diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..c2dc278 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,23 @@ +# Dependabot — keeps Poetry lockfile and Actions pins current. +# https://docs.github.com/code-security/dependabot +version: 2 +updates: + - package-ecosystem: pip + directory: / + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 10 + labels: + - dependencies + - python + + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 10 + labels: + - dependencies + - github-actions diff --git a/.github/requirements-update-ci.in b/.github/requirements-update-ci.in new file mode 100644 index 0000000..b34827c --- /dev/null +++ b/.github/requirements-update-ci.in @@ -0,0 +1,6 @@ +# Pins for the Update CI requirements workflow bootstrap (pip-tools). +# Regenerated with: +# pip-compile --generate-hashes --allow-unsafe \ +# -o .github/requirements-update-ci.txt .github/requirements-update-ci.in +pip==25.0.1 +pip-tools==7.6.0 diff --git a/.github/requirements-update-ci.txt b/.github/requirements-update-ci.txt new file mode 100644 index 0000000..767884f --- /dev/null +++ b/.github/requirements-update-ci.txt @@ -0,0 +1,46 @@ +# +# This file is autogenerated by pip-compile with Python 3.12 +# by the following command: +# +# pip-compile --allow-unsafe --generate-hashes --output-file=.github/requirements-update-ci.txt .github/requirements-update-ci.in +# +build==1.5.0 \ + --hash=sha256:13f3eecb844759ab66efec90ca17639bbf14dc06cb2fdf37a9010322d9c50a6f \ + --hash=sha256:302c22c3ba2a0fd5f3911918651341ebb3896176cbdec15bd421f80b1afc7647 + # via pip-tools +click==8.4.2 \ + --hash=sha256:9a6cea6e60b17ebe0a44c5cc636d94f09bd66142c1cd7d8b4cd731c4917a15f6 \ + --hash=sha256:e6f9f66136c816745b9d65817da91d61d957fb16e02e4dcd0552553c5a197b76 + # via pip-tools +packaging==26.2 \ + --hash=sha256:5fc45236b9446107ff2415ce77c807cee2862cb6fac22b8a73826d0693b0980e \ + --hash=sha256:ff452ff5a3e828ce110190feff1178bb1f2ea2281fa2075aadb987c2fb221661 + # via + # build + # wheel +pip-tools==7.6.0 \ + --hash=sha256:4bd99155b6d8de358a214b0865e1a2855a453570c1a83d40f7b564870b8657be \ + --hash=sha256:c1c59f7844df4866fa9542d3f50d1f44be537ac0027cb50b2563d6a992853981 + # via -r .github/requirements-update-ci.in +pyproject-hooks==1.2.0 \ + --hash=sha256:1e859bd5c40fae9448642dd871adf459e5e2084186e8d2c2a79a824c970da1f8 \ + --hash=sha256:9e5c6bfa8dcc30091c74b0cf803c81fdd29d94f01992a7707bc97babb1141913 + # via + # build + # pip-tools +wheel==0.47.0 \ + --hash=sha256:212281cab4dff978f6cedd499cd893e1f620791ca6ff7107cf270781e587eced \ + --hash=sha256:cc72bd1009ba0cf63922e28f94d9d83b920aa2bb28f798a31d0691b02fa3c9b3 + # via pip-tools + +# The following packages are considered to be unsafe in a requirements file: +pip==25.0.1 \ + --hash=sha256:88f96547ea48b940a3a385494e181e29fb8637898f88d88737c5049780f196ea \ + --hash=sha256:c46efd13b6aa8279f33f2864459c8ce587ea6a1a59ee20de055868d8f7688f7f + # via + # -r .github/requirements-update-ci.in + # pip-tools +setuptools==83.0.0 \ + --hash=sha256:025bccbbf0fa05b6192bc64ae1e7b16e001fd6d6d4d5de03c97b1c1ade523bef \ + --hash=sha256:29b23c360f22f414dc7336bb39178cc7bcbf6021ed2733cde173f09dba19abb3 + # via pip-tools diff --git a/.github/workflows/update-ci-requirements.yml b/.github/workflows/update-ci-requirements.yml index 1be2c0d..d69e83d 100644 --- a/.github/workflows/update-ci-requirements.yml +++ b/.github/workflows/update-ci-requirements.yml @@ -5,6 +5,8 @@ on: branches: [main] paths: - .github/requirements-ci.in + - .github/requirements-update-ci.in + - .github/requirements-update-ci.txt - .github/workflows/update-ci-requirements.yml - poetry.lock - pyproject.toml @@ -27,7 +29,7 @@ jobs: python-version: "3.12" - name: Install pip-tools - run: python -m pip install 'pip==25.0.1' 'pip-tools==7.6.0' + run: python -m pip install --require-hashes -r .github/requirements-update-ci.txt - name: Sync tox pin from poetry.lock and compile hashes run: | diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index e5cf7eb..209d4a7 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -1,8 +1,32 @@ -Please adhere to PEP 8 as best appropriate. Code committed must be -submitted under the existing project license. +# Contributing -This project is switching to a git-flow style, please make pull requests -against the `develop` branch. +Please adhere to PEP 8 where appropriate. Code committed must be +submitted under the existing project license (MIT). -Good reading -* https://packaging.python.org/en/latest/tutorials/packaging-projects/ +## Pull requests + +Open pull requests against the **`main`** branch. + +CI (tox via GitHub Actions) must pass for the supported Python versions +before merge. + +## Security + +Report vulnerabilities privately per [SECURITY.md](SECURITY.md). Do not +open public issues for security reports. + +## Development + +```bash +poetry install --with test,dev +poetry run tox +``` + +## OpenSSF Best Practices + +This project aims to earn an +[OpenSSF Best Practices](https://www.bestpractices.dev/) badge. +Maintainers: create or update the project entry at +[bestpractices.dev](https://www.bestpractices.dev/en/projects/new) +(repo URL: `https://github.com/FirefighterBlu3/python-pam`), then add the +badge markdown to `README.md` using the assigned project ID. diff --git a/README.md b/README.md index 843b9d7..e34e0c0 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,9 @@ # python-pam [![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/FirefighterBlu3/python-pam/badge)](https://scorecard.dev/viewer/?uri=github.com/FirefighterBlu3/python-pam) + Python pam module supporting py3 for Linux type systems (!windows, !py2)