Repository navigation
ci: Add static analysis of GitHub Actions with zizmor #2693
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
39fabe4
1d75da2
3a93fb8
ff7237d
6c55f2d
c4bfc39
a150fe1
c4f5914
adc1fea
f68835c
89eb730
052561f
e74d715
6120a62
b61feff
11a312f
e5bd918
c8f03b6
006069b
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -41,6 +41,9 @@ jobs: | |
| permissions: | ||
| contents: write # for Git to git push | ||
| runs-on: ubuntu-latest | ||
| environment: | ||
| name: ci | ||
| deployment: false | ||
| if: github.repository == 'scikit-hep/pyhf' | ||
|
|
||
| steps: | ||
|
|
@@ -51,6 +54,7 @@ jobs: | |
| ref: ${{ github.event.inputs.target_branch }} | ||
| fetch-depth: 0 | ||
| token: ${{ secrets.ACCESS_TOKEN }} | ||
| persist-credentials: false | ||
|
|
||
| - name: Check target branch is intended for release | ||
| if: github.event.inputs.force == 'false' | ||
|
|
@@ -77,13 +81,13 @@ jobs: | |
| echo "* Current version: ${current_tag}" | ||
| echo "* Latest stable version: ${latest_stable_tag}" | ||
|
|
||
| if [ ${{ github.event.inputs.release_candidate }} == 'true' ]; then | ||
| echo "* Attempting a ${{ github.event.inputs.part }} version release candidate bump from ${current_tag} to: ${{ github.event.inputs.new_version }}" | ||
| if [ ${GITHUB_EVENT_INPUTS_RELEASE_CANDIDATE} == 'true' ]; then | ||
| echo "* Attempting a ${GITHUB_EVENT_INPUTS_PART} version release candidate bump from ${current_tag} to: ${GITHUB_EVENT_INPUTS_NEW_VERSION}" | ||
| else | ||
| # For ease of use, set current tag to latest stable | ||
| current_tag="${latest_stable_tag}" | ||
|
|
||
| echo "* Attempting a ${{ github.event.inputs.part }} version bump from ${current_tag} to: ${{ github.event.inputs.new_version }}" | ||
| echo "* Attempting a ${GITHUB_EVENT_INPUTS_PART} version bump from ${current_tag} to: ${GITHUB_EVENT_INPUTS_NEW_VERSION}" | ||
| fi | ||
|
|
||
| echo "* Validating bump target version matches SemVer..." | ||
|
|
@@ -102,7 +106,7 @@ jobs: | |
|
|
||
| # IFS is single charecter, so split on the 'r' in "rc" | ||
| IFS='r' read bump_version bump_rc <<EOF | ||
| ${{ github.event.inputs.new_version }} | ||
| ${GITHUB_EVENT_INPUTS_NEW_VERSION} | ||
| EOF | ||
| bump_rc="${bump_rc:1}" | ||
|
|
||
|
|
@@ -113,87 +117,91 @@ jobs: | |
| unset bump_version | ||
|
|
||
| # Check release candidates are valid before proceeding | ||
| if [ ${{ github.event.inputs.release_candidate }} == 'true' ]; then | ||
| if [ ${GITHUB_EVENT_INPUTS_RELEASE_CANDIDATE} == 'true' ]; then | ||
| if [ -z "${current_rc}" ]; then | ||
| current_rc=0 | ||
| fi | ||
| if [ "${bump_rc}" != "$((${current_rc} + 1))" ]; then | ||
| echo "ERROR: ${{ github.event.inputs.new_version }} is more than 1 release candidate version greater then ${current_tag}" | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_NEW_VERSION} is more than 1 release candidate version greater then ${current_tag}" | ||
| exit 1 | ||
| fi | ||
| else | ||
| if [ ! -z "${bump_rc}" ]; then | ||
| echo "ERROR: ${{ github.event.inputs.new_version }} contains a release candidate signature rc${bump_rc} but was marked as stable release." | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_NEW_VERSION} contains a release candidate signature rc${bump_rc} but was marked as stable release." | ||
| exit 1 | ||
| fi | ||
| fi | ||
|
|
||
| if [ ${{ github.event.inputs.part }} == "major" ]; then | ||
| if [ ${GITHUB_EVENT_INPUTS_PART} == "major" ]; then | ||
| # Minor version should be zero | ||
| if [ "${bump_minor}" != "0" ]; then | ||
| echo "ERROR: ${{ github.event.inputs.part }} release attempted, ${{ github.event.inputs.new_version }} minor version should equal 0." | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_PART} release attempted, ${GITHUB_EVENT_INPUTS_NEW_VERSION} minor version should equal 0." | ||
| exit 1 | ||
| fi | ||
| # Patch version should be zero | ||
| if [ "${bump_patch}" != "0" ]; then | ||
| echo "ERROR: ${{ github.event.inputs.part }} release attempted, ${{ github.event.inputs.new_version }} patch version should equal 0." | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_PART} release attempted, ${GITHUB_EVENT_INPUTS_NEW_VERSION} patch version should equal 0." | ||
| exit 1 | ||
| fi | ||
| if [ "${bump_major}" != "$((${current_major} + 1))" ]; then | ||
| if ! ([ "${bump_major}" == "${current_major}" ] && [ ${{ github.event.inputs.release_candidate }} == 'true' ]); then | ||
| echo "ERROR: ${{ github.event.inputs.part }} release candidate release attempted, but ${{ github.event.inputs.new_version }} is more than 1 ${{ github.event.inputs.part }} version greater then ${current_tag}." | ||
| if ! ([ "${bump_major}" == "${current_major}" ] && [ ${GITHUB_EVENT_INPUTS_RELEASE_CANDIDATE} == 'true' ]); then | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_PART} release candidate release attempted, but ${GITHUB_EVENT_INPUTS_NEW_VERSION} is more than 1 ${GITHUB_EVENT_INPUTS_PART} version greater then ${current_tag}." | ||
| exit 1 | ||
| fi | ||
| fi | ||
| fi | ||
|
|
||
| if [ ${{ github.event.inputs.part }} == "minor" ]; then | ||
| if [ ${GITHUB_EVENT_INPUTS_PART} == "minor" ]; then | ||
| # Major versions should be equal | ||
| if [ "${bump_major}" != "${current_major}" ]; then | ||
| echo "ERROR: ${{ github.event.inputs.part }} release attempted, but ${{ github.event.inputs.new_version }} major version not equal to ${current_tag}." | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_PART} release attempted, but ${GITHUB_EVENT_INPUTS_NEW_VERSION} major version not equal to ${current_tag}." | ||
| exit 1 | ||
| fi | ||
| # Patch version should be zero | ||
| if [ "${bump_patch}" != "0" ]; then | ||
| echo "ERROR: ${{ github.event.inputs.part }} release attempted, ${{ github.event.inputs.new_version }} patch version should equal 0." | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_PART} release attempted, ${GITHUB_EVENT_INPUTS_NEW_VERSION} patch version should equal 0." | ||
| exit 1 | ||
| fi | ||
| if [ "${bump_minor}" != "$((${current_minor} + 1))" ]; then | ||
| if ! ([ "${bump_minor}" == "${current_minor}" ] && [ ${{ github.event.inputs.release_candidate }} == 'true' ]); then | ||
| echo "ERROR: ${{ github.event.inputs.part }} release candidate release attempted, but ${{ github.event.inputs.new_version }} is more than 1 ${{ github.event.inputs.part }} version greater then ${current_tag}." | ||
| if ! ([ "${bump_minor}" == "${current_minor}" ] && [ ${GITHUB_EVENT_INPUTS_RELEASE_CANDIDATE} == 'true' ]); then | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_PART} release candidate release attempted, but ${GITHUB_EVENT_INPUTS_NEW_VERSION} is more than 1 ${GITHUB_EVENT_INPUTS_PART} version greater then ${current_tag}." | ||
| exit 1 | ||
| fi | ||
| fi | ||
| fi | ||
|
|
||
| if [ ${{ github.event.inputs.part }} == "patch" ]; then | ||
| if [ ${GITHUB_EVENT_INPUTS_PART} == "patch" ]; then | ||
| # Major versions should be equal | ||
| if [ "${bump_major}" != "${current_major}" ]; then | ||
| echo "ERROR: ${{ github.event.inputs.part }} release attempted, but ${{ github.event.inputs.new_version }} major version not equal to ${current_tag}." | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_PART} release attempted, but ${GITHUB_EVENT_INPUTS_NEW_VERSION} major version not equal to ${current_tag}." | ||
| exit 1 | ||
| fi | ||
| # Minor versions should be equal | ||
| if [ "${bump_minor}" != "${current_minor}" ]; then | ||
| echo "ERROR: ${{ github.event.inputs.part }} release attempted, but ${{ github.event.inputs.new_version }} minor version not equal to ${current_tag}." | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_PART} release attempted, but ${GITHUB_EVENT_INPUTS_NEW_VERSION} minor version not equal to ${current_tag}." | ||
| exit 1 | ||
| fi | ||
| if [ "${bump_patch}" != "$((${current_patch} + 1))" ]; then | ||
| if ! ([ "${bump_patch}" == "${current_patch}" ] && [ ${{ github.event.inputs.release_candidate }} == 'true' ]); then | ||
| echo "ERROR: ${{ github.event.inputs.part }} release candidate release attempted, but ${{ github.event.inputs.new_version }} is more than 1 ${{ github.event.inputs.part }} version greater then ${current_tag}." | ||
| if ! ([ "${bump_patch}" == "${current_patch}" ] && [ ${GITHUB_EVENT_INPUTS_RELEASE_CANDIDATE} == 'true' ]); then | ||
| echo "ERROR: ${GITHUB_EVENT_INPUTS_PART} release candidate release attempted, but ${GITHUB_EVENT_INPUTS_NEW_VERSION} is more than 1 ${GITHUB_EVENT_INPUTS_PART} version greater then ${current_tag}." | ||
| exit 1 | ||
| fi | ||
| fi | ||
| fi | ||
|
|
||
| echo " ...version bump validated!" | ||
| if [ ${{ github.event.inputs.release_candidate }} == 'true' ]; then | ||
| echo "* Bumping version ${current_tag} to ${{ github.event.inputs.part }} version release candidate ${{ github.event.inputs.new_version }}" | ||
| if [ ${GITHUB_EVENT_INPUTS_RELEASE_CANDIDATE} == 'true' ]; then | ||
| echo "* Bumping version ${current_tag} to ${GITHUB_EVENT_INPUTS_PART} version release candidate ${GITHUB_EVENT_INPUTS_NEW_VERSION}" | ||
| else | ||
| echo "* Bumping version ${current_tag} to ${{ github.event.inputs.part }} version ${{ github.event.inputs.new_version }}" | ||
| echo "* Bumping version ${current_tag} to ${GITHUB_EVENT_INPUTS_PART} version ${GITHUB_EVENT_INPUTS_NEW_VERSION}" | ||
| fi | ||
|
|
||
| echo "steps.script.outputs.old_tag=v${current_tag}" | ||
| echo "old_tag=v${current_tag}" >> $GITHUB_OUTPUT | ||
| env: | ||
| GITHUB_EVENT_INPUTS_RELEASE_CANDIDATE: ${{ github.event.inputs.release_candidate }} | ||
| GITHUB_EVENT_INPUTS_PART: ${{ github.event.inputs.part }} | ||
| GITHUB_EVENT_INPUTS_NEW_VERSION: ${{ github.event.inputs.new_version }} | ||
|
|
||
| - name: Set up Python | ||
| if: success() | ||
|
|
@@ -222,16 +230,18 @@ jobs: | |
| ) | ||
| shell: bash | ||
| run: | | ||
| tbump --non-interactive --no-push ${{ github.event.inputs.new_version }} | ||
| tbump --non-interactive --no-push ${GITHUB_EVENT_INPUTS_NEW_VERSION} | ||
| env: | ||
| GITHUB_EVENT_INPUTS_NEW_VERSION: ${{ github.event.inputs.new_version }} | ||
|
|
||
| - name: Update the Git tag annotation | ||
| if: ${{ github.event.inputs.dry_run }} == 'false' | ||
| if: ${{ github.event.inputs.dry_run == 'false' }} | ||
| shell: bash | ||
| run: | | ||
| OLD_TAG=${{ steps.script.outputs.old_tag }} | ||
| OLD_TAG=${STEPS_SCRIPT_OUTPUTS_OLD_TAG} | ||
| git tag -n99 --list "${OLD_TAG}" | ||
|
|
||
| NEW_TAG=v${{ github.event.inputs.new_version }} | ||
| NEW_TAG=v${GITHUB_EVENT_INPUTS_NEW_VERSION} | ||
|
Comment on lines
+241
to
+244
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -eu
