Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ jobs:
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
steps:
- name: Checkout repository
uses: actions/checkout@v7
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Check whether language exists
id: check-language
Expand Down Expand Up @@ -79,7 +79,7 @@ jobs:
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
if: steps.check-language.outputs.exists == 'true'
uses: github/codeql-action/init@v4
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
Expand Down Expand Up @@ -109,6 +109,6 @@ jobs:

- name: Perform CodeQL Analysis
if: steps.check-language.outputs.exists == 'true'
uses: github/codeql-action/analyze@v4
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
with:
category: "/language:${{matrix.language}}"
6 changes: 3 additions & 3 deletions .github/workflows/grass-manual.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ jobs:
name: build-grass-manual
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Creation of GRASS GIS addon manual
run: |
ADDON_NAME=$(echo ${GITHUB_REPOSITORY} | cut -d "/" -f 2)
Expand All @@ -20,7 +20,7 @@ jobs:
echo $ID
docker cp $ID:/src/build/docs/html public
- name: Upload Pages artifact
uses: actions/upload-pages-artifact@v5
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
with:
path: "public"

Expand All @@ -41,4 +41,4 @@ jobs:
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@v5
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1
6 changes: 3 additions & 3 deletions .github/workflows/grass-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,17 +16,17 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: add Dockerfile and test skript
run: |
( mkdir -p test-docker && cd test-docker && \
wget https://raw.githubusercontent.com/mundialis/github-workflows/main/grass-gis-test-docker/Dockerfile \
&& wget https://raw.githubusercontent.com/mundialis/github-workflows/main/grass-gis-test-docker/test.sh )
- name: Tests of GRASS GIS addon
id: docker_build
uses: docker/build-push-action@v7
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
push: false
tags: addon-tests:alpine
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/lint-workflows.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: cschleiden/actions-linter@v1
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0
with:
workflows: '[".github/workflows/*.yaml"]'
files: ".github/workflows/*.yaml"
12 changes: 6 additions & 6 deletions .github/workflows/linting.yml
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ jobs:
if: ${{ inputs.flake8-version != '' }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install apt dependencies
run: |
sudo apt-get install -y -qq python3 python3-pip
Expand All @@ -108,7 +108,7 @@ jobs:
if: ${{ inputs.pylint-version != '' }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install apt dependencies
run: |
sudo apt-get install -y -qq python3 python3-pip
Expand Down Expand Up @@ -138,7 +138,7 @@ jobs:
if: ${{ inputs.black-version != '' }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install apt dependencies
run: |
sudo apt-get install -y -qq python3 python3-pip
Expand All @@ -161,7 +161,7 @@ jobs:
if: ${{ inputs.ruff-version != '' }}
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install apt dependencies
run: |
sudo apt-get install -y -qq python3 python3-pip
Expand Down Expand Up @@ -205,13 +205,13 @@ jobs:
# To report GitHub Actions status checks
statuses: write
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# super-linter needs the full git history to get the
# list of files that changed across commits
fetch-depth: 0
- name: Lint code base
uses: super-linter/super-linter/slim@v8
uses: super-linter/super-linter/slim@4ce20838b8ab83717e78138c5b3a1407148e0918 # v8.7.0
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
DEFAULT_BRANCH: main
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/post-pr-reviews.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,14 +20,14 @@ jobs:
steps:
- name: Create a .git directory needed by reviewdog
run: git init
- uses: actions/download-artifact@v8
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
id: diff
continue-on-error: true
with:
name: diff
github-token: ${{ github.token }}
run-id: ${{github.event.workflow_run.id }}
- uses: reviewdog/action-setup@v1
- uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0
- name: Check what tools have suggestions to post
# Using this pattern to have expected file names explicitly named
id: tools
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/python-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install dependencies
run: |
# noninteractive is necessary to install libgdal-dev
Expand All @@ -38,20 +38,20 @@ jobs:
- name: Build package
run: python3 -m build --outdir build .
- name: Release
uses: softprops/action-gh-release@v3
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
if: startsWith(github.ref, 'refs/tags/')
with:
files: build/*.whl
- name: Publish package to test pypi
uses: pypa/gh-action-pypi-publish@release/v1
uses: pypa/gh-action-pypi-publish@release/dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2
if: ${{ inputs.test_pypi }}
with:
repository_url: https://test.pypi.org/legacy/
password: ${{ secrets.PYPI_PASSWORD }}
packages_dir: build/
verbose: true
- name: Publish package to pypi
uses: pypa/gh-action-pypi-publish@release/v1
uses: pypa/gh-action-pypi-publish@release/dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2
if: ${{ inputs.test_pypi == false }}
with:
password: ${{ secrets.PYPI_PASSWORD }}
Expand Down
16 changes: 8 additions & 8 deletions .github/workflows/sbom-vulnerability-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ jobs:
fi

