mirror of
https://github.com/apache/superset.git
synced 2026-09-05 23:12:01 +00:00
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Evan Rusackas <evan@rusackas.com> Co-authored-by: Superset Dev <dev@superset.apache.org>
97 lines
4.4 KiB
YAML
97 lines
4.4 KiB
YAML
# Dependency Review Action
|
|
#
|
|
# This Action will scan dependency manifest files that change as part of a Pull Request, surfacing known-vulnerable versions of the packages declared or updated in the PR. Once installed, if the workflow run is marked as required, PRs introducing known-vulnerable packages will be blocked from merging.
|
|
#
|
|
# Source repository: https://github.com/actions/dependency-review-action
|
|
# Public documentation: https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review#dependency-review-enforcement
|
|
name: "Dependency Review"
|
|
on:
|
|
push:
|
|
branches:
|
|
- "master"
|
|
- "[0-9].[0-9]*"
|
|
pull_request:
|
|
types: [synchronize, opened, reopened, ready_for_review]
|
|
|
|
# cancel previous workflow jobs for PRs
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
actions: read
|
|
|
|
jobs:
|
|
dependency-review:
|
|
if: github.event_name == 'pull_request'
|
|
runs-on: ubuntu-slim
|
|
steps:
|
|
- name: "Checkout Repository"
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
- name: "Dependency Review"
|
|
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
|
|
with:
|
|
fail-on-severity: critical
|
|
# compatible/incompatible licenses addressed here: https://www.apache.org/legal/resolved.html
|
|
# find SPDX identifiers here: https://spdx.org/licenses/
|
|
deny-licenses: MS-LPL, BUSL-1.1, QPL-1.0, Sleepycat, SSPL-1.0, CPOL-1.02, AGPL-3.0, GPL-1.0+, BSD-4-Clause-UC, NPL-1.0, NPL-1.1, JSON
|
|
# pkg:npm/store2@2.14.2
|
|
# adding an exception for an ambigious license on store2, which has been resolved in
|
|
# the latest version. It's MIT: https://github.com/nbubna/store/blob/master/LICENSE-MIT
|
|
# pkg:npm/node-forge@1.3.1
|
|
# selecting BSD-3-Clause licensing terms for node-forge to ensure compatibility with Apache
|
|
allow-dependencies-licenses: pkg:npm/rgbcolor, pkg:npm/jszip@3.10.1
|
|
|
|
python-dependency-liccheck:
|
|
# NOTE: Configuration for liccheck lives in our pyproject.yml.
|
|
# You cannot use a liccheck.ini file in this workflow.
|
|
runs-on: ubuntu-slim
|
|
steps:
|
|
- uses: Kesin11/actions-timeline@57fc93f20c6da7fbc14063c6d24a2a5627c799ad # v3.2.0
|
|
with:
|
|
expand-composite-actions: true
|
|
|
|
- name: "Checkout Repository"
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Python
|
|
uses: ./.github/actions/setup-backend/
|
|
with:
|
|
requirements-type: base
|
|
|
|
- name: "Set up liccheck"
|
|
run: |
|
|
# liccheck (as of 0.9.2) still does a bare `import pkg_resources`
|
|
# without declaring setuptools as a dependency, relying on it
|
|
# having historically been bundled. setuptools 81+ (installed
|
|
# above via requirements/base.txt) dropped the pkg_resources
|
|
# subpackage entirely, so liccheck's own import breaks outright.
|
|
#
|
|
# Reinstalling an older setuptools would restore pkg_resources but
|
|
# would also downgrade the *real* setuptools install, which then
|
|
# trips liccheck's own working_set.resolve() -- it cross-checks
|
|
# requirements/base.txt's declared `setuptools==84.0.0` against
|
|
# what's actually installed, and a downgrade makes those disagree.
|
|
#
|
|
# Instead, vendor just the pkg_resources/ package files from an
|
|
# old setuptools wheel into site-packages, leaving the real
|
|
# setuptools install (and its dist-info metadata) untouched. This
|
|
# gives liccheck an importable pkg_resources whose own working-set
|
|
# scan still correctly reports the real installed setuptools
|
|
# version, so no conflict is raised.
|
|
pip download "setuptools<81" --no-deps -d /tmp/old-setuptools
|
|
python -m zipfile -e /tmp/old-setuptools/setuptools-*.whl /tmp/old-setuptools-extracted/
|
|
cp -r /tmp/old-setuptools-extracted/pkg_resources "$(python -c 'import site; print(site.getsitepackages()[0])')/"
|
|
uv pip install --system liccheck
|
|
- name: "Run liccheck"
|
|
run: |
|
|
# run the checks
|
|
liccheck -R output.txt
|
|
# Print the report
|
|
cat output.txt
|