diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 4f1c18566..78a56cea9 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -15,16 +15,29 @@ on: [pull_request] jobs: analyze: - name: Analyze + name: Analyze (${{ matrix.language }}) + # The other workflows pin the runner image to match the VMs. This one + # does not need to: the analysis reads the sources without building + # or running them, so the image cannot influence the findings. runs-on: ubuntu-latest + # Stated here rather than inherited from the repository default, so + # that tightening that default cannot silently stop the results from + # being uploaded. + permissions: + contents: read + # Required to upload the analysis results. + security-events: write + strategy: fail-fast: false matrix: language: [ 'javascript', 'python' ] - # CodeQL supports [ 'cpp', 'csharp', 'go', 'java', 'javascript', 'python' ] + # CodeQL supports [ 'actions', 'cpp', 'csharp', 'go', 'java', + # 'javascript', 'python', 'ruby', 'rust', 'swift' ]. 'javascript' + # covers TypeScript as well. # Learn more: - # https://docs.github.com/en/free-pro-team@latest/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#changing-the-languages-that-are-analyzed + # https://docs.github.com/en/code-security/reference/code-scanning/workflow-configuration-options steps: - name: Checkout repository @@ -35,26 +48,18 @@ jobs: uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} + # Both languages are interpreted, so the database is built from the + # sources and nothing has to be compiled first. A compiled language + # added to the matrix would need `autobuild` or `manual` instead. + build-mode: none # If you wish to specify custom queries, you can do so here or in a config file. # By default, queries listed here will override any specified in a config file. # Prefix the list here with "+" to use these queries and those in the config file. # queries: ./path/to/local/query, your-org/your-repo/queries@main - # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). - # If this step fails, then you should remove it and run the build manually (see below) - - name: Autobuild - uses: github/codeql-action/autobuild@v4 - - # â„šī¸ Command-line programs to run using the OS shell. - # 📚 https://git.io/JvXDl - - # âœī¸ If the Autobuild fails above, remove it and uncomment the following three lines - # and modify them (or add more) to build your code if your project - # uses a compiled language - - #- run: | - # make bootstrap - # make release - - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@v4 + with: + # Names the analysis the results belong to, so the two matrix legs + # are matched separately instead of by job identity alone. + category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/sphinx-books-tests.js.yml b/.github/workflows/sphinx-books-tests.js.yml index 8c443efb7..0945c909e 100644 --- a/.github/workflows/sphinx-books-tests.js.yml +++ b/.github/workflows/sphinx-books-tests.js.yml @@ -22,6 +22,14 @@ jobs: uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} + # Pinned like the packages it installs; the action applies it as an + # exact `pip==` requirement. + pip-version: '26.2.1' + cache: 'pip' + # Named explicitly: the default pattern matches `requirements.txt`, + # which is not the file the workflow installs, so the key would not + # change when a pinned version does. + cache-dependency-path: 'frontend/requirements_frozen.txt' - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable @@ -61,7 +69,6 @@ jobs: run: pnpm install --frozen-lockfile - name: Install Python dependencies run: | - python -m pip install --upgrade pip pip install -r requirements_frozen.txt pip install -e python/rst_code_example_pipeline - name: Run Webpack production diff --git a/.github/workflows/sphinx-content-tests.js.yml b/.github/workflows/sphinx-content-tests.js.yml index 840ace68a..d1df0c202 100644 --- a/.github/workflows/sphinx-content-tests.js.yml +++ b/.github/workflows/sphinx-content-tests.js.yml @@ -22,6 +22,14 @@ jobs: uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} + # Pinned like the packages it installs; the action applies it as an + # exact `pip==` requirement. + pip-version: '26.2.1' + cache: 'pip' + # Named explicitly: the default pattern matches `requirements.txt`, + # which is not the file the workflow installs, so the key would not + # change when a pinned version does. + cache-dependency-path: 'frontend/requirements_frozen.txt' - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable @@ -49,7 +57,6 @@ jobs: run: pnpm install --frozen-lockfile - name: Install Python dependencies run: | - python -m pip install --upgrade pip pip install -r requirements_frozen.txt pip install -e python/rst_code_example_pipeline - name: Run SPHINX engine tests diff --git a/.github/workflows/sphinx-plugin-tests.js.yml b/.github/workflows/sphinx-plugin-tests.js.yml index ca4cc9cb1..d6b5a6d65 100644 --- a/.github/workflows/sphinx-plugin-tests.js.yml +++ b/.github/workflows/sphinx-plugin-tests.js.yml @@ -28,6 +28,14 @@ jobs: uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} + # Pinned like the packages it installs; the action applies it as an + # exact `pip==` requirement. + pip-version: '26.2.1' + cache: 'pip' + # Named explicitly: the default pattern matches `requirements.txt`, + # which is not the file the workflow installs, so the key would not + # change when a pinned version does. + cache-dependency-path: 'frontend/requirements_frozen.txt' - name: Install OS Deps run: | sudo apt-get update && \ @@ -42,7 +50,6 @@ jobs: sudo sysctl -p - name: Install Python dependencies run: | - python -m pip install --upgrade pip pip install -r requirements_frozen.txt pip install -e python/rst_code_example_pipeline - name: Test Sphinx Widget Parser Plugin diff --git a/.github/workflows/typescript-tests.js.yml b/.github/workflows/typescript-tests.js.yml index 7491ae772..79b0c5390 100644 --- a/.github/workflows/typescript-tests.js.yml +++ b/.github/workflows/typescript-tests.js.yml @@ -29,6 +29,14 @@ jobs: uses: actions/setup-python@v7 with: python-version: ${{ matrix.python-version }} + # Pinned like the packages it installs; the action applies it as an + # exact `pip==` requirement. + pip-version: '26.2.1' + cache: 'pip' + # Named explicitly: the default pattern matches `requirements.txt`, + # which is not the file the workflow installs, so the key would not + # change when a pinned version does. + cache-dependency-path: 'frontend/requirements_frozen.txt' - uses: actions/checkout@v7 - name: Enable Corepack run: corepack enable @@ -54,7 +62,6 @@ jobs: run: pnpm install --frozen-lockfile - name: Install Python dependencies run: | - python -m pip install --upgrade pip pip install -r requirements_frozen.txt pip install -e python/rst_code_example_pipeline - name: Build HTML test pages