-
Notifications
You must be signed in to change notification settings - Fork 643
chore(deps): update github workflows #6733
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -28,9 +28,9 @@ | |
| TOX_UV_PYTHON_PREFERENCE: ${{ (matrix.python-version == '3.6' || matrix.python-version == '3.7') && 'only-system' || 'managed' }} | ||
| container: ${{ (matrix.python-version == '3.6' || matrix.python-version == '3.7') && format('python:{0}', matrix.python-version) || null }} | ||
| steps: | ||
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | ||
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
| - name: Install uv | ||
| uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 | ||
| uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 | ||
|
Check failure on line 33 in .github/workflows/test-integrations-cloud.yml
|
||
|
Comment on lines
+31
to
+33
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Workflow pins action SHAs with falsified version comments Workflow files and Jinja templates pin third-party GitHub Actions to specific commit SHAs while the adjacent comments claim major versions that do not match those commits. For example, Evidence
Identified by Warden find-bugs · 23X-UUS |
||
| with: | ||
| enable-cache: false | ||
| - name: Mark workspace safe for git (3.6/3.7 container) | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -19,15 +19,15 @@ | |
|
|
||
| steps: | ||
| - name: Checkout repo | ||
| uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
| with: | ||
| token: ${{ secrets.GITHUB_TOKEN }} | ||
|
|
||
| - name: Install uv | ||
| uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 | ||
| uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0 | ||
| with: | ||
| cache-python: true | ||
|
|
||
|
Check warning on line 30 in .github/workflows/update-tox.yml
|
||
|
Comment on lines
28
to
30
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. setup-uv v9 breaking option name not migrated in update-tox.yml
Evidence
Identified by Warden code-review · TJ2-EMN |
||
| - name: Pre-install Python interpreters | ||
| run: | | ||
| uv python install 3.8 3.9 3.10 3.11 3.12 3.13 3.14 3.14t | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Invalid setup-python action pin
High Severity
actions/setup-pythonis pinned to5fda3b95...with comment# v7, but the PR’s own update table targets digestece7cb0(publishedv6.3.0), and there is no publishedsetup-pythonv7release matching that SHA. The AI integration workflow can fail at action resolution before tests run.Reviewed by Cursor Bugbot for commit ae76386. Configure here.