Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/documentation_builder.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ jobs:
if [[ ${{github.event_name}} == "release" ]]
then
echo "Deploy doc for release: ${{ github.event.release.tag_name }}"
mike deploy --push --update-aliases ${{ github.event.release.tag_name }} latest || mike deploy --push ${{ github.event.release.tag_name }}
mike deploy --push --alias-type=redirect --update-aliases ${{ github.event.release.tag_name }} latest || mike deploy --push ${{ github.event.release.tag_name }}
mike set-default --push latest
else
echo "Deploy doc for main"
Expand Down
14 changes: 5 additions & 9 deletions .github/workflows/validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,21 +28,19 @@ jobs:
- name: Install Formatting
run: |
python -m pip install --upgrade pip
pip install flake8
pip install isort
pip install ruff

- name: Check Formatting
run: |
flake8 onecode tests/unit/ --exclude=__init__.py,tests/data --max-line-length=100
isort . -m3 --thirdparty . --check-only --skip tests/data
ruff check onecode tests

testing:
name: Check Testing
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]
python: ["3.10", "3.11", "3.12", "3.13", "3.14"]
python: ["3.11", "3.12", "3.13", "3.14"]
runs-on: ${{ matrix.os }}
timeout-minutes: 30
steps:
Expand All @@ -60,12 +58,11 @@ jobs:
- name: Check Testing Linux/MacOS
if: ${{ matrix.os != 'windows-latest' }}
run: |
ONECODE_DO_TYPECHECK=1 python -m pytest tests -n auto
python -m pytest tests -n auto

- name: Check Testing Windows
if: ${{ matrix.os == 'windows-latest' }}
run: |
set ONECODE_DO_TYPECHECK=1
python -m pytest tests

coverage:
Expand All @@ -92,12 +89,11 @@ jobs:
- name: Test coverage Linux
if: ${{ matrix.os == 'ubuntu-latest' }}
run: |
ONECODE_DO_TYPECHECK=1 coverage run -m pytest tests --cov=./ --cov-report=xml
coverage run -m pytest tests --cov=./ --cov-report=xml

- name: Test coverage Windows
if: ${{ matrix.os == 'windows-latest' }}
run: |
set ONECODE_DO_TYPECHECK=1
coverage run -m pytest tests --cov=./ --cov-report=xml

- name: Upload coverage reports to Codecov
Expand Down
117 changes: 117 additions & 0 deletions .github/workflows/vulnerability_monitor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,117 @@
name: Vulnerability monitor

on:
pull_request:
branches:
- "*.x"
schedule:
- cron: "0 5 * * *"
workflow_dispatch:
inputs:
backfill:
description: Attach SBOMs to releases that do not have one
type: boolean
default: false
release:
types: [published]

jobs:
ranges:
if: github.event_name == 'pull_request'
name: Dependency ranges
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"

- name: Install packaging
run: python -m pip install packaging

- name: Compare ranges with OSV
continue-on-error: true
run: python scripts/cra/scan_ranges.py

releases:
if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch'
name: Release SBOMs
runs-on: ubuntu-latest
permissions:
contents: read
issues: write
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"

- name: Install packaging
run: python -m pip install packaging

- name: Rescan release SBOMs
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
CRA_NOTIFY: theweaklink
run: python scripts/cra/monitor_releases.py

backfill:
if: github.event_name == 'workflow_dispatch' && inputs.backfill
name: Backfill release SBOMs
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"

- name: Attach missing SBOMs
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: python scripts/cra/backfill_sboms.py

sbom:
if: github.event_name == 'release'
name: Publish release SBOM
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Checkout SBOM scripts
uses: actions/checkout@v4
with:
path: workflow-src

- name: Checkout release
uses: actions/checkout@v4
with:
ref: ${{ github.event.release.tag_name }}
path: release-src

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"

- name: Generate CycloneDX
run: |
python workflow-src/scripts/cra/make_release_sbom.py \
--pyproject release-src/pyproject.toml \
--out-dir sbom

- name: Upload CycloneDX
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
gh release upload "${{ github.event.release.tag_name }}" sbom/*.cdx.json \
--clobber \
--repo deeplime-io/onecode
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -217,6 +217,10 @@ for your patience on that one.

## :wave: Getting Help

Security reports go through [private vulnerability reporting](https://github.com/deeplime-io/onecode/security/advisories/new). See [SECURITY.md](SECURITY.md). Security fixes are published for the maintained `1.x` line.

Issues labeled [`cra-vulnerability`](https://github.com/deeplime-io/onecode/issues?q=is%3Aissue+is%3Aopen+label%3Acra-vulnerability) come from the dependency scan. They are not the place to disclose a new flaw.

If you are a OneCode customer, you may directly email our support team.
Feel free as well to browse the [GitHub Issues](https://github.com/deeplime-io/onecode/issues)
and reach out to the community by posting bug reports, questions and suggestions.
19 changes: 19 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Security

OneCode is open source under the MIT license and is maintained by DeepLime, not as a community project. Security fixes are published for the maintained `1.x` line.

## Reporting a vulnerability

Report a vulnerability in OneCode through [GitHub private vulnerability reporting](https://github.com/deeplime-io/onecode/security/advisories/new).

Do not open a public issue, and do not file the report in the GitHub Advisory Database. A public report discloses the problem before a fix is available.

DeepLime acknowledges the report, prepares a fix on the maintained line, and releases it. After that release, DeepLime publishes a GitHub Security Advisory. That publication is what enters the public advisory database and OSV.

If the vulnerability is actively exploited, DeepLime also reports it through the CRA single reporting platform operated with ENISA. That duty applies from 11 September 2026. An early warning is due within 24 hours of learning that exploitation is underway, followed by the fuller notification the platform requires.

## Dependency monitor

Issues labeled [`cra-vulnerability`](https://github.com/deeplime-io/onecode/issues?q=is%3Aissue+is%3Aopen+label%3Acra-vulnerability) are opened by the scheduled scan of release SBOMs. They record published advisories that intersect a released dependency range. They are not the channel for reporting a new vulnerability in OneCode.

Each published GitHub release carries a CycloneDX file named `onecode-<version>.cdx.json`.
14 changes: 12 additions & 2 deletions codecov.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,13 @@
coverage:
status:
project:
default:
target: 95%
patch:
default:
target: 95%

ignore:
- "tests/**/*"
- "tests/*"
- "tests"
- "onecode/pycg"
- "scripts"
30 changes: 30 additions & 0 deletions docs/changelogs/1.3.0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
## Bug Fixes

:octicons-issue-opened-24: Issue Ref | :fontawesome-solid-thumbtack: Summary | :material-message-text: Description
-|-|-


## Enhancements

:octicons-issue-opened-24: Issue Ref | :fontawesome-solid-thumbtack: Summary | :material-message-text: Description
-|-|-
[No Ref] | Meta-data of input element to match expections from OneCode cloud | `metadata()` to be consistent with OneCode Cloud usage.
[No Ref] | Remove the `typeguard` dependency | `is_type` now checks values with the standard library. Every item of a list is checked.
[No Ref] | Raise minimum dependency versions | PyArrow, pydash, pytest, and Material for MkDocs now start at versions that include published security fixes. Other runtime, test, and docs dependencies move off release lines that predate the supported Python range.
[No Ref] | Vendor the call-graph library | The `onecode-pycg` dependency is removed. The call-graph code OneCode uses now lives in `onecode.pycg` under the Apache License 2.0.
[No Ref] | Check style with Ruff | Formatting CI uses Ruff instead of flake8 and isort.
[No Ref] | Publish a dependency SBOM and scan released versions | Each GitHub release carries a CycloneDX SBOM of the direct runtime dependency ranges. Pull requests report advisories that intersect those ranges, and a daily job updates one issue per affected release. Security reports go through private vulnerability reporting. See `SECURITY.md`.
[No Ref] | Lock the manifest with the operating system | Concurrent appends to the output manifest now use `filelock` (`fcntl` on Unix, `msvcrt` on Windows). The `flufl.lock` dependency is removed.


## New Features

:octicons-issue-opened-24: Issue Ref | :fontawesome-solid-thumbtack: Summary | :material-message-text: Description
-|-|-


## :warning: Breaking changes

Python 3.10 and older are no longer supported. OneCode now requires Python 3.11, 3.12, 3.13, or 3.14.

The `check_type` decorator and the `ONECODE_DO_TYPECHECK` environment variable are removed. `Env.ONECODE_DO_TYPECHECK` is no longer available, and Pydantic is no longer a developer dependency.
2 changes: 1 addition & 1 deletion docs/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,5 +5,5 @@
## Credits
Credits to all open-source libraries that helped build this project. Special thanks to:

- [PyCG](https://github.com/vitsalis/PyCG) and its contributors for making the Call Graph algos essential to the OneCode mechanism.
- [PyCG](https://github.com/vitsalis/PyCG) (Vitalis Salis) and its contributors for the call-graph algorithms used by OneCode. The DeepLime fork is vendored in `onecode.pycg` under the Apache License 2.0. See `onecode/pycg/LICENCE`. The rest of OneCode remains MIT.
- [Geode Solutions](https://geode-solutions.com/) and [Spotlight Earth](https://spotlight-earth.com/) for testing the open-source library and providing invaluable feedback.
2 changes: 1 addition & 1 deletion mkdocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@ nav:
- Project: reference/base/project.md
- FAQs: faq.md
- Changelogs:
- 1.3.0: changelogs/1.3.0.md
- 1.2.2: changelogs/1.2.2.md
- 1.2.1: changelogs/1.2.1.md
- 1.2.0: changelogs/1.2.0.md
Expand Down Expand Up @@ -69,7 +70,6 @@ plugins:
show_source: false
show_root_toc_entry: false
separate_signature: false
new_path_syntax: yes
filters:
- "^_"
- "^"
Expand Down
2 changes: 1 addition & 1 deletion onecode/__init__.py
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-FileCopyrightText: 2023-2024 DeepLime <contact@deeplime.io>
# SPDX-License-Identifier: MIT

__version__ = "1.2.2"
__version__ = "1.3.0.dev"


from .base import *
Expand Down
1 change: 0 additions & 1 deletion onecode/base/__init__.py
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
# SPDX-FileCopyrightText: 2023-2024 DeepLime <contact@deeplime.io>
# SPDX-License-Identifier: MIT

from .decorator import *
from .enums import *
from .logger import *
from .project import *
31 changes: 0 additions & 31 deletions onecode/base/decorator.py

This file was deleted.

Loading
Loading