Skip to content

CI: cache and pin the Python dependency install - #1384

Merged
gusthoff merged 7 commits into
AdaCore:mainfrom
gusthoff:dev/topic/infrastructure/ci/python-dep-cache/2026-09-18
Sep 18, 2026
Merged

gusthoff merged 7 commits into
AdaCore:mainfrom
gusthoff:dev/topic/infrastructure/ci/python-dep-cache/2026-09-18

Conversation

@gusthoff

Copy link
Copy Markdown
Collaborator

Two changes to how the four Python workflows set up their environment.

Stacked on the "update the GitHub actions" branch, which this needs for
setup-python@v7; review that one first.

Cache the Python dependencies

The Node steps have cached their store all along, while the pinned
packages from requirements_frozen.txt were reinstalled from scratch on
every run. cache: 'pip' is enabled on the four setup-python steps
that install them.

The dependency path is named explicitly, and that part is load-bearing:
the default pattern is **/requirements.txt, which matches a file this
repository has but does not install. Left implicit, the cache key would
never change when a pinned version in requirements_frozen.txt does, and
a stale cache would be served after every dependency update.

The type-check workflow is not cached. It installs an unpinned pyright
plus a local editable package, with no pinned manifest to key on.

Pin pip

Each of those workflows ran python -m pip install --upgrade pip before
installing its requirements, leaving the tool that resolves the pinned
packages as the only unpinned part of the environment. setup-python's
pip-version input replaces it and the step is dropped.

Note this is an exact pin: the action applies the value as pip==<value>,
not as a range, and nothing updates it automatically -- Dependabot tracks
uses: lines, not input values.

Scope and impact

sphinx-books-tests.js.yml, sphinx-content-tests.js.yml,
sphinx-plugin-tests.js.yml, typescript-tests.js.yml. No other
workflow, and no content or frontend file, is touched.

Validation

All workflows parse. Each cached step was checked to name a dependency
path that exists relative to the repository root, and to run after the
checkout that creates it. The pip-version value matches the format the
action validates, and no manual pip upgrade remains in any workflow.

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com

gusthoff and others added 7 commits September 18, 2026 20:12
The job declared no `permissions`, so it ran with whatever the repository
default grants. That default is configurable outside this file, and a
restricted one withholds `security-events: write`, which the analysis
needs to upload its results.

Declare the two scopes the job uses. Every other scope is dropped, which
is the intent: the job checks out the sources and analyzes them.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The workflow ran `codeql-action/autobuild` between `init` and `analyze`.
Both analyzed languages are interpreted, so that step had nothing to
build and the surrounding comments described a compiled-language setup
this repository does not have.

Set `build-mode: none` on `init`, which states the same thing directly,
and drop the step along with the commented-out manual build it pointed
at.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The matrix uploads one set of results per language, and without a
category they were told apart only by the job they came from. Code
scanning uses the category to match an upload against the analysis it
replaces.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Every other workflow pins `ubuntu-26.04` so that CI matches the VMs,
which makes this one look like an oversight. It is not: the analysis
neither builds nor runs the sources, so the runner image has no bearing
on the findings.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The list of supported languages predated `actions`, `ruby`, `rust` and
`swift`, and the documentation link still carried the retired
`free-pro-team@latest` prefix, reaching the current page only through a
redirect. Note also that `javascript` covers TypeScript, which is not
obvious from the matrix.

Name the job after the language it analyzes, so the two matrix legs are
told apart in the checks list.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The Node steps have cached their store all along, while every run
reinstalled the pinned packages from `requirements_frozen.txt` from
scratch.

Enable pip caching on `setup-python` and key it on the frozen
requirements file. Naming the file matters: the default pattern matches
`requirements.txt`, which is not what these workflows install, so the key
would not change when a pinned version does and a stale cache would be
served.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Each workflow ran `python -m pip install --upgrade pip` before installing
its requirements, leaving the one tool that resolves the pinned packages
as the only unpinned part of the environment.

Use `setup-python`'s `pip-version` instead, which the action applies as
an exact `pip==` requirement, and drop the upgrade step. Bumping it is a
manual edit; Dependabot does not track this input.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@gusthoff
gusthoff merged commit d74ba88 into AdaCore:main Sep 18, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants