chore(deps): update pgvector/pgvector:pg15 docker digest to a947c45 #785
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| check-pr-size: | |
| name: PR Size Check | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Fail if PR adds more than 400 lines | |
| env: | |
| BASE_REF: ${{ github.base_ref }} | |
| run: | | |
| ADDED=$(git diff "origin/$BASE_REF"...HEAD \ | |
| -- . ':(exclude)*.lock' ':(exclude)*-lock.json' ':(exclude)*.lockb' \ | |
| ':(exclude)*.md' ':(exclude)LICENSE' ':(exclude).secrets.baseline' \ | |
| ':(exclude)*/data/*.json' ':(exclude)*/tests/*' ':(exclude)*/test_*.py' \ | |
| | grep -cE '^\+[^+]' || echo 0) | |
| echo "Lines added (excl. lockfiles, docs, tests): $ADDED" | |
| if [ "$ADDED" -gt 400 ]; then | |
| echo "::error::PR zu gross (${ADDED} Zeilen hinzugefuegt, Maximum: 400) — bitte aufteilen." | |
| exit 1 | |
| fi | |
| lint: | |
| name: Lint & Format | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: astral-sh/ruff-action@278981a28ce3188b1e39527901f38254bf3aac89 # v4.1.0 | |
| with: | |
| args: check src/ tests/ | |
| - uses: astral-sh/ruff-action@278981a28ce3188b1e39527901f38254bf3aac89 # v4.1.0 | |
| with: | |
| args: format --check src/ tests/ | |
| security: | |
| name: Security | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: gitleaks | |
| uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| GITLEAKS_ENABLE_UPLOAD_ARTIFACT: false | |
| GITLEAKS_ENABLE_SUMMARY: false | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 | |
| with: | |
| python-version: "3.14" | |
| - name: Install uv + audit tools | |
| run: pip install pip-audit==2.8.0 uv==0.7.8 | |
| - name: pip-audit | |
| # CVE-2025-69872: diskcache pickle deserialisation (transitive via trafilatura, no fix available) | |
| # GHSA-pjjw-68hj-v9mw: uv RECORD path traversal on uninstall (build tool, not runtime dep) | |
| # PYSEC-2026-196: pip console_scripts path traversal (build tool, not runtime) | |
| run: | | |
| uv export --frozen --no-hashes -o /tmp/req.txt | |
| pip-audit -r /tmp/req.txt --ignore-vuln CVE-2025-69872 --ignore-vuln GHSA-pjjw-68hj-v9mw --ignore-vuln PYSEC-2026-196 | |
| - name: bandit | |
| # These rules are handled by ruff S-rules with targeted per-file-ignores | |
| # and noqa comments (bandit doesn't support ruff's # noqa: SXXX syntax) | |
| run: | | |
| pip install bandit==1.8.3 | |
| bandit -r src/niles/ -q --skip B101,B105,B314,B324,B405,B608 | |
| - name: semgrep | |
| run: | | |
| pip install semgrep==1.164.0 | |
| semgrep scan --error --config p/python --config p/owasp-top-ten src/niles/ | |
| - name: SBOM (CycloneDX via syft) | |
| uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2 | |
| with: | |
| path: . | |
| artifact-name: niles-sbom.cdx.json | |
| output-file: niles-sbom.cdx.json | |
| format: cyclonedx-json | |
| typecheck: | |
| name: Type Check | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 | |
| with: | |
| python-version: "3.14" | |
| enable-cache: true | |
| - name: Install dependencies | |
| run: uv sync --frozen --extra dev | |
| - name: mypy | |
| run: uv run --extra dev mypy src/niles/ | |
| test: | |
| name: Tests | |
| needs: typecheck | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Python 3.14 | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 | |
| with: | |
| python-version: "3.14" | |
| - uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 | |
| with: | |
| enable-cache: true | |
| - name: Install dependencies | |
| run: uv sync --frozen --extra dev | |
| - name: Run tests with coverage | |
| env: | |
| EVOLUTION_POSTGRES_PASSWORD: test-password # pragma: allowlist secret | |
| EVOLUTION_API_KEY: test-api-key # pragma: allowlist secret | |
| NILES_API_KEY: test-niles-key # pragma: allowlist secret | |
| LOG_LEVEL: DEBUG | |
| run: uv run --extra dev pytest -m "not llm_eval" --cov --cov-report=term-missing --cov-report=xml | |
| - name: Upload coverage artifact | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 | |
| with: | |
| name: coverage-report | |
| path: coverage.xml | |
| trivy: | |
| name: Trivy Image Scan | |
| needs: lint | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Build Docker image | |
| run: docker build -t niles-core:ci -f docker/Dockerfile.niles . | |
| - name: Scan image | |
| uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 | |
| with: | |
| image-ref: niles-core:ci | |
| exit-code: '1' | |
| severity: CRITICAL,HIGH | |
| ignore-unfixed: true | |
| format: table | |
| output: trivy-niles.txt | |
| - name: Upload Trivy results | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 | |
| with: | |
| name: trivy-niles | |
| path: trivy-niles.txt | |
| retention-days: 90 | |
| ci-ok: | |
| name: CI OK (All Green Gate) | |
| runs-on: ubuntu-latest | |
| if: always() | |
| needs: [check-pr-size, lint, security, typecheck, test, trivy] | |
| steps: | |
| - name: All checks passed | |
| env: | |
| NEEDS_JSON: ${{ toJSON(needs.*.result) }} | |
| run: | | |
| if echo "$NEEDS_JSON" | grep -qE '"failure"|"cancelled"'; then | |
| echo "One or more required jobs failed or were cancelled." | |
| exit 1 | |
| fi | |
| echo "All CI jobs passed." |