Skip to content

upgrade pip - #95

Merged
metzm merged 4 commits into
mainfrom
upgrade_pip_sbom
Sep 11, 2026
Merged

metzm merged 4 commits into
mainfrom
upgrade_pip_sbom

Conversation

@metzm

@metzm metzm commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor
  • upgrade pip in the Python venvs created for sbom check
  • do not pin the ubuntu version, use latest
  • sync sbom-vulnerability-scan.yml to third-party-licenses.yml

@metzm
metzm requested review from griembauer and mmacata September 10, 2026 15:39
@metzm

metzm commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor Author

Review from laguna:

Code Review: GitHub Workflows

Summary of Findings

I've analyzed all 9 workflow files in .github/workflows/. Here are the key issues found:


1. Pinned Versions (Commit Hashes)

Multiple files use pinned commit SHA hashes instead of version tags for actions. This goes against the stated goal of using latest available versions.

post-pr-reviews.yml

  • Line 23: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 - Should use @v8
  • Line 30: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0 - Should use @v1

sbom-vulnerability-scan.yml

  • Line 69: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 - Should use @v0.24 or @v1
  • Line 79: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 - Should use a version tag
  • Line 87: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 - Should use @v4
  • Line 126: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 - Duplicate of line 69
  • Line 136: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 - Duplicate
  • Line 147: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 - Duplicate

third-party-licenses.yml

  • Line 30: actions/checkout@v4 - Outdated, should be @v7
  • Line 127: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 - Pinned SHA
  • Line 174: actions/checkout@v4 - Duplicate, should be @v7
  • Line 177: actions/download-artifact@v4 - Outdated, should be @v4 (actually v4 is latest for this action)
  • Line 160: actions/upload-release-asset@v1 - Deprecated action, should use softprops/action-gh-release

linting.yml

  • Line 208: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - Pinned SHA (should use @v7)
  • Line 214: super-linter/super-linter/slim@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 - Pinned SHA (should use @v8)

2. Pinned Python Tool Versions

linting.yml - Input Defaults for Python Tools

The workflow pins specific versions for linting tools via input defaults:

Tool Default Version Line
black 26.1.0 Line 9
flake8 7.3.0 Line 13
pylint 4.0.4 Line 17
ruff 0.15.0 Line 21

These should be removed to allow latest versions.


3. Python venv Usage Analysis

Correct Usage

sbom-vulnerability-scan.yml - Lines 102-104, 115-117, 122:

python -m venv .sbom_venv
source .sbom_venv/bin/activate
pip install --upgrade pip --quiet

✅ Uses python -m venv correctly

third-party-licenses.yml - Lines 87-89, 104-106:

python -m venv .license-venv
source .license-venv/bin/activate
pip install --upgrade pip pip-licenses --quiet

✅ Uses python -m venv correctly

Issues Found

third-party-licenses.yml - Line 122:

.sbom_venv/bin/pip install --upgrade "pip>=26.1.2"

⚠️ Pins pip to minimum version >=26.1.2 - should just upgrade to latest


4. Ubuntu Runner Version

All files use ubuntu-latest ✅ - No issues found.


5. pip Upgrade Analysis

All Python-related workflows correctly upgrade pip:

  • linting.yml: Lines 100, 117, 147, 170 use python -m pip install --upgrade pip ✅
  • sbom-vulnerability-scan.yml: Lines 104, 117, 122 upgrade pip ✅
  • third-party-licenses.yml: Lines 89, 106 upgrade pip ✅

Recommendations

  1. Replace all commit SHA hashes with version tags for actions that support them
  2. Remove pinned Python tool version defaults in linting.yml inputs
  3. Remove pip version pinning in sbom-vulnerability-scan.yml line 122
  4. Update actions/checkout@v4 to @v7 in third-party-licenses.yml
  5. Replace deprecated actions/upload-release-asset@v1 with softprops/action-gh-release

Comment thread .github/workflows/sbom-vulnerability-scan.yml
Comment thread .github/workflows/third-party-licenses.yml
@metzm

metzm commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Any opinion on the

Recommendations

  1. Replace all commit SHA hashes with version tags for actions that support them
  2. Remove pinned Python tool version defaults in linting.yml inputs
  3. Remove pip version pinning in sbom-vulnerability-scan.yml line 122
  4. Update actions/checkout@v4 to @v7 in third-party-licenses.yml
  5. Replace deprecated actions/upload-release-asset@v1 with softprops/action-gh-release

?

@anikaweinmann

Copy link
Copy Markdown
Member

Any opinion on the

Recommendations

1. Replace all commit SHA hashes with version tags for actions that support them

2. Remove pinned Python tool version defaults in linting.yml inputs

3. Remove pip version pinning in sbom-vulnerability-scan.yml line 122

4. Update actions/checkout@v4 to @v7 in third-party-licenses.yml

5. Replace deprecated actions/upload-release-asset@v1 with softprops/action-gh-release

?

@metzm feel free to adjust the workflows for anything except for 2.
In the linting.yml, we intentionally pinned the Python tool versions, so that a Repo can pin the versions (e.g by using a version of the linting.yml) and have not every day new linting errors.

@metzm
metzm merged commit a9cfdec into main Sep 11, 2026
1 check passed
@metzm
metzm deleted the upgrade_pip_sbom branch September 11, 2026 09:18
@mmacata

mmacata commented Sep 15, 2026

Copy link
Copy Markdown
Member

@metzm also 1. is not recommended as it is a floating tag instead of a fixed version. It is explicitely recommended by renovate https://docs.renovatebot.com/docker/#digest-pinning (I will revert this in a separate MR).
And for 5. - it would have been good to have this in a separeate MR as a testing is needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants