Repository navigation
Conversation
| # Use actions-poetry to handle installation | ||
| - name: Install Poetry and Dependencies | ||
| uses: abatilo/actions-poetry@v4 | ||
| uses: abatilo/actions-poetry@0dd19c9498c3dc8728967849d0d2eae428a8a3d8 # v4 |
There was a problem hiding this comment.
I don't understand this change. Why is simply the version as before not applicable? when we update are we going to have to look for the tag instead of just going @v5?
There was a problem hiding this comment.
Sonar flagged this
We could remove that check but it's because of
https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions
And
We could use dependabot to enable this so we don't have to be looking up the hash each time
We probably aren't pinning hashes in other repo but I've started with all the supply chain stuff going on.
There was a problem hiding this comment.
alright. sounds good. as long as dependabot is able to update it.
|



Main's SonarCloud quality gate fails on three reliability findings and ten unpinned workflow dependencies. This fixes the reported findings without changing the runtime API.
Validation: 98 mock/doctest tests, strict mypy, pre-commit, and actionlint pass locally. All eight normal PR checks pass, including SonarCloud, CodeQL, and Python 3.9/latest unit tests. Failure probes confirm that undeleted data, HTTP 500, and unexpected errors fail, while the previous effective level and HTTP 404 are accepted. The corrected tests pass all 80 integration tests on Python 3.9 with production CDA and production schema. The remaining combinations in the full matrix are still running: https://github.com/HydrologicEngineeringCenter/cwms-python/actions/runs/34545073336.