From 7824ad80706c9423432f885547fd25285f80ad9b Mon Sep 17 00:00:00 2001 From: Markus Metz Date: Thu, 10 Sep 2026 17:37:19 +0200 Subject: [PATCH 1/4] upgrade pip --- .github/workflows/sbom-vulnerability-scan.yml | 24 +++++++++++-------- .github/workflows/third-party-licenses.yml | 4 ++-- 2 files changed, 16 insertions(+), 12 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 1db1649..7ec5569 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -38,7 +38,7 @@ on: jobs: sbom-vulnerability-scan: - runs-on: ubuntu-26.04 + runs-on: ubuntu-latest steps: - name: Validate inputs @@ -99,29 +99,33 @@ jobs: - name: Create Python environment from requirements if: inputs.requirements != '' run: | - python -m venv .venv + python -m venv .sbom_venv + source .sbom-venv/bin/activate + pip install --upgrade pip --quiet if grep -qi '^gdal' "${{ inputs.requirements }}"; then echo "GDAL==$(gdal-config --version).*" > /tmp/constraints.txt - .venv/bin/pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt + pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt else - .venv/bin/pip install -r "${{ inputs.requirements }}" + pip install -r "${{ inputs.requirements }}" fi - name: Create Python environment from pyproject if: inputs.pyproject != '' run: | - python -m venv .venv - .venv/bin/pip install . + python -m venv .sbom_venv + source .sbom-venv/bin/activate + pip install --upgrade pip --quiet + pip install . - name: Ensure pip version if: inputs.requirements != '' || inputs.pyproject != '' - run: .venv/bin/pip install --upgrade "pip>=26.1.2" + run: .sbom_venv/bin/pip install --upgrade "pip>=26.1.2" - name: Generate SBOM from Python environment if: inputs.requirements != '' || inputs.pyproject != '' uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 with: - path: .venv + path: .sbom_venv artifact-name: python.cyclonedx.json output-file: python.cyclonedx.json format: cyclonedx-json @@ -131,10 +135,10 @@ jobs: id: python-vulnerability-scan uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 with: - # Scan the .venv directly instead of the generated SBOM because + # Scan the .sbom_venv directly instead of the generated SBOM because # the SBOM scan produced empty SARIF artifact locations, while # the direct .venv scan provides valid locations for GitHub Code Scanning. - path: .venv + path: .sbom_venv fail-build: ${{ inputs.fail-build }} output-format: sarif diff --git a/.github/workflows/third-party-licenses.yml b/.github/workflows/third-party-licenses.yml index fee692d..90d4b27 100644 --- a/.github/workflows/third-party-licenses.yml +++ b/.github/workflows/third-party-licenses.yml @@ -24,7 +24,7 @@ on: jobs: generate: name: Generate THIRD_PARTY_LICENSES.json - runs-on: ubuntu-26.04 + runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v4 @@ -167,7 +167,7 @@ jobs: asset_content_type: application/json license-scan: - runs-on: ubuntu-26.04 + runs-on: ubuntu-latest needs: generate continue-on-error: true steps: From f72d6cce139aee550785a17d23c6a4f5c453ce18 Mon Sep 17 00:00:00 2001 From: Markus Metz Date: Thu, 10 Sep 2026 18:14:49 +0200 Subject: [PATCH 2/4] fix python venv paths --- .github/workflows/sbom-vulnerability-scan.yml | 6 +++--- .github/workflows/third-party-licenses.yml | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 7ec5569..058ecba 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -100,7 +100,7 @@ jobs: if: inputs.requirements != '' run: | python -m venv .sbom_venv - source .sbom-venv/bin/activate + source .sbom_venv/bin/activate pip install --upgrade pip --quiet if grep -qi '^gdal' "${{ inputs.requirements }}"; then echo "GDAL==$(gdal-config --version).*" > /tmp/constraints.txt @@ -113,7 +113,7 @@ jobs: if: inputs.pyproject != '' run: | python -m venv .sbom_venv - source .sbom-venv/bin/activate + source .sbom_venv/bin/activate pip install --upgrade pip --quiet pip install . @@ -137,7 +137,7 @@ jobs: with: # Scan the .sbom_venv directly instead of the generated SBOM because # the SBOM scan produced empty SARIF artifact locations, while - # the direct .venv scan provides valid locations for GitHub Code Scanning. + # the direct .sbom_venv scan provides valid locations for GitHub Code Scanning. path: .sbom_venv fail-build: ${{ inputs.fail-build }} output-format: sarif diff --git a/.github/workflows/third-party-licenses.yml b/.github/workflows/third-party-licenses.yml index 90d4b27..ce41af9 100644 --- a/.github/workflows/third-party-licenses.yml +++ b/.github/workflows/third-party-licenses.yml @@ -89,9 +89,9 @@ jobs: pip install --upgrade pip pip-licenses --quiet if grep -qi '^gdal' "${{ inputs.requirements }}"; then echo "GDAL==$(gdal-config --version).