CheckCodeQuality

The CheckCodeQuality job template runs three independent code quality checks on the package sources:

  • security scanning with bandit,

  • code metrics and complexity with radon, and

  • linting with pylint.

Each check is a separate job with its own enable parameter, so a repository can adopt them one at a time. All three are disabled by default in CompletePipeline, because an established code base rarely passes linting on the first run.

Instantiation

The following instantiation example creates a CodeQuality job derived from job template CheckCodeQuality version @r8. The package directory comes from Parameters, so that job is a dependency.

jobs:
  Params:
    uses: pyTooling/Actions/.github/workflows/Parameters.yml@r8
    with:
      package_name: myPackage

  CodeQuality:
    uses: pyTooling/Actions/.github/workflows/CheckCodeQuality.yml@r8
    needs:
      - Params
    with:
      python_version:    ${{ needs.Params.outputs.python_version }}
      package_directory: ${{ needs.Params.outputs.package_directory }}
      artifact:          ${{ fromJson(needs.Params.outputs.artifact_names).codequality }}
      bandit:            'true'
      radon:             'true'
      pylint:            'false'

See also

CheckDocumentation

Checks documentation coverage rather than code quality.

StaticTypeCheck

Checks type annotations using mypy.

Parameter Summary

Goto input parameters

Parameter Name

Required

Type

Default

ubuntu_image_version

no

string

'26.04'

python_version

no

string

'3.14'

package_directory

yes

string

— — — —

artifact

yes

string

— — — —

requirements

no

string

'-r requirements.txt'

bandit

no

string

'true'

radon

no

string

'true'

pylint

no

string

'true'

Goto secrets

This job template needs no secrets.

Goto output parameters

This job template has no output parameters.

Input Parameters

ubuntu_image_version

Type:

string

Required:

no

Default Value:

'26.04'

Possible Values:

See actions/runner-images - Available Images for available Ubuntu image versions.

Description:

Version of the Ubuntu image used to run the job.

Note

Unfortunately, GitHub Actions has only a limited set of functions, thus, the usual Ubuntu image name like 'ubuntu-26.04' can’t be split into image name and image version.

python_version

Type:

string

Required:

no

Default Value:

'3.14'

Possible Values:

Any valid Python version conforming to the pattern <major>.<minor> or pypy-<major>.<minor>.
See actions/python-versions - available Python versions and actions/setup-python - configurable Python versions.

Description:

Python version used to run Python code in the job.

package_directory

Type:

string

Required:

yes

Default Value:

— — — —

Possible Values:

Any path relative to the repository root.

Description:

Directory containing the package sources to be checked.
Usually taken from package_directory.

artifact

Type:

string

Required:

yes

Default Value:

— — — —

Possible Values:

Any valid artifact name.

Description:

Name of the package artifact.

Note

The template currently does not reference this parameter. It is kept because it is declared required: true and removing it would break consumers that pass it.

requirements

Type:

string

Required:

no

Default Value:

'-r requirements.txt'

Possible Values:

Any valid list of parameters for pip install.

Description:

Python dependencies to be installed through pip.

bandit

Type:

string

Required:

no

Default Value:

'true'

Possible Values:

'true' / 'false'

Description:

Run the Bandit job performing Static Application Security Testing (SAST).
'true' - run the job.
'false' - skip it.

radon

Type:

string

Required:

no

Default Value:

'true'

Possible Values:

'true' / 'false'

Description:

Run the Radon job reporting code metrics, complexity and maintainability.
'true' - run the job.
'false' - skip it.

pylint

Type:

string

Required:

no

Default Value:

'true'

Possible Values:

'true' / 'false'

Description:

Run the PyLint job performing code linting.
'true' - run the job.
'false' - skip it.

Secrets

This job template needs no secrets.

Outputs

This job template has no output parameters.