security.yml previously ran safety/bandit/semgrep with `|| true` and could not go red. Now: pip-audit on requirements.txt is a hard gate (dev deps reported only), bandit HIGH fails (B104 bind-all skipped: intended behind Cloudflare/Caddy), pip-licenses uploaded as a report. Weekly + on dependency/source changes. Running it locally found 29 advisories, all in pinned-and-forgotten runtime deps: starlette 0.27 (7, incl. Host-header path confusion and form DoS), fastapi 0.104, requests 2.31 (3), pymysql 1.1. Bumped to current: fastapi 0.141.1 / starlette 1.6.0, pydantic 2.13.5, uvicorn 0.52.4, requests 2.34.2, pymysql 1.2.0; dev: pytest 9.1.1, black 26.5.1. pip-audit is now clean. requires-python narrowed to 3.11 (the truth: psycopg2-binary 2.9.9 fails on 3.13; pandas 2.0.3 has no 3.12 wheels). Full suite passes; API smoke-tested (health, stations, forecast, history, stats, docs, openapi) on the new stack. black 26 reformatted 8 files.
144 lines
3.6 KiB
TOML
144 lines
3.6 KiB
TOML
[build-system]
|
|
requires = ["setuptools>=61.0", "wheel"]
|
|
build-backend = "setuptools.build_meta"
|
|
|
|
[project]
|
|
name = "northern-thailand-ping-river-monitor"
|
|
version = "3.1.3"
|
|
description = "Real-time water level monitoring system for the Ping River Basin in Northern Thailand"
|
|
readme = "README.md"
|
|
license = {text = "MIT"}
|
|
authors = [
|
|
{name = "Ping River Monitor Team", email = "contact@example.com"}
|
|
]
|
|
keywords = [
|
|
"water monitoring",
|
|
"hydrology",
|
|
"thailand",
|
|
"ping river",
|
|
"environmental monitoring",
|
|
"time series",
|
|
"fastapi",
|
|
"real-time data"
|
|
]
|
|
classifiers = [
|
|
"Development Status :: 4 - Beta",
|
|
"Intended Audience :: Science/Research",
|
|
"Intended Audience :: System Administrators",
|
|
"Topic :: Scientific/Engineering :: Hydrology",
|
|
"Topic :: System :: Monitoring",
|
|
"Programming Language :: Python :: 3",
|
|
"Programming Language :: Python :: 3.11",
|
|
"Programming Language :: Python :: 3.12",
|
|
"Operating System :: OS Independent",
|
|
"Environment :: Web Environment",
|
|
"Framework :: FastAPI"
|
|
]
|
|
requires-python = ">=3.11,<3.12"
|
|
dependencies = [
|
|
# Core dependencies
|
|
"requests==2.34.2",
|
|
"schedule==1.2.0",
|
|
"pandas==2.0.3",
|
|
"numpy>=1.24,<2",
|
|
# Flood forecasting (ML)
|
|
"scikit-learn==1.9.0",
|
|
# Web API framework
|
|
"fastapi==0.141.1",
|
|
"uvicorn[standard]==0.52.4",
|
|
"pydantic==2.13.5",
|
|
# Database adapters
|
|
"sqlalchemy==2.0.23",
|
|
"influxdb==5.3.1",
|
|
"pymysql==1.2.0",
|
|
"psycopg2-binary==2.9.9",
|
|
# Monitoring and metrics
|
|
"psutil==5.9.6"
|
|
]
|
|
|
|
[project.optional-dependencies]
|
|
dev = [
|
|
# Testing
|
|
"pytest==9.1.1",
|
|
"pytest-cov==4.1.0",
|
|
"pytest-asyncio==0.21.1",
|
|
# Code formatting and linting
|
|
"black==26.5.1",
|
|
"flake8==6.1.0",
|
|
"isort==5.12.0",
|
|
"mypy==1.7.1",
|
|
# Pre-commit hooks
|
|
"pre-commit==3.5.0",
|
|
# Development tools
|
|
"ipython==8.17.2",
|
|
"jupyter==1.0.0",
|
|
# Type stubs
|
|
"types-requests==2.33.0.20260906",
|
|
"types-python-dateutil==2.8.19.14"
|
|
]
|
|
docs = [
|
|
"sphinx==7.2.6",
|
|
"sphinx-rtd-theme==1.3.0",
|
|
"sphinx-autodoc-typehints==1.25.2"
|
|
]
|
|
all = [
|
|
"influxdb==5.3.1",
|
|
"pymysql==1.2.0",
|
|
"psycopg2-binary==2.9.9"
|
|
]
|
|
|
|
[project.scripts]
|
|
ping-river-monitor = "src.main:main"
|
|
ping-river-api = "src.web_api:main"
|
|
|
|
[project.urls]
|
|
Homepage = "https://git.b4l.co.th/B4L/Northern-Thailand-Ping-River-Monitor"
|
|
Repository = "https://git.b4l.co.th/B4L/Northern-Thailand-Ping-River-Monitor"
|
|
Issues = "https://git.b4l.co.th/B4L/Northern-Thailand-Ping-River-Monitor/issues"
|
|
Documentation = "https://git.b4l.co.th/B4L/Northern-Thailand-Ping-River-Monitor/wiki"
|
|
|
|
[dependency-groups]
|
|
dev = [
|
|
# Testing
|
|
"pytest==9.1.1",
|
|
"pytest-cov==4.1.0",
|
|
"pytest-asyncio==0.21.1",
|
|
# Code formatting and linting
|
|
"black==26.5.1",
|
|
"flake8==6.1.0",
|
|
"isort==5.12.0",
|
|
"mypy==1.7.1",
|
|
# Pre-commit hooks
|
|
"pre-commit==3.5.0",
|
|
# Development tools
|
|
"ipython==8.17.2",
|
|
"jupyter==1.0.0",
|
|
# Type stubs
|
|
"types-requests==2.33.0.20260906",
|
|
"types-python-dateutil==2.8.19.14",
|
|
# Documentation
|
|
"sphinx==7.2.6",
|
|
"sphinx-rtd-theme==1.3.0",
|
|
"sphinx-autodoc-typehints==1.25.2",
|
|
"pyinstaller>=6.16.0",
|
|
]
|
|
|
|
[tool.setuptools.packages.find]
|
|
where = ["src"]
|
|
|
|
[tool.setuptools.package-dir]
|
|
"" = "src"
|
|
|
|
# One formatting contract for CI, pre-commit and editors. Black's default 88
|
|
# columns; isort in black-compatible mode. Run `make format` before committing.
|
|
[tool.black]
|
|
line-length = 88
|
|
target-version = ["py311"]
|
|
extend-exclude = '/(\.venv|venv|models|\.claude-flow|\.swarm)/'
|
|
|
|
[tool.isort]
|
|
profile = "black"
|
|
line_length = 88
|
|
known_first_party = ["src"]
|
|
skip_gitignore = true
|