Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/linting.yml
Original file line number Diff line number Diff line change
Expand Up @@ -205,13 +205,13 @@ jobs:
# To report GitHub Actions status checks
statuses: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/checkout@v7
with:
# super-linter needs the full git history to get the
# list of files that changed across commits
fetch-depth: 0
- name: Lint code base
uses: super-linter/super-linter/slim@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0
uses: super-linter/super-linter/slim@v8
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
DEFAULT_BRANCH: main
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/post-pr-reviews.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,14 +20,14 @@ jobs:
steps:
- name: Create a .git directory needed by reviewdog
run: git init
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
- uses: actions/download-artifact@v8
id: diff
continue-on-error: true
with:
name: diff
github-token: ${{ github.token }}
run-id: ${{github.event.workflow_run.id }}
- uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0
- uses: reviewdog/action-setup@v1
- name: Check what tools have suggestions to post
# Using this pattern to have expected file names explicitly named
id: tools
Expand Down
38 changes: 21 additions & 17 deletions .github/workflows/sbom-vulnerability-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ on:

jobs:
sbom-vulnerability-scan:
runs-on: ubuntu-26.04
Comment thread
metzm marked this conversation as resolved.
runs-on: ubuntu-latest

steps:
- name: Validate inputs
Expand Down Expand Up @@ -66,7 +66,7 @@ jobs:

- name: Generate SBOM from Docker image
if: inputs.dockerfile != ''
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
uses: anchore/sbom-action@v1
with:
image: localbuild/testimage:latest
artifact-name: docker.cyclonedx.json
Expand All @@ -76,15 +76,15 @@ jobs:
- name: Scan Docker SBOM for vulnerabilities
if: inputs.dockerfile != ''
id: docker-vulnerability-scan
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2
uses: anchore/scan-action@v7
with:
sbom: docker.cyclonedx.json
fail-build: ${{ inputs.fail-build }}
output-format: sarif

- name: Upload Docker vulnerability results to GitHub Security
if: inputs.dockerfile != ''
uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0
uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }}
category: grype-docker
Expand All @@ -99,48 +99,52 @@ jobs:
- name: Create Python environment from requirements
if: inputs.requirements != ''
run: |
python -m venv .venv
python -m venv .sbom_venv
source .sbom_venv/bin/activate
pip install --upgrade pip --quiet
if grep -qi '^gdal' "${{ inputs.requirements }}"; then
echo "GDAL==$(gdal-config --version).*" > /tmp/constraints.txt
.venv/bin/pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt
pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt
else
.venv/bin/pip install -r "${{ inputs.requirements }}"
pip install -r "${{ inputs.requirements }}"
fi

- name: Create Python environment from pyproject
if: inputs.pyproject != ''
run: |
python -m venv .venv
.venv/bin/pip install .
python -m venv .sbom_venv
source .sbom_venv/bin/activate
pip install --upgrade pip --quiet
pip install .

- name: Ensure pip version
if: inputs.requirements != '' || inputs.pyproject != ''
run: .venv/bin/pip install --upgrade "pip>=26.1.2"
run: .sbom_venv/bin/pip install --upgrade pip

- name: Generate SBOM from Python environment
if: inputs.requirements != '' || inputs.pyproject != ''
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
uses: anchore/sbom-action@v1
with:
path: .venv
path: .sbom_venv
artifact-name: python.cyclonedx.json
output-file: python.cyclonedx.json
format: cyclonedx-json

- name: Scan Python environment for vulnerabilities
if: inputs.requirements != '' || inputs.pyproject != ''
id: python-vulnerability-scan
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2
uses: anchore/scan-action@v7
with:
# Scan the .venv directly instead of the generated SBOM because
# Scan the .sbom_venv directly instead of the generated SBOM because
# the SBOM scan produced empty SARIF artifact locations, while
# the direct .venv scan provides valid locations for GitHub Code Scanning.
path: .venv
# the direct .sbom_venv scan provides valid locations for GitHub Code Scanning.
path: .sbom_venv
fail-build: ${{ inputs.fail-build }}
output-format: sarif

- name: Upload Python vulnerability results to GitHub Security
if: inputs.requirements != '' || inputs.pyproject != ''
uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0
uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: ${{ steps.python-vulnerability-scan.outputs.sarif }}
category: grype-python
18 changes: 9 additions & 9 deletions .github/workflows/third-party-licenses.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,10 +24,10 @@ on:
jobs:
generate:
name: Generate THIRD_PARTY_LICENSES.json
runs-on: ubuntu-26.04
runs-on: ubuntu-latest
Comment thread
anikaweinmann marked this conversation as resolved.
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v7

- name: Validate inputs
id: validate
Expand Down Expand Up @@ -89,9 +89,9 @@ jobs:
pip install --upgrade pip pip-licenses --quiet
if grep -qi '^gdal' "${{ inputs.requirements }}"; then
echo "GDAL==$(gdal-config --version).*" > /tmp/constraints.txt
.venv/bin/pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt
pip install -r "${{ inputs.requirements }}" -c /tmp/constraints.txt
else
.venv/bin/pip install -r "${{ inputs.requirements }}"
pip install -r "${{ inputs.requirements }}"
fi
pip-licenses --from=mixed --with-authors --with-urls --with-license-file --format=json --output-file=THIRD_PARTY_LICENSES.json

Expand Down Expand Up @@ -124,7 +124,7 @@ jobs:
"
- name: Generate SBOM from Docker image
if: inputs.dockerfile != ''
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
uses: anchore/sbom-action@v1
with:
image: license-scan-image
format: syft-json
Expand Down Expand Up @@ -157,7 +157,7 @@ jobs:
path: THIRD_PARTY_LICENSES.json

- name: Upload as release asset
uses: actions/upload-release-asset@v1
uses: softprops/action-gh-release@v3
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
Expand All @@ -167,14 +167,14 @@ jobs:
asset_content_type: application/json

license-scan:
runs-on: ubuntu-26.04
runs-on: ubuntu-latest
needs: generate
continue-on-error: true
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- name: Download THIRD_PARTY_LICENSES.json
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
name: third-party-license
path: .
Expand Down
Loading