name: CI

on:
  push:
    branches: [ "main" ]
  pull_request:
    branches: [ "main" ]

permissions:
  contents: read

jobs:
  build:
    runs-on: ubuntu-latest

    strategy:
      matrix:
        python-version: ['3.10', '3.11', '3.12', '3.13']

    steps:
    - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4

    - name: Install uv
      uses: astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57 # v8.0.0
      with:
        python-version: ${{ matrix.python-version }}

    - name: Run CI checks
      run: bash hooks/ci-check.sh

    - name: Upload security artifacts
      uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
      if: always()
      with:
        name: security-reports-py${{ matrix.python-version }}
        path: |
          bandit-report.json
          licenses.json
        retention-days: 30
