Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/attestation-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ jobs:
if: steps.release.outputs.skip != 'true'
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
with:
python-version: '3.12'
python-version: '3.14'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Interpreter mismatch in attestation-check.yml Set up Python: switching to Python 3.14 makes the later pip download "cachekit==${VER}" --no-deps --only-binary :all: accept only cp314 wheels, but release-please.yml (lines 239-277) builds only cp310–cp313 wheels and publishes no abi3 wheel. On every scheduled run, pip fails with "No matching distribution found" and the step exits 1 with "Could not download wheel", so the weekly check goes red without verifying any attestation, which raises a false tamper alarm and defeats the tripwire. Fix: pin the interpreter to '3.13', pass --python-version 3.12 --platform manylinux_2_17_x86_64 to pip download, or add python3.14 to the release interpreter matrix first.

python-version: '3.13'
Prompt for LLM

File .github/workflows/attestation-check.yml:

Line 81:

Interpreter mismatch in attestation-check.yml Set up Python: switching to Python 3.14 makes the later `pip download "cachekit==${VER}" --no-deps --only-binary :all:` accept only cp314 wheels, but release-please.yml (lines 239-277) builds only cp310–cp313 wheels and publishes no abi3 wheel. On every scheduled run, pip fails with "No matching distribution found" and the step exits 1 with "Could not download wheel", so the weekly check goes red without verifying any attestation, which raises a false tamper alarm and defeats the tripwire. Fix: pin the interpreter to '3.13', pass `--python-version 3.12 --platform manylinux_2_17_x86_64` to `pip download`, or add python3.14 to the release interpreter matrix first.

Suggested Code:

          python-version: '3.13'

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​


- name: Verify attestations
id: verify
Expand Down
16 changes: 8 additions & 8 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,9 +30,9 @@ jobs:
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec
version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec

# `uv sync` builds the Rust extension via maturin into ./target, and clippy
# below compiles the same workspace — cache the dependency artifacts and the
Expand Down Expand Up @@ -108,9 +108,9 @@ jobs:
redis:7-alpine redis-server --save "" --appendonly no
until docker exec redis redis-cli ping | grep -q PONG; do sleep 1; done

- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec
version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec
cache-suffix: py${{ matrix.python-version }} # setup-uv keys on lockfile hash only, not job/matrix

# pyo3 is built per interpreter (no abi3), so key the Rust cache per matrix
Expand Down Expand Up @@ -304,9 +304,9 @@ jobs:
redis:7-alpine redis-server --save "" --appendonly no
until docker exec redis redis-cli ping | grep -q PONG; do sleep 1; done

- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec
version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec
cache-suffix: py3.14t

- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
Expand Down Expand Up @@ -342,9 +342,9 @@ jobs:
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec
version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec

# `uv sync` below builds the Rust extension via maturin — cache its dependencies.
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ jobs:
if: matrix.language == 'python'
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
with:
python-version: "3.12"
python-version: "3.14"

- name: Install Python dependencies
if: matrix.language == 'python'
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/release-please.yml
Original file line number Diff line number Diff line change
Expand Up @@ -138,7 +138,7 @@ jobs:

- name: Install uv
if: steps.find.outputs.branch != ''
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2

- name: Install Rust toolchain
if: steps.find.outputs.branch != ''
Expand Down Expand Up @@ -333,7 +333,7 @@ jobs:
# action's own upload-artifact / upload-release-assets are disabled; the SBOM is
# handed to `attest` via the explicit artifact below.
- name: Generate SBOM (Python + Rust)
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
uses: anchore/sbom-action@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
with:
path: .
config: .github/syft.yaml
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/security-deep.yml
Original file line number Diff line number Diff line change
Expand Up @@ -124,9 +124,9 @@ jobs:
# No uv or Rust cache on this nightly job: the cold `uv sync` (maturin
# build included) is noise against 30 min of fuzz time, and an unsuffixed
# uv cache would just restore the cp312 wheel set the PR jobs save.
- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec
version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec
enable-cache: false

# Pin to 3.11: atheris 2.3.0's newest prebuilt wheel is cp311. On a newer
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/security-fast.yml
Original file line number Diff line number Diff line change
Expand Up @@ -96,9 +96,9 @@ jobs:
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6

- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: "0.12.12" # pinned: uv runs as step 1 of every job; a floating release is code exec
version: "0.12.19" # pinned: uv runs as step 1 of every job; a floating release is code exec

# `uv sync` builds the Rust extension via maturin — cache its dependencies.
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
Expand Down
Loading