diff --git a/.github/workflows/black.yml b/.github/workflows/black.yml deleted file mode 100644 index b9f760d..0000000 --- a/.github/workflows/black.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: Black code style check - -on: [push] - -jobs: - black: - - runs-on: ubuntu-24.04 - - steps: - - uses: actions/checkout@v7 - - name: Install apt dependencies - run: | - sudo apt-get update && sudo apt-get install python3 python3-pip -y - - name: Install pip dependencies - run: | - pip3 install black - - name: Check code style with Black - run: | - black --check --diff --line-length 79 . diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..f4a037c --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,23 @@ +name: CodeQL Code Scan + +on: + push: + branches: [ "main" ] + schedule: + # Check every Monday at 04:36 + - cron: "36 04 * * 1" + +jobs: + codeql: + uses: mundialis/github-workflows/.github/workflows/codeql.yml@main + + permissions: + # required for all workflows + security-events: write + + # required to fetch internal or private CodeQL packs + packages: read + + # only required for workflows in private repositories + actions: read + contents: read diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index 47db4c1..0227614 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -3,6 +3,10 @@ on: push: branches: - main + +# the workflow does not require permissions, but to avoid a code security warning this should be explicitly defined: +permissions: {} + jobs: deploy: runs-on: ubuntu-latest diff --git a/.github/workflows/flake8.yml b/.github/workflows/flake8.yml deleted file mode 100644 index 4b37b65..0000000 --- a/.github/workflows/flake8.yml +++ /dev/null @@ -1,28 +0,0 @@ -name: Python code quality check - -on: - push: - branches: [ main ] - pull_request: - # The branches below must be a subset of the branches above - branches: [ main ] - -jobs: - - flake8: - - runs-on: ubuntu-24.04 - - steps: - - uses: actions/checkout@v7 - - name: Set up Python - uses: actions/setup-python@v7 - with: - python-version: 3.8 - - name: Install - run: | - python -m pip install --upgrade pip - pip install flake8==3.8.0 - - name: Run Flake8 - run: | - flake8 --config=.flake8 --count --statistics --show-source --jobs=$(nproc) . diff --git a/.github/workflows/linting.yml b/.github/workflows/linting.yml new file mode 100644 index 0000000..0272528 --- /dev/null +++ b/.github/workflows/linting.yml @@ -0,0 +1,24 @@ +name: Linting and code quality check + +on: + push: + branches: + - main + pull_request: + branches: + - main + +jobs: + lint: + uses: mundialis/github-workflows/.github/workflows/linting.yml@main + with: + # exclude everything except flake8 and black + pylint-version: '' + ruff-version: '' + SUPER_LINTER_FILTER_REGEX_EXCLUDE: '.*' + # the workflow requires permissions that need to be granted by the parent job: + permissions: + contents: read + packages: read + # To report GitHub Actions status checks + statuses: write diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml index 2c66769..d23ba04 100644 --- a/.github/workflows/python-publish.yml +++ b/.github/workflows/python-publish.yml @@ -4,6 +4,9 @@ on: release: types: [published] +# the workflow does not require permissions, but to avoid a code security warning this should be explicitly defined: +permissions: {} + jobs: publish-python: uses: mundialis/github-workflows/.github/workflows/python-publish.yml@python-publish diff --git a/.github/workflows/sbom-vulnerability-scan.yml b/.github/workflows/sbom-vulnerability-scan.yml new file mode 100644 index 0000000..2f878fe --- /dev/null +++ b/.github/workflows/sbom-vulnerability-scan.yml @@ -0,0 +1,21 @@ +name: SBOM Vulnerability Scan + +on: + push: + branches: [ "main" ] + schedule: + # Check every Monday at 04:36 + - cron: "36 04 * * 1" + release: + types: [published] + + +jobs: + sbom-scan: + permissions: + contents: read + security-events: write + + uses: mundialis/github-workflows/.github/workflows/sbom-vulnerability-scan.yml@main + with: + pyproject: pyproject.toml diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index c5019aa..25ffc4b 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -7,6 +7,9 @@ on: # The branches below must be a subset of the branches above branches: [ main ] +# the workflow does not require permissions, but to avoid a code security warning this should be explicitly defined: +permissions: {} + jobs: integration-tests: diff --git a/.github/workflows/third-party-licenses.yml b/.github/workflows/third-party-licenses.yml new file mode 100644 index 0000000..148fd18 --- /dev/null +++ b/.github/workflows/third-party-licenses.yml @@ -0,0 +1,13 @@ +name: Generate Third-Party Licenses + +on: + release: + types: [published] + +permissions: {} + +jobs: + generate-third-party-licenses: + uses: mundialis/github-workflows/.github/workflows/third-party-licenses.yml@main + with: + pyproject: pyproject.toml