ci: OSSF scorecard hardening (DPLAN-0243) — hash-pin all standalone workflow pip installs via .github/requirements/ locks (pip/lint/build/e2e/audit, pip-compile --generate-hashes, 11/11 target-env closure verified incl. Windows colorama marker fix) + provenance attestation on publish (attest-build-provenance v4.1.1 SHA-pinned, id-token+attestations perms) + dependabot pip ecosystem for the new locks. Editable -e . installs untouched byte-identical. 5/5 fresh-venv --require-hashes installs green, 5/5 YAML parse, pinned ruff matches repo lint. First SSH-signed commit (repo config wired this session).
This commit is contained in:
@@ -20,7 +20,9 @@ jobs:
|
||||
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: pip install ruff
|
||||
# Hash-pinned tool install (Scorecard: Pinned-Dependencies). Pins ruff to
|
||||
# the version this lint gate is known-green against; see .github/requirements/lint.in.
|
||||
- run: python -m pip install --require-hashes -r .github/requirements/lint.txt
|
||||
- run: ruff check src/ tests/
|
||||
- run: ruff format --check src/ tests/
|
||||
|
||||
@@ -36,7 +38,7 @@ jobs:
|
||||
with:
|
||||
python-version: ${{ matrix.python-version }}
|
||||
- run: |
|
||||
python -m pip install --upgrade pip
|
||||
python -m pip install --require-hashes -r .github/requirements/pip.txt
|
||||
pip install -e ".[dev]"
|
||||
# tests/e2e build a wheel + clean venv per the dedicated e2e-wheel.yml
|
||||
# workflow — they are not part of the fast unit lane.
|
||||
@@ -57,7 +59,7 @@ jobs:
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: |
|
||||
python -m pip install --upgrade pip
|
||||
python -m pip install --require-hashes -r .github/requirements/pip.txt
|
||||
# Install the `memory` extra (numpy/chromadb/fastembed) alongside dev:
|
||||
# the diagnostics standard runs pyright over every branch, and memory's
|
||||
# handlers import chromadb/numpy. Without these deps installed, pyright
|
||||
@@ -79,7 +81,7 @@ jobs:
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: |
|
||||
python -m pip install --upgrade pip
|
||||
python -m pip install --require-hashes -r .github/requirements/pip.txt
|
||||
pip install -e ".[dev]"
|
||||
- run: coverage run -m pytest --rootdir=. --ignore=tests/e2e
|
||||
- run: coverage xml
|
||||
|
||||
@@ -47,7 +47,14 @@ jobs:
|
||||
python-version: ${{ matrix.python-version }}
|
||||
|
||||
- name: Install build tooling
|
||||
run: python -m pip install --upgrade pip build pytest
|
||||
# Hash-pinned (Scorecard: Pinned-Dependencies). e2e.txt carries colorama
|
||||
# explicitly — build/pytest need it only on Windows (os_name == "nt" /
|
||||
# sys_platform == "win32"), and a Linux-generated lock would otherwise
|
||||
# omit it and break the windows-latest leg under --require-hashes.
|
||||
# See .github/requirements/e2e.in.
|
||||
run: |
|
||||
python -m pip install --require-hashes -r .github/requirements/pip.txt
|
||||
python -m pip install --require-hashes -r .github/requirements/e2e.txt
|
||||
|
||||
- name: Run cross-OS e2e wiring harness
|
||||
# conftest.py builds the wheel + clean venv internally; the outer env
|
||||
|
||||
@@ -11,13 +11,34 @@ permissions:
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
# Job-level permissions REPLACE the top-level block rather than merge with
|
||||
# it, so `contents: read` is restated here on purpose — dropping it would
|
||||
# break actions/checkout. id-token/attestations are what the provenance
|
||||
# attestation below needs (Scorecard: Signed-Releases).
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
attestations: write
|
||||
steps:
|
||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
||||
with:
|
||||
python-version: "3.13"
|
||||
- run: pip install build
|
||||
# Hash-pinned tool install (Scorecard: Pinned-Dependencies).
|
||||
- run: python -m pip install --require-hashes -r .github/requirements/build.txt
|
||||
- run: python -m build
|
||||
- name: Attest build provenance
|
||||
# Signs a provenance statement binding these exact sdist/wheel digests to
|
||||
# this workflow run, via the same keyless Sigstore/OIDC path as the
|
||||
# release signing below. Runs after the artifacts exist and before they
|
||||
# leave the job, so the attested digests are the published ones.
|
||||
# NOTE: the bundle is deliberately NOT written into dist/ — the publish
|
||||
# job feeds dist/* to gh-action-pypi-publish, which rejects any file that
|
||||
# is not a distribution. See the report note on attaching provenance to
|
||||
# the GitHub Release.
|
||||
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
|
||||
with:
|
||||
subject-path: "dist/*"
|
||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: dist
|
||||
|
||||
@@ -27,9 +27,11 @@ jobs:
|
||||
# 26.1.2). Upgrading removes the vulnerable version outright rather than
|
||||
# suppressing it — and 26.1.2 also resolves CVE-2026-3219 / CVE-2026-6357,
|
||||
# which is why those two stale --ignore-vuln entries are no longer needed.
|
||||
# Both installs are hash-pinned (Scorecard: Pinned-Dependencies); pip.txt
|
||||
# holds the >=26.1.2 floor the comment above requires.
|
||||
- run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install pip-audit
|
||||
python -m pip install --require-hashes -r .github/requirements/pip.txt
|
||||
python -m pip install --require-hashes -r .github/requirements/audit.txt
|
||||
- run: pip install -e .
|
||||
- name: Pip audit
|
||||
run: pip-audit --skip-editable
|
||||
|
||||
Reference in New Issue
Block a user