*" > /tmp/constraints.txt - .venv/bin/pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt + pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt else - .venv/bin/pip install -r "${{ inputs.requirements }}" + pip install -r "${{ inputs.requirements }}" fi pip-licenses --from=mixed --with-authors --with-urls --with-license-file --format=json --output-file=THIRD_PARTY_LICENSES.json From 08ca9b97796cfac38580a39f594c587dc7a640d2 Mon Sep 17 00:00:00 2001 From: Markus Metz Date: Fri, 11 Sep 2026 09:35:15 +0200 Subject: [PATCH 3/4] pip version has no effect --- .github/workflows/sbom-vulnerability-scan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index 058ecba..d96a649 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -119,7 +119,7 @@ jobs: - name: Ensure pip version if: inputs.requirements != '' || inputs.pyproject != '' - run: .sbom_venv/bin/pip install --upgrade "pip>=26.1.2" + run: .sbom_venv/bin/pip install --upgrade pip - name: Generate SBOM from Python environment if: inputs.requirements != '' || inputs.pyproject != '' From f9705fbb991374231ff8b8693f389f590433db36 Mon Sep 17 00:00:00 2001 From: Markus Metz Date: Fri, 11 Sep 2026 11:15:58 +0200 Subject: [PATCH 4/4] Replace all commit SHA hashes with version tags --- .github/workflows/linting.yml | 4 ++-- .github/workflows/post-pr-reviews.yml | 4 ++-- .github/workflows/sbom-vulnerability-scan.yml | 12 ++++++------ .github/workflows/third-party-licenses.yml | 10 +++++----- 4 files changed, 15 insertions(+), 15 deletions(-) diff --git a/.github/workflows/linting.yml b/.github/workflows/linting.yml index ddef776..a7bc05a 100644 --- a/.github/workflows/linting.yml +++ b/.github/workflows/linting.yml @@ -205,13 +205,13 @@ jobs: # To report GitHub Actions status checks statuses: write steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7 with: # super-linter needs the full git history to get the # list of files that changed across commits fetch-depth: 0 - name: Lint code base - uses: super-linter/super-linter/slim@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0 + uses: super-linter/super-linter/slim@v8 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} DEFAULT_BRANCH: main diff --git a/.github/workflows/post-pr-reviews.yml b/.github/workflows/post-pr-reviews.yml index 41fb11e..aa7e445 100644 --- a/.github/workflows/post-pr-reviews.yml +++ b/.github/workflows/post-pr-reviews.yml @@ -20,14 +20,14 @@ jobs: steps: - name: Create a .git directory needed by reviewdog run: git init - - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + - uses: actions/download-artifact@v8 id: diff continue-on-error: true with: name: diff github-token: ${{ github.token }} run-id: ${{github.event.workflow_run.id }} - - uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0 + - uses: reviewdog/action-setup@v1 - name: Check what tools have suggestions to post # Using this pattern to have expected file names explicitly named id: tools diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml index d96a649..c6a11ce 100644 --- a/.github/workflows/sbom-vulnerability-scan.yml +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -66,7 +66,7 @@ jobs: - name: Generate SBOM from Docker image if: inputs.dockerfile != '' - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + uses: anchore/sbom-action@v1 with: image: localbuild/testimage:latest artifact-name: docker.cyclonedx.json @@ -76,7 +76,7 @@ jobs: - name: Scan Docker SBOM for vulnerabilities if: inputs.dockerfile != '' id: docker-vulnerability-scan - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + uses: anchore/scan-action@v7 with: sbom: docker.cyclonedx.json fail-build: ${{ inputs.fail-build }} @@ -84,7 +84,7 @@ jobs: - name: Upload Docker vulnerability results to GitHub Security if: inputs.dockerfile != '' - uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }} category: grype-docker @@ -123,7 +123,7 @@ jobs: - name: Generate SBOM from Python environment if: inputs.requirements != '' || inputs.pyproject != '' - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + uses: anchore/sbom-action@v1 with: path: .sbom_venv artifact-name: python.cyclonedx.json @@ -133,7 +133,7 @@ jobs: - name: Scan Python environment for vulnerabilities if: inputs.requirements != '' || inputs.pyproject != '' id: python-vulnerability-scan - uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 + uses: anchore/scan-action@v7 with: # Scan the .sbom_venv directly instead of the generated SBOM because # the SBOM scan produced empty SARIF artifact locations, while @@ -144,7 +144,7 @@ jobs: - name: Upload Python vulnerability results to GitHub Security if: inputs.requirements != '' || inputs.pyproject != '' - uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: ${{ steps.python-vulnerability-scan.outputs.sarif }} category: grype-python diff --git a/.github/workflows/third-party-licenses.yml b/.github/workflows/third-party-licenses.yml index ce41af9..355f9a8 100644 --- a/.github/workflows/third-party-licenses.yml +++ b/.github/workflows/third-party-licenses.yml @@ -27,7 +27,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Validate inputs id: validate @@ -124,7 +124,7 @@ jobs: " - name: Generate SBOM from Docker image if: inputs.dockerfile != '' - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + uses: anchore/sbom-action@v1 with: image: license-scan-image format: syft-json @@ -157,7 +157,7 @@ jobs: path: THIRD_PARTY_LICENSES.json - name: Upload as release asset - uses: actions/upload-release-asset@v1 + uses: softprops/action-gh-release@v3 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: @@ -171,10 +171,10 @@ jobs: needs: generate continue-on-error: true steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Download THIRD_PARTY_LICENSES.json - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: name: third-party-license path: .