c639bce2c Mon Sep 17 00:00:00 2001 From: Lars Date: Sun, 6 Sep 2026 09:00:45 +0200 Subject: [PATCH 1/2] Add pre-commit config and CONTRIBUTING.md - Add .pre-commit-config.yaml with ruff + basic hooks (trailing-whitespace, end-of-file-fixer) - Add CONTRIBUTING.md with development workflow documentation Closes #113 --- .pre-commit-config.yaml | 23 ++++++++++++ CONTRIBUTING.md | 77 +++++++++++++++++++++++++++++++++++++++++ 2 files changed, 100 insertions(+) create mode 100644 .pre-commit-config.yaml create mode 100644 CONTRIBUTING.md diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml new file mode 100644 index 0000000..6858e32 --- /dev/null +++ b/.pre-commit-config.yaml @@ -0,0 +1,23 @@ +# See https://pre-commit.com for more information +# See https://pre-commit.com/hooks.html for more hooks +repos: + - repo: https://github.com/astral-sh/ruff-pre-commit + # Ruff version. + rev: v0.6.0 + hooks: + # Run the linter. + - id: ruff + args: [--fix] + # Run the formatter. + - id: ruff-format + - repo: https://github.com/pre-commit/pre-commit-hooks + rev: v4.6.0 + hooks: + # Checks for trailing whitespace. + - id: trailing-whitespace + # Checks that files end with a newline. + - id: end-of-file-fixer + # Checks for files that would conflict with git's case-insensitive file system. + - id: check-case-conflict + # Checks for added large files. + - id: check-added-large-files diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..496c2e9 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,77 @@ +# Contributing to dynavec + +Welcome! We're glad you're interested in contributing to dynavec. + +## Getting Started + +1. **Fork the repository** on GitHub +2. **Clone your fork** locally +3. **Install dependencies**: + ```bash + pip install -e ".[dev]" + ``` +4. **Install pre-commit hooks**: + ```bash + pre-commit install + ``` + +## Development Workflow + +### Code Style + +We use [Ruff](https://github.com/astral-sh/ruff) for linting and formatting: + +```bash +# Run ruff linter +ruff check . + +# Run ruff formatter +ruff format . +``` + +### Pre-commit Hooks + +This project uses pre-commit hooks to ensure code quality: + +- `ruff` - Linting with automatic fixes +- `ruff-format` - Code formatting +- `trailing-whitespace` - Removes trailing whitespace +- `end-of-file-fixer` - Ensures files end with a newline +- `check-case-conflict` - Checks for case conflicts +- `check-added-large-files` - Prevents adding large files + +Install hooks with: +```bash +pre-commit install +``` + +Run hooks manually: +```bash +pre-commit run --all-files +``` + +### Running Tests + +```bash +# Run all tests +pytest + +# Run with coverage +pytest --cov=dynavec --cov-report=term-missing +``` + +### Submitting Changes + +1. Create a new branch for your changes +2. Make your changes and commit them +3. Ensure pre-commit hooks pass +4. Push to your fork and open a Pull Request +5. Reference the issue number in your PR description + +## Good First Issues + +Looking for a place to start? Check out issues labeled [good first issue](https://github.com/codeforstartups/dynavec/labels/good%20first%20issue). + +## Questions? + +Feel free to open an issue for any questions or discussions. From 262a0328905766c281009f4b8d2bb064d4542f72 Mon Sep 17 00:00:00 2001 From: Lars Date: Sun, 6 Sep 2026 09:02:13 +0200 Subject: [PATCH 2/2] Add Python 3.13 to CI matrix and add pip-audit security job - Add Python 3.13 to the test matrix - Add pip-audit job for dependency vulnerability scanning Closes #114, Closes #115 --- .github/workflows/ci.yml | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d10d15b..e56523b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,7 +11,7 @@ jobs: strategy: fail-fast: false matrix: - python-version: ["3.9", "3.11", "3.12"] + python-version: ["3.9", "3.11", "3.12", "3.13"] steps: - uses: actions/checkout@v4 - name: Install uv @@ -24,3 +24,19 @@ jobs: run: uv run --no-sync ruff check src benchmarks - name: Test run: uv run --no-sync pytest -q + + security: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + - name: Install uv + uses: astral-sh/setup-uv@v5 + with: + python-version: "3.12" + - name: Install deps + run: uv pip install -e ".[dev]" + - name: Run pip-audit + uses: pypa/gh-action-pip-audit@v1.1.0 + with: + requirements: pyproject.toml +