file=".github/workflows/bump-version.yml"
wc -l "$file"
sed -n '40,90p' "$file"
sed -n '230,295p' "$file"
printf '\nAll relevant identifiers and commands:\n'
rg -n -C 3 'old_tag|OLD_TAG|git log|git tag|git push|persist-credentials|force|script:' "$file"Repository: scikit-hep/pyhf Length of output: 8436 🏁 Script executed: #!/bin/bash
set -eu
file=".github/workflows/bump-version.yml"
sed -n '85,210p' "$file"
printf '\nRevision resolution for an empty OLD_TAG:\n'
git rev-parse --revs-only '..HEAD' || true
git rev-parse --symbolic --revs-only '..HEAD' || true
git log --pretty=format:'%s' '..HEAD' --regexp-ignore-case --extended-regexp --grep='^([a-z]*?):' | head -20
printf '\nRepository state:\n'
git status --short
git rev-parse --is-inside-work-treeRepository: scikit-hep/pyhf Length of output: 6569 Populate When 🤖 Prompt for AI AgentsSource: MCP tools
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. |
||
| git tag -n99 --list "${NEW_TAG}" | ||
|
|
||
| CHANGES=$(git log --pretty=format:'%s' "${OLD_TAG}"..HEAD --regexp-ignore-case --extended-regexp --grep='^([a-z]*?):') | ||
|
|
@@ -245,24 +255,34 @@ jobs: | |
| SANITIZED_CHANGES=$(echo "${CHANGES}" | sed -e 's/^/<li>/' -e 's|$|</li>|' -e 's/(#[0-9]\+)//' -e 's/"/'"'"'/g') | ||
| NUM_CHANGES=$(echo -n "${CHANGES}" | grep -c '^') | ||
|
|
||
| if [ ${{ github.event.inputs.release_candidate }} == 'true' ]; then | ||
| git tag "${NEW_TAG}" "${NEW_TAG}"^{} -f -m "$(printf "This is a ${{ github.event.inputs.part }} release candidate from ${OLD_TAG} → ${NEW_TAG}.\n\nChanges:\n${CHANGES_NEWLINE}")" | ||
| if [ ${GITHUB_EVENT_INPUTS_RELEASE_CANDIDATE} == 'true' ]; then | ||
| git tag "${NEW_TAG}" "${NEW_TAG}"^{} -f -m "$(printf "This is a ${GITHUB_EVENT_INPUTS_PART} release candidate from ${OLD_TAG} → ${NEW_TAG}.\n\nChanges:\n${CHANGES_NEWLINE}")" | ||
| else | ||
| git tag "${NEW_TAG}" "${NEW_TAG}"^{} -f -m "$(printf "This is a ${{ github.event.inputs.part }} release from ${OLD_TAG} → ${NEW_TAG}.\n\nChanges:\n${CHANGES_NEWLINE}")" | ||
| git tag "${NEW_TAG}" "${NEW_TAG}"^{} -f -m "$(printf "This is a ${GITHUB_EVENT_INPUTS_PART} release from ${OLD_TAG} → ${NEW_TAG}.\n\nChanges:\n${CHANGES_NEWLINE}")" | ||
| fi | ||
|
|
||
| git tag -n99 --list "${NEW_TAG}" | ||
| env: | ||
| STEPS_SCRIPT_OUTPUTS_OLD_TAG: ${{ steps.script.outputs.old_tag }} | ||
| GITHUB_EVENT_INPUTS_NEW_VERSION: ${{ github.event.inputs.new_version }} | ||
| GITHUB_EVENT_INPUTS_RELEASE_CANDIDATE: ${{ github.event.inputs.release_candidate }} | ||
| GITHUB_EVENT_INPUTS_PART: ${{ github.event.inputs.part }} | ||
|
|
||
| - name: Show annotated Git tag | ||
| shell: bash | ||
| run: | | ||
| git show v${{ github.event.inputs.new_version }} | ||
| git show v${GITHUB_EVENT_INPUTS_NEW_VERSION} | ||
| env: | ||
| GITHUB_EVENT_INPUTS_NEW_VERSION: ${{ github.event.inputs.new_version }} | ||
|
|
||
| - name: Push new tag back to GitHub | ||
| shell: bash | ||
| run: | | ||
| if [ ${{ github.event.inputs.dry_run }} == 'true' ]; then | ||
| if [ ${GITHUB_EVENT_INPUTS_DRY_RUN} == 'true' ]; then | ||
| echo "# DRY RUN" | ||
| else | ||
| git push origin ${{ github.event.inputs.target_branch }} --tags | ||
| git push origin ${GITHUB_EVENT_INPUTS_TARGET_BRANCH} --tags | ||
| fi | ||
| env: | ||
| GITHUB_EVENT_INPUTS_DRY_RUN: ${{ github.event.inputs.dry_run }} | ||
| GITHUB_EVENT_INPUTS_TARGET_BRANCH: ${{ github.event.inputs.target_branch }} | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@henryiii we had some discussion on the appropriate duration for cooldowns. Do you have thoughts here?