feat(devtools): bump Flow canary on release (#6830) #4651
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Vulnerability Scan | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| schedule: | |
| # Run weekly on Monday at 9:00 UTC | |
| - cron: '0 9 * * 1' | |
| permissions: | |
| contents: read | |
| jobs: | |
| changes: | |
| name: Detect changes | |
| runs-on: ubuntu-latest | |
| outputs: | |
| code: ${{ steps.set.outputs.code }} | |
| steps: | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 | |
| if: github.event_name == 'pull_request' | |
| - uses: dorny/paths-filter@d1c1ffe0248fe513906c8e24db8ea791d46f8590 # v3 | |
| id: filter | |
| if: github.event_name == 'pull_request' | |
| with: | |
| # Exclusion-only patterns match every non-excluded file under the | |
| # default "some" quantifier. Require all patterns (including "**") | |
| # so docs/markdown/Actions-only PRs correctly set code=false. | |
| predicate-quantifier: every | |
| filters: | | |
| code: | |
| - '**' | |
| - '!docs/**' | |
| - '!**/*.md' | |
| - '!.github/**' | |
| - name: Set code output | |
| id: set | |
| run: | | |
| if [ "${{ github.event_name }}" != "pull_request" ]; then | |
| echo "code=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "code=${{ steps.filter.outputs.code }}" >> "$GITHUB_OUTPUT" | |
| fi | |
| pip-audit: | |
| name: pip-audit | |
| needs: changes | |
| if: needs.changes.outputs.code == 'true' | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 | |
| with: | |
| persist-credentials: false | |
| - name: Restore global uv cache | |
| id: cache-restore | |
| uses: actions/cache/restore@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 | |
| with: | |
| path: | | |
| ~/.cache/uv | |
| ~/.local/share/uv | |
| .venv | |
| key: uv-main-py3.11-${{ hashFiles('uv.lock') }} | |
| restore-keys: | | |
| uv-main-py3.11- | |
| - name: Install uv | |
| uses: astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6 | |
| with: | |
| version: "0.11.3" | |
| python-version: "3.11" | |
| enable-cache: false | |
| - name: Install dependencies | |
| run: uv sync --all-groups --all-extras --no-install-project | |
| - name: Install pip-audit | |
| run: uv pip install pip-audit | |
| - name: Run pip-audit | |
| run: | | |
| pip_audit_args=( | |
| --desc | |
| --aliases | |
| --skip-editable | |
| --format json | |
| --output pip-audit-report.json | |
| --ignore-vuln GHSA-rrmf-rvhw-rf47 # torch 2.12.0 (CVE-2025-3000): local-only memory corruption in torch.jit.script; no fix available. | |
| --ignore-vuln GHSA-f4j7-r4q5-qw2c # chromadb 1.1.1 (CVE-2026-45829): pre-auth RCE in the HTTP server; no fix available. | |
| ) | |
| uv run pip-audit "${pip_audit_args[@]}" | |
| continue-on-error: true | |
| - name: Display results | |
| if: always() | |
| run: | | |
| if [ -f pip-audit-report.json ]; then | |
| echo "## pip-audit Results" >> $GITHUB_STEP_SUMMARY | |
| echo '```json' >> $GITHUB_STEP_SUMMARY | |
| cat pip-audit-report.json | python3 -m json.tool >> $GITHUB_STEP_SUMMARY | |
| echo '```' >> $GITHUB_STEP_SUMMARY | |
| # Fail if vulnerabilities found | |
| python3 -c " | |
| import json, sys | |
| with open('pip-audit-report.json') as f: | |
| data = json.load(f) | |
| vulns = [d for d in data.get('dependencies', []) if d.get('vulns')] | |
| if vulns: | |
| print(f'::error::Found vulnerabilities in {len(vulns)} package(s)') | |
| for v in vulns: | |
| for vuln in v['vulns']: | |
| print(f' - {v[\"name\"]}=={v[\"version\"]}: {vuln[\"id\"]}') | |
| sys.exit(1) | |
| print('No known vulnerabilities found') | |
| " | |
| else | |
| echo "::error::pip-audit failed to produce a report. Check the pip-audit step logs." | |
| exit 1 | |
| fi | |
| - name: Upload pip-audit report | |
| if: always() | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 | |
| with: | |
| name: pip-audit-report | |
| path: pip-audit-report.json | |
| - name: Save uv caches | |
| if: steps.cache-restore.outputs.cache-hit != 'true' | |
| uses: actions/cache/save@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 | |
| with: | |
| path: | | |
| ~/.cache/uv | |
| ~/.local/share/uv | |
| .venv | |
| key: uv-main-py3.11-${{ hashFiles('uv.lock') }} |