- name: Checkout the code
uses: actions/checkout@v7
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: ${{ inputs.fetch_depth }}

Expand All @@ -66,7 +66,7 @@ jobs:

- name: Generate SBOM from Docker image
if: inputs.dockerfile != ''
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
image: localbuild/testimage:latest
artifact-name: docker.cyclonedx.json
Expand All @@ -76,16 +76,16 @@ jobs:
- name: Scan Docker SBOM for vulnerabilities
if: inputs.dockerfile != ''
id: docker-vulnerability-scan
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2
uses: anchore/scan-action@27805bf3b4e84b4a5c980df22ed233c00390a439 # v7.4.2
with:
image:
image:
sbom: docker.cyclonedx.json
fail-build: ${{ inputs.fail-build }}
output-format: sarif

- name: Upload Docker vulnerability results to GitHub Security
if: inputs.dockerfile != ''
uses: github/codeql-action/upload-sarif@v4
uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0
with:
sarif_file: ${{ steps.docker-vulnerability-scan.outputs.sarif }}
category: grype-docker
Expand Down Expand Up @@ -124,7 +124,7 @@ jobs:

- name: Generate SBOM from Python environment
if: inputs.requirements != '' || inputs.pyproject != ''
uses: anchore/sbom-action@v0.24.2
uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
path: .sbom_venv
artifact-name: python.cyclonedx.json
Expand All @@ -134,7 +134,7 @@ jobs:
- name: Scan Python environment for vulnerabilities
if: inputs.requirements != '' || inputs.pyproject != ''
id: python-vulnerability-scan
uses: anchore/scan-action@v7
uses: anchore/scan-action@27805bf3b4e84b4a5c980df22ed233c00390a439 # v7.4.2
with:
# Scan the .sbom_venv directly instead of the generated SBOM because
# the SBOM scan produced empty SARIF artifact locations, while
Expand All @@ -145,7 +145,7 @@ jobs:

- name: Upload Python vulnerability results to GitHub Security
if: inputs.requirements != '' || inputs.pyproject != ''
uses: github/codeql-action/upload-sarif@v4
uses: github/codeql-action/upload-sarif@24ea975727876cf496b1eb0c5b36e96e01600b51 # v4.37.0
with:
sarif_file: ${{ steps.python-vulnerability-scan.outputs.sarif }}
category: grype-python
17 changes: 7 additions & 10 deletions .github/workflows/third-party-licenses.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Validate inputs
id: validate
Expand Down Expand Up @@ -124,7 +124,7 @@ jobs:
"
- name: Generate SBOM from Docker image
if: inputs.dockerfile != ''
uses: anchore/sbom-action@v0.24.2
uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
image: license-scan-image
format: syft-json
Expand All @@ -151,30 +151,27 @@ jobs:
python3 -c "import json; json.load(open('THIRD_PARTY_LICENSES.json'))"

- name: Upload THIRD_PARTY_LICENSES.json as artifact
uses: actions/upload-artifact@v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: third-party-license
path: THIRD_PARTY_LICENSES.json

- name: Upload as release asset
uses: softprops/action-gh-release@v3
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
upload_url: ${{ github.event.release.upload_url }}
asset_path: ./THIRD_PARTY_LICENSES.json
asset_name: THIRD_PARTY_LICENSES.json
asset_content_type: application/json
files: ./THIRD_PARTY_LICENSES.json

license-scan:
runs-on: ubuntu-latest
needs: generate
continue-on-error: true
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Download THIRD_PARTY_LICENSES.json
uses: actions/download-artifact@v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: third-party-license
path: .
Expand Down