Repository navigation
feat: add Copier template for production-ready Python projects - #2
Merged
Merged
Conversation
added 2 commits
October 4, 2026 18:41
Generated projects meet the Technical, Quality and Security pillars from the first commit: uv, ruff, strict mypy, pytest with a coverage gate, pre-commit with gitleaks and conventional commits, uv audit, a tested Docker image and GitHub Actions CI that runs the same invoke tasks as a developer does locally. An optional API variant adds a FastAPI service around an injectable upstream client, a fake upstream, and a Bruno collection that runs as end-to-end tests. It uses httpx2 because Starlette's test client now deprecates httpx. The template's own tests render each variant and run its lint and test tasks, and CI additionally runs audit, smoke and API tests inside the rendered projects, so a template change can't ship a broken project.
setup-uv no longer publishes a moving major tag, so @v10 fails to resolve. Dependabot keeps the pinned version current.
jitsejan
pushed a commit
that referenced
this pull request
Oct 4, 2026
* feat: add Copier template for production-ready Python projects Generated projects meet the Technical, Quality and Security pillars from the first commit: uv, ruff, strict mypy, pytest with a coverage gate, pre-commit with gitleaks and conventional commits, uv audit, a tested Docker image and GitHub Actions CI that runs the same invoke tasks as a developer does locally. An optional API variant adds a FastAPI service around an injectable upstream client, a fake upstream, and a Bruno collection that runs as end-to-end tests. It uses httpx2 because Starlette's test client now deprecates httpx. The template's own tests render each variant and run its lint and test tasks, and CI additionally runs audit, smoke and API tests inside the rendered projects, so a template change can't ship a broken project. * fix: pin setup-uv to a published release tag setup-uv no longer publishes a moving major tag, so @v10 fails to resolve. Dependabot keeps the pinned version current. --------- Co-authored-by: Jitse-Jan <jitsejan@qualixto.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Every new project should start where a good team's projects end up: locked dependencies, strict linting and typing, a coverage gate, secrets scanning and a tested container, with CI that can't drift from local checks. This template packages that so Qualixto projects, and anyone cloning them, start there.
What changed
copier.ymlwith validated questions (name, slug, package, Python 3.12–3.14, licence, optional API)uv audit, Dependabot, Docker image with smoke test,DEFINITION_OF_DONE.md, ADRs andCLAUDE.mdhttpx2upstream, fake upstream, and Bruno collection run as end-to-end testsReviewer notes
httpx2replaceshttpxbecause Starlette's test client now deprecates httpx.api-testand the Docker smoke test bind free ports, so they don't clash with anything already running on 8000/8001.uvx copier copy --trust --vcs-ref feat/1-copier-template gh:Qualixto/python-template /tmp/demoCloses #1
Checklist
<type>/<issue>-<short-description><type>: <description>