Skip to content
Latchkey

Python application workflow

GitHub's official Python application starter workflow, explained and hardened by Latchkey.

D

CI health: D - needs work

The optimized version below adds caching, run de-duplication, job timeouts.

Source: GitHub official starter workflowci/python-app.ymlLicense CC0-1.0View source

What it does

This is the Python application workflow GitHub offers by default. It sets up Python, installs dependencies, lints with flake8, and runs tests with pytest.

Notably it does not cache pip downloads and sets no job timeout or concurrency, all of which Latchkey adds below.

The workflow

workflow (.yml)
name: Python application

on:
  push:
    branches: [ "main" ]
  pull_request:
    branches: [ "main" ]

permissions:
  contents: read

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Set up Python 3.10
        uses: actions/setup-python@v5
        with:
          python-version: "3.10"
      - name: Install dependencies
        run: |
          python -m pip install --upgrade pip
          pip install flake8 pytest
          if [ -f requirements.txt ]; then pip install -r requirements.txt; fi
      - name: Lint with flake8
        run: |
          flake8 . --count --select=E9,F63,F7,F82 --show-source --statistics
      - name: Test with pytest
        run: pytest

The same workflow, on Latchkey

Estimated ~20% faster on cache hits, plus fewer wasted runs and a safer supply chain. Added and changed lines are highlighted.

name: Python application on:  push:    branches: [ "main" ]  pull_request:    branches: [ "main" ] permissions:  contents: read concurrency:  group: ${{ github.workflow }}-${{ github.ref }}  cancel-in-progress: true jobs:  build:    timeout-minutes: 30    runs-on: latchkey-small    steps:      - uses: actions/checkout@v4      - name: Set up Python 3.10        uses: actions/setup-python@v5        with:          cache: 'pip'          python-version: "3.10"      - name: Install dependencies        run: |          python -m pip install --upgrade pip          pip install flake8 pytest          if [ -f requirements.txt ]; then pip install -r requirements.txt; fi      - name: Lint with flake8        run: |          flake8 . --count --select=E9,F63,F7,F82 --show-source --statistics      - name: Test with pytest        run: pytest 

What changed

  • Run on Latchkey managed runners with one line (runs-on), which apply the fixes below automatically and self-heal transient failures. This example uses latchkey-small; pick the runner size that fits the job.
  • Cancel superseded runs when a branch or PR gets a newer push.
  • Cache dependency installs on the setup step so they are served from cache.
  • Add a job timeout so a hung step cannot burn hours of runner time.

What Latchkey heals here

This workflow has steps that commonly fail on transient issues (network, registries, flaky browsers). On Latchkey managed runners they are detected, retried, and self-healed instead of failing your build:

  • Dependency installs

This workflow runs 1 job per trigger. On Latchkey the same minutes cost up to 58% less than GitHub-hosted, with zero queue time.

Actions used in this workflow

Frequently asked questions

What does the Python application workflow workflow do?
This is the Python application workflow GitHub offers by default. It sets up Python, installs dependencies, lints with flake8, and runs tests with pytest.
What CI health grade does this workflow get?
This Python workflow grades D. Paste your own workflow into the Latchkey grader to see its grade and the exact fixes.
How can I improve this Python workflow?
Apply caching, run de-duplication, job timeouts. Latchkey applies these automatically on managed runners when you point runs-on at Latchkey.

References