diff --git a/.github/workflows/linting.yml b/.github/workflows/linting.yml index ddef776..a7bc05a 100644 --- a/.github/workflows/linting.yml +++ b/.github/workflows/linting.yml @@ -205,13 +205,13 @@ jobs: # To report GitHub Actions status checks statuses: write steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 with: # super-linter needs the full git history to get the # list of files that changed across commits fetch-depth: 0 - name: Lint code base - uses: super-linter/super-linter/slim@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 + uses: super-linter/super-linter/slim@v8 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main diff --git a/.github/workflows/post-pr-reviews.yml b/.github/workflows/post-pr-reviews.yml index 41fb11e..aa7e445 100644 --- a/.github/workflows/post-pr-reviews.yml +++ b/.github/workflows/post-pr-reviews.yml @@ -20,14 +20,14 @@ jobs: steps: - name: Create a .git directory needed by reviewdog run: git init - - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + - uses: actions/download-artifact@v8 id: diff continue-on-error: true with: name: diff github-token: ${{ github.token }} run-id: ${{github.event.workflow_run.id }} - - uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0 + - uses: reviewdog/action-setup@v1 - name: Check what tools have suggestions to post # Using this pattern to have expected file names explicitly named id: tools diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 1db1649..c6a11ce 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -38,7 +38,7 @@ on: jobs: sbom-vulnerability-scan: - runs-on: ubuntu-26.04 + runs-on: ubuntu-latest steps: - name: Validate inputs @@ -66,7 +66,7 @@ jobs: - name: Generate SBOM from Docker image if: inputs.dockerfile != '' - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + uses: anchore/sbom-action@v1 with: image: localbuild/testimage:latest artifact-name: docker.cyclonedx.json @@ -76,7 +76,7 @@ jobs: - name: Scan Docker SBOM for vulnerabilities if: inputs.dockerfile != '' id: docker-vulnerability-scan - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + uses: anchore/scan-action@v7 with: sbom: docker.cyclonedx.json fail-build: ${{ inputs.fail-build }} @@ -84,7 +84,7 @@ jobs: - name: Upload Docker vulnerability results to GitHub Security if: inputs.dockerfile != '' - uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }} category: grype-docker @@ -99,29 +99,33 @@ jobs: - name: Create Python environment from requirements if: inputs.requirements != '' run: | - python -m venv .venv + python -m venv .sbom_venv + source .sbom_venv/bin/activate + pip install --upgrade pip --quiet if grep -qi '^gdal' "${{ inputs.requirements }}"; then echo "GDAL==$(gdal-config --version).*" > /tmp/constraints.txt - .venv/bin/pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt + pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt else - .venv/bin/pip install -r "${{ inputs.requirements }}" + pip install -r "${{ inputs.requirements }}" fi - name: Create Python environment from pyproject if: inputs.pyproject != '' run: | - python -m venv .venv - .venv/bin/pip install . + python -m venv .sbom_venv + source .sbom_venv/bin/activate + pip install --upgrade pip --quiet + pip install . - name: Ensure pip version if: inputs.requirements != '' || inputs.pyproject != '' - run: .venv/bin/pip install --upgrade "pip>=26.1.2" + run: .sbom_venv/bin/pip install --upgrade pip - name: Generate SBOM from Python environment if: inputs.requirements != '' || inputs.pyproject != '' - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + uses: anchore/sbom-action@v1 with: - path: .venv + path: .sbom_venv artifact-name: python.cyclonedx.json output-file: python.cyclonedx.json format: cyclonedx-json @@ -129,18 +133,18 @@ jobs: - name: Scan Python environment for vulnerabilities if: inputs.requirements != '' || inputs.pyproject != '' id: python-vulnerability-scan - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + uses: anchore/scan-action@v7 with: - # Scan the .venv directly instead of the generated SBOM because + # Scan the .sbom_venv directly instead of the generated SBOM because # the SBOM scan produced empty SARIF artifact locations, while - # the direct .venv scan provides valid locations for GitHub Code Scanning. - path: .venv + # the direct .sbom_venv scan provides valid locations for GitHub Code Scanning. + path: .sbom_venv fail-build: ${{ inputs.fail-build }} output-format: sarif - name: Upload Python vulnerability results to GitHub Security if: inputs.requirements != '' || inputs.pyproject != '' - uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: ${{ steps.python-vulnerability-scan.outputs.sarif }} category: grype-python diff --git a/.github/workflows/third-party-licenses.yml b/.github/workflows/third-party-licenses.yml index fee692d..355f9a8 100644 --- a/.github/workflows/third-party-licenses.yml +++ b/.github/workflows/third-party-licenses.yml @@ -24,10 +24,10 @@ on: jobs: generate: name: Generate THIRD_PARTY_LICENSES.json - runs-on: ubuntu-26.04 + runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Validate inputs id: validate @@ -89,9 +89,9 @@ jobs: pip install --upgrade pip pip-licenses --quiet if grep -qi '^gdal' "${{ inputs.requirements }}"; then echo "GDAL==$(gdal-config --version).*" > /tmp/constraints.txt - .venv/bin/pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt + pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt else - .venv/bin/pip install -r "${{ inputs.requirements }}" + pip install -r "${{ inputs.requirements }}" fi pip-licenses --from=mixed --with-authors --with-urls --with-license-file --format=json --output-file=THIRD_PARTY_LICENSES.json @@ -124,7 +124,7 @@ jobs: " - name: Generate SBOM from Docker image if: inputs.dockerfile != '' - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + uses: anchore/sbom-action@v1 with: image: license-scan-image format: syft-json @@ -157,7 +157,7 @@ jobs: path: THIRD_PARTY_LICENSES.json - name: Upload as release asset - uses: actions/upload-release-asset@v1 + uses: softprops/action-gh-release@v3 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: @@ -167,14 +167,14 @@ jobs: asset_content_type: application/json license-scan: - runs-on: ubuntu-26.04 + runs-on: ubuntu-latest needs: generate continue-on-error: true steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Download THIRD_PARTY_LICENSES.json - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: third-party-license path: .