Skip to content

feat(security): add HSTS header to all REST and MCP HTTP responses #39

feat(security): add HSTS header to all REST and MCP HTTP responses

feat(security): add HSTS header to all REST and MCP HTTP responses #39

Workflow file for this run

name: CI
# Lint + test the API/MCP package (src/idc_api, tests). No GCP or credentials needed; the
# first test run downloads the specialized idc-index parquet (IDC_API_INCLUDE_INDICES=all
# by default).
on:
workflow_dispatch:
push:
branches: [main]
paths:
- "src/idc_api/**"
- "tests/**"
- "pyproject.toml"
- "uv.lock"
- ".github/workflows/ci.yml"
pull_request:
paths:
- "src/idc_api/**"
- "tests/**"
- "pyproject.toml"
- "uv.lock"
- ".github/workflows/ci.yml"
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
test:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
python-version: ["3.11", "3.12"]
steps:
- uses: actions/checkout@v7
- name: Set up uv
uses: astral-sh/setup-uv@v7
with:
enable-cache: true
python-version: ${{ matrix.python-version }}
- name: Install (locked deps + dev extras)
run: uv sync --extra dev --python ${{ matrix.python-version }}
- name: Lint (ruff)
run: uv run ruff check src tests
- name: Format (ruff)
run: uv run ruff format --check src tests
- name: Security lint (bandit)
run: uv run bandit -q -r src/idc_api
- name: Dependency vulnerability scan (pip-audit)
run: uv run pip-audit
- name: Test (pytest)
run: uv run pytest tests -q