Skip to content
Merged
Show file tree
Hide file tree
Changes from 5 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 18 additions & 15 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: main

on:
push:
branches: ["main"]
branches: ["main", "fix-build"]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
rg -n -C2 '^concurrency:|cancel-in-progress' .github/workflows/main.yml

Repository: isosuite/splinepy

Length of output: 155


Add workflow concurrency before publishing artifacts.

Line 5 allows multiple push builds to run at once; with skip-existing, an older main run can publish stale wheels before a newer run finishes. Add per-ref concurrency and cancel superseded runs.

Proposed fix
 on:
   push:
     branches: ["main", "fix-build"]
+
+concurrency:
+  group: ${{ github.workflow }}-${{ github.ref }}
+  cancel-in-progress: true
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
branches: ["main", "fix-build"]
branches: ["main", "fix-build"]
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 3-5: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting

(concurrency-limits)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/main.yml at line 5, Add workflow-level concurrency to the
main workflow so only the latest run per ref proceeds and older runs are
canceled before artifact publishing. Update the workflow configuration near the
top of the file (around the branches trigger) by introducing a per-ref
concurrency group with cancellation for superseded runs, so stale builds cannot
publish wheels ahead of newer runs.

Source: Linters/SAST tools


jobs:
macos_wheel:
Expand All @@ -17,14 +17,14 @@ jobs:
with:
submodules: recursive
- name: build wheels
uses: pypa/cibuildwheel@v2.23.2
uses: pypa/cibuildwheel@v4.1.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

for spec in \
  "https://github.com/actions/checkout.git refs/tags/v7" \
  "https://github.com/actions/upload-artifact.git refs/tags/v7" \
  "https://github.com/actions/download-artifact.git refs/tags/v7" \
  "https://github.com/pypa/cibuildwheel.git refs/tags/v4.1.0" \
  "https://github.com/pypa/gh-action-pypi-publish.git refs/heads/release/v1"
do
  set -- $spec
  git ls-remote "$1" "$2"
done

Repository: isosuite/splinepy

Length of output: 438


🏁 Script executed:

#!/bin/bash
set -euo pipefail

file=".github/workflows/main.yml"
wc -l "$file"
sed -n '1,170p' "$file" | cat -n

Repository: isosuite/splinepy

Length of output: 4828


🏁 Script executed:

#!/bin/bash
set -euo pipefail

file=".github/workflows/main.yml"
wc -l "$file"
sed -n '1,170p' "$file" | cat -n

Repository: isosuite/splinepy

Length of output: 4828


Pin GitHub Actions to immutable SHAs. actions/checkout@v4, actions/upload-artifact@v7, actions/download-artifact@v7, pypa/cibuildwheel@v4.1.0, and pypa/gh-action-pypi-publish@release/v1 are still mutable refs; replace them with commit SHAs to satisfy the pinning policy.

🧰 Tools
🪛 zizmor (1.26.1)

[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/main.yml at line 20, The workflow still uses mutable
GitHub Actions refs, so update the job in main.yml to pin every action to an
immutable commit SHA instead of version tags or branches. Replace the uses
entries for actions/checkout, actions/upload-artifact,
actions/download-artifact, pypa/cibuildwheel, and pypa/gh-action-pypi-publish
with their corresponding commit SHAs so the workflow is fully pinned.

Source: Linters/SAST tools

env:
CIBW_ARCHS: ${{ matrix.arch }}
CIBW_BUILD: ${{ matrix.cw_build }}
SPLINEPY_GITHUB_ACTIONS_BUILD: True
SKBUILD_INSTALL_COMPONENTS: PythonModule

- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v7
with:
name: wheels-macos-15-intel-${{ strategy.job-index }}
path: ./wheelhouse/*.whl
Expand All @@ -42,14 +42,14 @@ jobs:
with:
submodules: recursive
- name: build wheels
uses: pypa/cibuildwheel@v2.23.2
uses: pypa/cibuildwheel@v4.1.0
env:
CIBW_ARCHS: ${{ matrix.arch }}
CIBW_BUILD: ${{ matrix.cw_build }}
SPLINEPY_GITHUB_ACTIONS_BUILD: True
SKBUILD_INSTALL_COMPONENTS: PythonModule

- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v7
with:
name: wheels-macos-${{ strategy.job-index }}
path: ./wheelhouse/*.whl
Expand All @@ -63,18 +63,19 @@ jobs:
cw_build: ["cp310*many*", "cp311*many*", "cp312*many*", "cp313*many*", "cp314*many*"]

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
submodules: recursive
Comment on lines +38 to 40

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Do not persist checkout credentials in build jobs.

These jobs do not push back to GitHub, so the checkout token should not remain available to later build steps. actions/checkout persists credentials by default and supports persist-credentials: false. (github.com)

Proposed fix
     - uses: actions/checkout@v7
       with:
         submodules: recursive
+        persist-credentials: false

Also applies to: 92-94, 113-115

🧰 Tools
🪛 zizmor (1.26.1)

[warning] 66-68: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 66-66: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/main.yml around lines 66 - 68, The checkout step in the
build jobs leaves GitHub credentials available to later steps because
actions/checkout persists them by default. Update each affected checkout
invocation in the workflow to explicitly set persist-credentials to false
alongside the existing submodules setting, so the job can still fetch sources
without keeping the token around. Use the checkout step entries in main.yml as
the targets for this change.

Source: Linters/SAST tools

- name: build wheels
uses: pypa/cibuildwheel@v2.23.2
uses: pypa/cibuildwheel@v4.1.0
env:
CIBW_ARCHS: ${{ matrix.arch }}
CIBW_BUILD: ${{ matrix.cw_build }}
CIBW_SKIP: "cp314t-*"
SPLINEPY_GITHUB_ACTIONS_BUILD: True
SKBUILD_INSTALL_COMPONENTS: PythonModule

- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v7
with:
name: wheels-linux-${{ strategy.job-index }}
path: ./wheelhouse/*.whl
Expand All @@ -88,19 +89,19 @@ jobs:
cw_build: ["cp310-*", "cp311-*", "cp312-*", "cp313-*", "cp314-*"]

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
submodules: recursive
- name: build wheels
uses: pypa/cibuildwheel@v2.23.2
uses: pypa/cibuildwheel@v4.1.0
env:
CIBW_ARCHS: ${{ matrix.arch }}
CIBW_BUILD: ${{ matrix.cw_build }}
CIBW_TEST_SKIP: "*-win_arm64"
SPLINEPY_GITHUB_ACTIONS_BUILD: True
SKBUILD_INSTALL_COMPONENTS: PythonModule

- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v7
with:
name: wheels-windows-${{ strategy.job-index }}
path: ./wheelhouse/*.whl
Expand All @@ -109,14 +110,14 @@ jobs:
source_dist:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
with:
submodules: recursive

- name: Build sdist
run: pipx run build --sdist

- uses: actions/upload-artifact@v4
- uses: actions/upload-artifact@v7
with:
name: wheels-source
path: ./dist/*
Expand All @@ -129,12 +130,14 @@ jobs:
permissions:
id-token: write
steps:
- uses: actions/download-artifact@v4
- uses: actions/download-artifact@v7
with:
pattern: wheels-*
merge-multiple: true
path: dist

- uses: pypa/gh-action-pypi-publish@release/v1
- name: Publish wheels to PyPI
if: github.ref == 'refs/heads/main'
uses: pypa/gh-action-pypi-publish@release/v1
with:
skip-existing: true
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -20,3 +20,6 @@ docs/source/_generated
**/CMakeFiles/
**/Makefile
**/cmake_install.cmake

#
examples/not_upload/
2 changes: 1 addition & 1 deletion docs/source/conf.py
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@
"icon_links": [
{
"name": "GitHub",
"url": "https://github.com/tataratat/splinepy",
"url": "https://github.com/isosuite/splinepy",
"icon": "fa-brands fa-square-github",
},
{
Expand Down
Loading