mirror of
https://github.com/semantica-agi/semantica.git
synced 2026-09-05 04:00:31 +00:00
Scorecard's Pinned-Dependencies check requires pip installs to be hash-verified, not just version-pinned - our existing pkg==X.Y.Z pins (and even pip install -r requirements-ci.txt, despite that file already carrying hashes) still scored a 4 because the pin/hash isn't visible on the command line itself. Adds .github/requirements/*.txt: hash-locked files generated via `uv pip compile --generate-hashes` for every pip target that isn't already requirements-ci.txt, covering standalone CI tooling (build, wheel, twine, uv, pip-audit, safety/bandit/semgrep/jq, pip/setuptools bootstrap) and the project's own local-source installs. The latter (`pip install -e ".[explorer]"`, `pip install -e .`) can't be hash-pinned directly since there's nothing to hash for a local source tree; split into `pip install --no-deps -e .` plus a separate hash-pinned install of the actual fetched dependencies instead. Also adds --require-hashes to every `-r requirements-ci.txt` install so hash verification is enforced explicitly rather than only implied by the file's own content. Simplifies the Dockerfile in the process: it now installs from the same pre-generated explorer-extra.txt (copied in at build time) instead of extracting constraints from requirements-ci.txt at build time, which also means setuptools gets its CVE-2025-47273 fix as a side effect of the hash-pinned install rather than a separate upgrade step. benchmark.yml: pip install -r benchmarks/requirements.txt is left unpinned - that directory doesn't exist in this repo, so there's nothing to generate hashes from. Pre-existing breakage, unrelated to this change.
43 lines
1.7 KiB
YAML
43 lines
1.7 KiB
YAML
name: Security
|
|
|
|
on:
|
|
schedule:
|
|
- cron: '0 0 * * 1'
|
|
workflow_dispatch:
|
|
pull_request:
|
|
branches: [main]
|
|
paths:
|
|
- 'pyproject.toml'
|
|
- 'requirements-ci.txt'
|
|
- '.github/workflows/security.yml'
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
audit:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
|
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7
|
|
with:
|
|
python-version: '3.11'
|
|
# Upgrade first: actions/setup-python's baked-in setuptools has been
|
|
# behind known-vulnerable floors before (e.g. PYSEC-2026-3447 /
|
|
# setuptools 75.1.0), so don't trust the preinstalled one.
|
|
- run: pip install -r .github/requirements/bootstrap.txt --require-hashes
|
|
# Audit the pinned dependency set (requirements-ci.txt is compiled from
|
|
# pyproject.toml with --extra all — the same coverage as the [all]
|
|
# extra, minus the Linux-only gpu set — so this keeps scan parity with
|
|
# CI/release builds without a time-dependent resolution). This is the
|
|
# fix for PYSEC-2024-38 (#869): the bare-env job never had fastapi or
|
|
# python-multipart installed to look at.
|
|
- run: pip install -r requirements-ci.txt --require-hashes
|
|
# PR runs gate on findings, since they're scoped to actual
|
|
# pyproject.toml changes under review. The schedule/workflow_dispatch
|
|
# runs stay non-blocking until a full pass over pre-existing findings
|
|
# across the whole [all] tree has been done.
|
|
- run: pip install -r .github/requirements/pip-audit.txt --require-hashes
|
|
- run: pip-audit -r requirements-ci.txt
|
|
continue-on-error: ${{ github.event_name != 'pull_request' }}
|