ci: OSSF scorecard hardening (DPLAN-0243) — hash-pin all standalone workflow pip installs via .github/requirements/ locks (pip/lint/build/e2e/audit, pip-compile --generate-hashes, 11/11 target-env closure verified incl. Windows colorama marker fix) + provenance attestation on publish (attest-build-provenance v4.1.1 SHA-pinned, id-token+attestations perms) + dependabot pip ecosystem for the new locks. Editable -e . installs untouched byte-identical. 5/5 fresh-venv --require-hashes installs green, 5/5 YAML parse, pinned ruff matches repo lint. First SSH-signed commit (repo config wired this session).

This commit is contained in:
AIOSAI
2026-07-15 12:21:22 -07:00
parent 25fc02d07a
commit 9048666c65
15 changed files with 578 additions and 8 deletions
+6 -4
View File
@@ -20,7 +20,9 @@ jobs:
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.13"
- run: pip install ruff
# Hash-pinned tool install (Scorecard: Pinned-Dependencies). Pins ruff to
# the version this lint gate is known-green against; see .github/requirements/lint.in.
- run: python -m pip install --require-hashes -r .github/requirements/lint.txt
- run: ruff check src/ tests/
- run: ruff format --check src/ tests/
@@ -36,7 +38,7 @@ jobs:
with:
python-version: ${{ matrix.python-version }}
- run: |
python -m pip install --upgrade pip
python -m pip install --require-hashes -r .github/requirements/pip.txt
pip install -e ".[dev]"
# tests/e2e build a wheel + clean venv per the dedicated e2e-wheel.yml
# workflow — they are not part of the fast unit lane.
@@ -57,7 +59,7 @@ jobs:
with:
python-version: "3.13"
- run: |
python -m pip install --upgrade pip
python -m pip install --require-hashes -r .github/requirements/pip.txt
# Install the `memory` extra (numpy/chromadb/fastembed) alongside dev:
# the diagnostics standard runs pyright over every branch, and memory's
# handlers import chromadb/numpy. Without these deps installed, pyright
@@ -79,7 +81,7 @@ jobs:
with:
python-version: "3.13"
- run: |
python -m pip install --upgrade pip
python -m pip install --require-hashes -r .github/requirements/pip.txt
pip install -e ".[dev]"
- run: coverage run -m pytest --rootdir=. --ignore=tests/e2e
- run: coverage xml
+8 -1
View File
@@ -47,7 +47,14 @@ jobs:
python-version: ${{ matrix.python-version }}
- name: Install build tooling
run: python -m pip install --upgrade pip build pytest
# Hash-pinned (Scorecard: Pinned-Dependencies). e2e.txt carries colorama
# explicitly — build/pytest need it only on Windows (os_name == "nt" /
# sys_platform == "win32"), and a Linux-generated lock would otherwise
# omit it and break the windows-latest leg under --require-hashes.
# See .github/requirements/e2e.in.
run: |
python -m pip install --require-hashes -r .github/requirements/pip.txt
python -m pip install --require-hashes -r .github/requirements/e2e.txt
- name: Run cross-OS e2e wiring harness
# conftest.py builds the wheel + clean venv internally; the outer env
+22 -1
View File
@@ -11,13 +11,34 @@ permissions:
jobs:
build:
runs-on: ubuntu-latest
# Job-level permissions REPLACE the top-level block rather than merge with
# it, so `contents: read` is restated here on purpose — dropping it would
# break actions/checkout. id-token/attestations are what the provenance
# attestation below needs (Scorecard: Signed-Releases).
permissions:
contents: read
id-token: write
attestations: write
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: "3.13"
- run: pip install build
# Hash-pinned tool install (Scorecard: Pinned-Dependencies).
- run: python -m pip install --require-hashes -r .github/requirements/build.txt
- run: python -m build
- name: Attest build provenance
# Signs a provenance statement binding these exact sdist/wheel digests to
# this workflow run, via the same keyless Sigstore/OIDC path as the
# release signing below. Runs after the artifacts exist and before they
# leave the job, so the attested digests are the published ones.
# NOTE: the bundle is deliberately NOT written into dist/ — the publish
# job feeds dist/* to gh-action-pypi-publish, which rejects any file that
# is not a distribution. See the report note on attaching provenance to
# the GitHub Release.
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
with:
subject-path: "dist/*"
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: dist
+4 -2
View File
@@ -27,9 +27,11 @@ jobs:
# 26.1.2). Upgrading removes the vulnerable version outright rather than
# suppressing it — and 26.1.2 also resolves CVE-2026-3219 / CVE-2026-6357,
# which is why those two stale --ignore-vuln entries are no longer needed.
# Both installs are hash-pinned (Scorecard: Pinned-Dependencies); pip.txt
# holds the >=26.1.2 floor the comment above requires.
- run: |
python -m pip install --upgrade pip
pip install pip-audit
python -m pip install --require-hashes -r .github/requirements/pip.txt
python -m pip install --require-hashes -r .github/requirements/audit.txt
- run: pip install -e .
- name: Pip audit
run: pip-audit --skip-editable