ci(security): upgrade pip in dependency-scan, drop stale ignores
dependency-scan (pip-audit) was red: it scans the whole env, and the runner's bundled pip 26.1.1 carries PYSEC-2026-196 (fixed in 26.1.2). The job was the only CI job not upgrading pip. Now runs 'python -m pip install --upgrade pip' before auditing — removes the vulnerable version outright instead of suppressing it. pip 26.1.2 also fixes CVE-2026-3219 and CVE-2026-6357 (both were pip vulns, per pip-audit attributing them to the pip package), so the two now-stale --ignore-vuln entries are removed — stale security ignores mask the exact CVEs they name if those reappear elsewhere. Verified in a clean reproduction of the job env (fresh venv, upgrade pip, pip install -e ., pip-audit --skip-editable with NO ignores): 'No known vulnerabilities found', exit 0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
27a175b2c9
commit
1ee51f3295
@@ -22,10 +22,17 @@ jobs:
|
||||
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: pip install pip-audit
|
||||
# Upgrade pip first: pip-audit scans the whole environment, and the
|
||||
# runner's bundled pip (26.1.1) carries advisory PYSEC-2026-196 (fixed in
|
||||
# 26.1.2). Upgrading removes the vulnerable version outright rather than
|
||||
# suppressing it — and 26.1.2 also resolves CVE-2026-3219 / CVE-2026-6357,
|
||||
# which is why those two stale --ignore-vuln entries are no longer needed.
|
||||
- run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install pip-audit
|
||||
- run: pip install -e .
|
||||
- name: Pip audit
|
||||
run: pip-audit --skip-editable --ignore-vuln CVE-2026-3219 --ignore-vuln CVE-2026-6357
|
||||
run: pip-audit --skip-editable
|
||||
|
||||
codeql:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
Reference in New Issue
Block a user