File tree Expand file tree Collapse file tree 10 files changed +24
-22
lines changed Expand file tree Collapse file tree 10 files changed +24
-22
lines changed Original file line number Diff line number Diff line change @@ -34,13 +34,13 @@ jobs:
3434
3535 # Initializes the CodeQL tools for scanning.
3636 - name : Initialize CodeQL
37- uses : github/codeql-action/init@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
37+ uses : github/codeql-action/init@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
3838 with :
3939 languages : ${{ matrix.language }}
4040 build-mode : ${{ matrix.build-mode }}
4141 queries : security-extended
4242
4343 - name : Perform CodeQL Analysis
44- uses : github/codeql-action/analyze@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
44+ uses : github/codeql-action/analyze@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
4545 with :
4646 category : " /language:${{matrix.language}}"
Original file line number Diff line number Diff line change 2222 with :
2323 python-version-file : " .python-version"
2424 - name : Install uv
25- uses : astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6.8.0
25+ uses : astral-sh/setup-uv@85856786d1ce8acfbcc2f13a5f3fbd6b938f9f41 # v7.1.2
2626 - name : Install dependencies
2727 run : |
2828 uv sync --locked --extra docs
Original file line number Diff line number Diff line change @@ -26,11 +26,11 @@ jobs:
2626 with :
2727 python-version-file : " .python-version"
2828 - name : Set up Node.js
29- uses : actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 .0.0
29+ uses : actions/setup-node@2028fbc5c25fe9cf00d9f06a71cc4710d4507903 # v6 .0.0
3030 with :
31- node-version : 22
31+ node-version : 24
3232 - name : Install uv
33- uses : astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6.8.0
33+ uses : astral-sh/setup-uv@85856786d1ce8acfbcc2f13a5f3fbd6b938f9f41 # v7.1.2
3434 - name : Install dependencies
3535 run : |
3636 uv sync --locked --all-extras
4949 with :
5050 python-version-file : " .python-version"
5151 - name : Install uv
52- uses : astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6.8.0
52+ uses : astral-sh/setup-uv@85856786d1ce8acfbcc2f13a5f3fbd6b938f9f41 # v7.1.2
5353 - name : Install dependencies
5454 run : |
5555 uv sync --locked --extra tests
Original file line number Diff line number Diff line change @@ -26,14 +26,14 @@ jobs:
2626 - name : Build sdist
2727 run : |
2828 uv build --sdist
29- - uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
29+ - uses : actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
3030 with :
3131 name : artifact-sdist
3232 path : dist/*.tar.gz
3333 - name : Build wheel
3434 run : |
3535 uv build --wheel
36- - uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
36+ - uses : actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
3737 with :
3838 name : artifact-wheel
3939 path : dist/*.whl
4848 id-token : write # required by trusted publisher
4949 steps :
5050 - name : Download artifacts
51- uses : actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5
51+ uses : actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53 # v6
5252 with :
5353 path : dist
5454 pattern : artifact-*
Original file line number Diff line number Diff line change 7272 private-key : ${{ secrets.RENOVATE_APP_PEM }}
7373
7474 - name : Self-hosted Renovate
75- uses : renovatebot/github-action@2d941ef4e268e53affdc1f11365c69a73e544f50 # v43.0.14
75+ uses : renovatebot/github-action@ea850436a5fe75c0925d583c7a02c60a5865461d # v43.0.20
7676 with :
7777 configurationFile : .github/renovate.json5
7878 token : " ${{ steps.get-github-app-token.outputs.token }}"
Original file line number Diff line number Diff line change 3535
3636 # Upload the results to GitHub's code scanning dashboard
