mirror of
https://github.com/semantica-agi/semantica.git
synced 2026-09-02 04:00:40 +00:00
- setup-semantica action: pass extras/version through env vars instead
of interpolating ${{ inputs.* }} directly into the bash script, which
was a script-injection vector for any caller deriving these from
event/matrix data
- install-matrix: trigger on the Release workflow's completion
(workflow_run) instead of `release: published`, since the GitHub
release is created before the PyPI upload runs - the old trigger
could race the publish and silently verify the prior version; also
assert the installed version matches the triggering release tag
- examples/ci/github-actions.yml: pin actions/checkout and
actions/setup-python to the same verified commit SHAs used elsewhere
in this repo instead of mutable v5/v6 tags, and document how to pin
the setup-semantica@main reference for production use
- examples/ci templates + README: make the requirements.txt install
step conditional (guard with `-f requirements.txt`) and call out
pyproject.toml/Poetry/Pipenv as alternatives, since the templates
previously assumed every project has a requirements.txt; CircleCI's
cache key also no longer hashes a file that may not exist