Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 4 additions & 7 deletions .editorconfig
Original file line number Diff line number Diff line change
@@ -1,17 +1,14 @@
root = true

[*.py]
[*.{py,md,yml,yaml,json,toml}]
charset = utf-8
end_of_line = lf
indent_style = space
indent_size = 4
insert_final_newline = true
trim_trailing_whitespace = true

[*.py]
indent_size = 4

[*.{md,yml,yaml,json,toml}]
charset = utf-8
end_of_line = lf
indent_style = space
indent_size = 2
insert_final_newline = true
trim_trailing_whitespace = true
6 changes: 2 additions & 4 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,10 @@
name: CodeQL Security Analysis

on:
push:
branches:
- main
pull_request:
push: &main-branch-trigger
branches:
- main
pull_request: *main-branch-trigger
schedule:
# Run weekly on Monday at 06:00 UTC
- cron: "0 6 * * 1"
Expand Down
18 changes: 10 additions & 8 deletions .github/workflows/docker-image-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ on:
pull_request:
paths:
- "Dockerfile*"
- "docker-install-rust.sh"
- ".dockerignore"
- "modelaudit/**"
- "packages/modelaudit-picklescan/**"
Expand Down Expand Up @@ -37,6 +38,7 @@ jobs:
filters: |
docker:
- 'Dockerfile*'
- 'docker-install-rust.sh'
- '.dockerignore'
- 'modelaudit/**'
- 'packages/modelaudit-picklescan/**'
Expand All @@ -45,10 +47,12 @@ jobs:
- '.github/workflows/docker-image-test.yml'
full-image:
- 'Dockerfile.full'
- 'docker-install-rust.sh'
- 'packages/modelaudit-picklescan/**'
- '.github/workflows/docker-image-test.yml'
tensorflow-image:
- 'Dockerfile.tensorflow'
- 'docker-install-rust.sh'
- 'requirements-tensorflow.txt'
- 'modelaudit/**'
- 'packages/modelaudit-picklescan/**'
Expand All @@ -65,7 +69,8 @@ jobs:
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6

- name: Set up Docker Buildx
- &shared-set-up-docker-buildx
name: Set up Docker Buildx
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4

- name: Build lightweight image
Expand All @@ -77,7 +82,7 @@ jobs:
load: true
cache-from: type=gha,scope=lightweight
cache-to: type=gha,mode=max,scope=lightweight
build-args: |
build-args: &inline-cache-build-args |
BUILDKIT_INLINE_CACHE=1

- name: Test lightweight container help command
Expand Down Expand Up @@ -130,8 +135,7 @@ jobs:
- name: Set up QEMU
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
- *shared-set-up-docker-buildx

- name: Build full image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7
Expand All @@ -142,8 +146,7 @@ jobs:
load: true
cache-from: type=gha,scope=full
cache-to: type=gha,mode=max,scope=full
build-args: |
BUILDKIT_INLINE_CACHE=1
build-args: *inline-cache-build-args
timeout-minutes: 60 # Increased timeout for ML dependency build

- name: Test full container help command
Expand Down Expand Up @@ -195,8 +198,7 @@ jobs:
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4
- *shared-set-up-docker-buildx

- name: Build TensorFlow image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7
Expand Down
20 changes: 7 additions & 13 deletions .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,16 +24,17 @@ jobs:
if: github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
timeout-minutes: 5
outputs:
outputs: &validated-image-outputs
image_tag: ${{ steps.validate.outputs.image_tag }}
source_ref: ${{ steps.validate.outputs.source_ref }}
source_sha: ${{ steps.validate.outputs.source_sha }}
environment:
name: ghcr-manual-publish
permissions:
permissions: &read-contents-permissions
contents: read
steps:
- name: Checkout repo
- &shared-checkout-repo
name: Checkout repo
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
ref: ${{ github.event.repository.default_branch }}
Expand All @@ -56,17 +57,10 @@ jobs:
if: github.event_name == 'release' && startsWith(github.event.release.tag_name, 'v')
runs-on: ubuntu-latest
timeout-minutes: 5
outputs:
image_tag: ${{ steps.validate.outputs.image_tag }}
source_ref: ${{ steps.validate.outputs.source_ref }}
source_sha: ${{ steps.validate.outputs.source_sha }}
permissions:
contents: read
outputs: *validated-image-outputs
permissions: *read-contents-permissions
steps:
- name: Checkout repo
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
ref: ${{ github.event.repository.default_branch }}
- *shared-checkout-repo

- name: Validate release image tag
id: validate
Expand Down
30 changes: 11 additions & 19 deletions .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,10 +25,12 @@ jobs:
- { os: windows-latest, python-version: "3.12" }
- { os: windows-latest, python-version: "3.13" }
steps:
- name: Checkout repo
- &checkout-repo
name: Checkout repo
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6

- name: Install uv
- &install-uv
name: Install uv
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7
with:
enable-cache: true
Expand All @@ -37,7 +39,8 @@ jobs:
run: |
uv python pin ${{ matrix.python-version }}

- name: Install Rust toolchain
- &install-rust-toolchain
name: Install Rust toolchain
run: |
rustup toolchain install stable --profile minimal
rustup default stable
Expand All @@ -55,22 +58,15 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
- name: Checkout repo
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
- *checkout-repo

- name: Install uv
uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7
with:
enable-cache: true
- *install-uv

- name: Pin Python version
run: |
uv python pin 3.11

- name: Install Rust toolchain
run: |
rustup toolchain install stable --profile minimal
rustup default stable
- *install-rust-toolchain

- name: Sync dependencies
run: |
Expand All @@ -85,13 +81,9 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
- name: Checkout repo
uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
- *checkout-repo

- name: Install Rust toolchain
run: |
rustup toolchain install stable --profile minimal
rustup default stable
- *install-rust-toolchain

- name: Run standalone picklescan Rust tests once
run: |
Expand Down
15 changes: 2 additions & 13 deletions .github/workflows/perf.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: Performance Benchmarks

on:
pull_request:
paths:
paths: &benchmark-trigger-paths
- "modelaudit/**"
- "packages/modelaudit-picklescan/**"
- "tests/benchmarks/**"
Expand All @@ -17,18 +17,7 @@ on:
push:
branches:
- main
paths:
- "modelaudit/**"
- "packages/modelaudit-picklescan/**"
- "tests/benchmarks/**"
- "tests/helpers/**"
- "tests/conftest.py"
- "tests/test_benchmark_report.py"
- "tests/test_performance_benchmarks.py"
- "scripts/benchmark_report.py"
- "pyproject.toml"
- "uv.lock"
- ".github/workflows/perf.yml"
paths: *benchmark-trigger-paths
workflow_dispatch:

permissions:
Expand Down
Loading
Loading