Skip to content

chore(deps): update pgvector/pgvector:pg15 docker digest to a947c45 #785

chore(deps): update pgvector/pgvector:pg15 docker digest to a947c45

chore(deps): update pgvector/pgvector:pg15 docker digest to a947c45 #785

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }}
cancel-in-progress: true
permissions:
contents: read
jobs:
check-pr-size:
name: PR Size Check
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Fail if PR adds more than 400 lines
env:
BASE_REF: ${{ github.base_ref }}
run: |
ADDED=$(git diff "origin/$BASE_REF"...HEAD \
-- . ':(exclude)*.lock' ':(exclude)*-lock.json' ':(exclude)*.lockb' \
':(exclude)*.md' ':(exclude)LICENSE' ':(exclude).secrets.baseline' \
':(exclude)*/data/*.json' ':(exclude)*/tests/*' ':(exclude)*/test_*.py' \
| grep -cE '^\+[^+]' || echo 0)
echo "Lines added (excl. lockfiles, docs, tests): $ADDED"
if [ "$ADDED" -gt 400 ]; then
echo "::error::PR zu gross (${ADDED} Zeilen hinzugefuegt, Maximum: 400) — bitte aufteilen."
exit 1
fi
lint:
name: Lint & Format
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: astral-sh/ruff-action@278981a28ce3188b1e39527901f38254bf3aac89 # v4.1.0
with:
args: check src/ tests/
- uses: astral-sh/ruff-action@278981a28ce3188b1e39527901f38254bf3aac89 # v4.1.0
with:
args: format --check src/ tests/
security:
name: Security
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: gitleaks
uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITLEAKS_ENABLE_UPLOAD_ARTIFACT: false
GITLEAKS_ENABLE_SUMMARY: false
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7
with:
python-version: "3.14"
- name: Install uv + audit tools
run: pip install pip-audit==2.8.0 uv==0.7.8
- name: pip-audit
# CVE-2025-69872: diskcache pickle deserialisation (transitive via trafilatura, no fix available)
# GHSA-pjjw-68hj-v9mw: uv RECORD path traversal on uninstall (build tool, not runtime dep)
# PYSEC-2026-196: pip console_scripts path traversal (build tool, not runtime)
run: |
uv export --frozen --no-hashes -o /tmp/req.txt
pip-audit -r /tmp/req.txt --ignore-vuln CVE-2025-69872 --ignore-vuln GHSA-pjjw-68hj-v9mw --ignore-vuln PYSEC-2026-196
- name: bandit
# These rules are handled by ruff S-rules with targeted per-file-ignores
# and noqa comments (bandit doesn't support ruff's # noqa: SXXX syntax)
run: |
pip install bandit==1.8.3
bandit -r src/niles/ -q --skip B101,B105,B314,B324,B405,B608
- name: semgrep
run: |
pip install semgrep==1.164.0
semgrep scan --error --config p/python --config p/owasp-top-ten src/niles/
- name: SBOM (CycloneDX via syft)
uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
path: .
artifact-name: niles-sbom.cdx.json
output-file: niles-sbom.cdx.json
format: cyclonedx-json
typecheck:
name: Type Check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: "3.14"
enable-cache: true
- name: Install dependencies
run: uv sync --frozen --extra dev
- name: mypy
run: uv run --extra dev mypy src/niles/
test:
name: Tests
needs: typecheck
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Python 3.14
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7
with:
python-version: "3.14"
- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
enable-cache: true
- name: Install dependencies
run: uv sync --frozen --extra dev
- name: Run tests with coverage
env:
EVOLUTION_POSTGRES_PASSWORD: test-password # pragma: allowlist secret
EVOLUTION_API_KEY: test-api-key # pragma: allowlist secret
NILES_API_KEY: test-niles-key # pragma: allowlist secret
LOG_LEVEL: DEBUG
run: uv run --extra dev pytest -m "not llm_eval" --cov --cov-report=term-missing --cov-report=xml
- name: Upload coverage artifact
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: coverage-report
path: coverage.xml
trivy:
name: Trivy Image Scan
needs: lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Build Docker image
run: docker build -t niles-core:ci -f docker/Dockerfile.niles .
- name: Scan image
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
image-ref: niles-core:ci
exit-code: '1'
severity: CRITICAL,HIGH
ignore-unfixed: true
format: table
output: trivy-niles.txt
- name: Upload Trivy results
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: trivy-niles
path: trivy-niles.txt
retention-days: 90
ci-ok:
name: CI OK (All Green Gate)
runs-on: ubuntu-latest
if: always()
needs: [check-pr-size, lint, security, typecheck, test, trivy]
steps:
- name: All checks passed
env:
NEEDS_JSON: ${{ toJSON(needs.*.result) }}
run: |
if echo "$NEEDS_JSON" | grep -qE '"failure"|"cancelled"'; then
echo "One or more required jobs failed or were cancelled."
exit 1
fi
echo "All CI jobs passed."