upgrade pip - #95
upgrade pip#95
Conversation
|
Review from laguna: Code Review: GitHub WorkflowsSummary of FindingsI've analyzed all 9 workflow files in 1. Pinned Versions (Commit Hashes)Multiple files use pinned commit SHA hashes instead of version tags for actions. This goes against the stated goal of using latest available versions.
|
| Tool | Default Version | Line |
|---|---|---|
| black | 26.1.0 | Line 9 |
| flake8 | 7.3.0 | Line 13 |
| pylint | 4.0.4 | Line 17 |
| ruff | 0.15.0 | Line 21 |
These should be removed to allow latest versions.
3. Python venv Usage Analysis
Correct Usage
sbom-vulnerability-scan.yml - Lines 102-104, 115-117, 122:
python -m venv .sbom_venv
source .sbom_venv/bin/activate
pip install --upgrade pip --quiet✅ Uses python -m venv correctly
third-party-licenses.yml - Lines 87-89, 104-106:
python -m venv .license-venv
source .license-venv/bin/activate
pip install --upgrade pip pip-licenses --quiet✅ Uses python -m venv correctly
Issues Found
third-party-licenses.yml - Line 122:
.sbom_venv/bin/pip install --upgrade "pip>=26.1.2">=26.1.2 - should just upgrade to latest
4. Ubuntu Runner Version
All files use ubuntu-latest ✅ - No issues found.
5. pip Upgrade Analysis
All Python-related workflows correctly upgrade pip:
linting.yml: Lines 100, 117, 147, 170 usepython -m pip install --upgrade pip✅sbom-vulnerability-scan.yml: Lines 104, 117, 122 upgrade pip ✅third-party-licenses.yml: Lines 89, 106 upgrade pip ✅
Recommendations
- Replace all commit SHA hashes with version tags for actions that support them
- Remove pinned Python tool version defaults in
linting.ymlinputs - Remove pip version pinning in
sbom-vulnerability-scan.ymlline 122 - Update
actions/checkout@v4to@v7inthird-party-licenses.yml - Replace deprecated
actions/upload-release-asset@v1withsoftprops/action-gh-release
|
Any opinion on the Recommendations
? |
@metzm feel free to adjust the workflows for anything except for 2. |
|
@metzm also 1. is not recommended as it is a floating tag instead of a fixed version. It is explicitely recommended by renovate https://docs.renovatebot.com/docker/#digest-pinning (I will revert this in a separate MR). |
sbom-vulnerability-scan.ymltothird-party-licenses.yml