diff --git a/.github/workflows/attestation-check.yml b/.github/workflows/attestation-check.yml index beee84e5..71d83275 100644 --- a/.github/workflows/attestation-check.yml +++ b/.github/workflows/attestation-check.yml @@ -78,7 +78,7 @@ jobs: if: steps.release.outputs.skip != 'true' uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 with: - python-version: '3.12' + python-version: '3.14' - name: Verify attestations id: verify diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 825318d9..c7f1341b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -30,9 +30,9 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: - version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec + version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec # `uv sync` builds the Rust extension via maturin into ./target, and clippy # below compiles the same workspace — cache the dependency artifacts and the @@ -108,9 +108,9 @@ jobs: redis:7-alpine redis-server --save "" --appendonly no until docker exec redis redis-cli ping | grep -q PONG; do sleep 1; done - - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: - version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec + version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec cache-suffix: py${{ matrix.python-version }} # setup-uv keys on lockfile hash only, not job/matrix # pyo3 is built per interpreter (no abi3), so key the Rust cache per matrix @@ -304,9 +304,9 @@ jobs: redis:7-alpine redis-server --save "" --appendonly no until docker exec redis redis-cli ping | grep -q PONG; do sleep 1; done - - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: - version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec + version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec cache-suffix: py3.14t - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 @@ -342,9 +342,9 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: - version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec + version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec # `uv sync` below builds the Rust extension via maturin — cache its dependencies. - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 3929f9af..ea00e39f 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -57,7 +57,7 @@ jobs: if: matrix.language == 'python' uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 with: - python-version: "3.12" + python-version: "3.14" - name: Install Python dependencies if: matrix.language == 'python' diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index cedba7a3..c1b11484 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -138,7 +138,7 @@ jobs: - name: Install uv if: steps.find.outputs.branch != '' - uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 + uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 - name: Install Rust toolchain if: steps.find.outputs.branch != '' @@ -333,7 +333,7 @@ jobs: # action's own upload-artifact / upload-release-assets are disabled; the SBOM is # handed to `attest` via the explicit artifact below. - name: Generate SBOM (Python + Rust) - uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0 + uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2 with: path: . config: .github/syft.yaml diff --git a/.github/workflows/security-deep.yml b/.github/workflows/security-deep.yml index 74584a5d..56ee18a5 100644 --- a/.github/workflows/security-deep.yml +++ b/.github/workflows/security-deep.yml @@ -124,9 +124,9 @@ jobs: # No uv or Rust cache on this nightly job: the cold `uv sync` (maturin # build included) is noise against 30 min of fuzz time, and an unsuffixed # uv cache would just restore the cp312 wheel set the PR jobs save. - - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: - version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec + version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec enable-cache: false # Pin to 3.11: atheris 2.3.0's newest prebuilt wheel is cp311. On a newer diff --git a/.github/workflows/security-fast.yml b/.github/workflows/security-fast.yml index 17f4fc9f..1105240b 100644 --- a/.github/workflows/security-fast.yml +++ b/.github/workflows/security-fast.yml @@ -96,9 +96,9 @@ jobs: steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 - - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 + - uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0 with: - version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec + version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec # `uv sync` builds the Rust extension via maturin — cache its dependencies. - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2