3737 - name : Upload to code-scanning
38- uses : github/codeql-action/upload-sarif@3599b3baa15b485a2e49ef411a7a4bb2452e7f93 # v3.30.5
38+ uses : github/codeql-action/upload-sarif@0499de31b99561a6d14a36a5f662c2a54f91beee # v4.31.2
3939 with :
4040 sarif_file : results.sarif
Original file line number Diff line number Diff line change 2424 with :
2525 persist-credentials : false
2626 - name : Run Zizmor scan
27- uses : open-edge-platform/geti-ci/actions/zizmor@c2bb2697178bb2e50014420aef2351a45749b925
27+ uses : open-edge-platform/geti-ci/actions/zizmor@4ec90fb54c7be053e40b9e3ecdf399cf501596ca
2828 with :
2929 scan-scope : " all"
3030 severity-level : " LOW"
4242 with :
4343 persist-credentials : false
4444 - name : Run Bandit scan
45- uses : open-edge-platform/geti-ci/actions/bandit@c2bb2697178bb2e50014420aef2351a45749b925
45+ uses : open-edge-platform/geti-ci/actions/bandit@4ec90fb54c7be053e40b9e3ecdf399cf501596ca
4646 with :
4747 scan-scope : " all"
4848 severity-level : " LOW"
6262 persist-credentials : false
6363 - name : Run Trivy scan
6464 id : trivy
65- uses : open-edge-platform/geti-ci/actions/trivy@c2bb2697178bb2e50014420aef2351a45749b925
65+ uses : open-edge-platform/geti-ci/actions/trivy@4ec90fb54c7be053e40b9e3ecdf399cf501596ca
6666 with :
6767 scan_type : " fs"
6868 scan-scope : all
8484 persist-credentials : false
8585 - name : Run Semgrep scan
8686 id : semgrep
87- uses : open-edge-platform/geti-ci/actions/semgrep@c2bb2697178bb2e50014420aef2351a45749b925
87+ uses : open-edge-platform/geti-ci/actions/semgrep@4ec90fb54c7be053e40b9e3ecdf399cf501596ca
8888 with :
8989 scan-scope : " all"
9090 severity : " LOW"
Original file line number Diff line number Diff line change 1919 with :
2020 python-version-file : " .python-version"
2121 - name : Install uv
22- uses : astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6.8.0
22+ uses : astral-sh/setup-uv@85856786d1ce8acfbcc2f13a5f3fbd6b938f9f41 # v7.1.2
2323 - name : Install dependencies
2424 run : |
2525 uv sync --locked --extra tests --extra-index-url https://download.pytorch.org/whl/cpu
Original file line number Diff line number Diff line change 2121 with :
2222 python-version-file : " .python-version"
2323 - name : Install uv
24- uses : astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6.8.0
24+ uses : astral-sh/setup-uv@85856786d1ce8acfbcc2f13a5f3fbd6b938f9f41 # v7.1.2
2525 - name : Install dependencies
2626 run : |
2727 uv sync --locked --extra tests --extra-index-url https://download.pytorch.org/whl/cpu
4141 with :
4242 persist-credentials : false
4343 - name : Run Zizmor scan
44- uses : open-edge-platform/geti-ci/actions/zizmor@c2bb2697178bb2e50014420aef2351a45749b925
44+ uses : open-edge-platform/geti-ci/actions/zizmor@4ec90fb54c7be053e40b9e3ecdf399cf501596ca
4545 with :
4646 scan-scope : " changed"
4747 severity-level : " LOW"
5757 with :
5858 persist-credentials : false
5959 - name : Run Bandit scan
60- uses : open-edge-platform/geti-ci/actions/bandit@c2bb2697178bb2e50014420aef2351a45749b925
60+ uses : open-edge-platform/geti-ci/actions/bandit@4ec90fb54c7be053e40b9e3ecdf399cf501596ca
6161 with :
6262 scan-scope : " changed"
6363 severity-level : " LOW"
7474 uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
7575 with :
7676 persist-credentials : false
77- - name : Run Bandit scan
78- uses : open-edge-platform/geti-ci/actions/semgrep@c2bb2697178bb2e50014420aef2351a45749b925
77+ fetch-depth : 0
78+ - name : Run Semgrep scan
79+ uses : open-edge-platform/geti-ci/actions/semgrep@4ec90fb54c7be053e40b9e3ecdf399cf501596ca
7980 with :
8081 scan-scope : " changed"
8182 severity : " LOW"
Original file line number Diff line number Diff line change 1+ **/uv.lock
You can’t perform that action at this time.
0 commit comments