From 12c764c0b8edf6b2a899de371bab6b84725d8c77 Mon Sep 17 00:00:00 2001 From: "Jason M. Gates" Date: Wed, 3 Jul 2024 09:38:54 -0600 Subject: [PATCH] ci: Tweak automated suggestions --- .github/workflows/codeql.yml | 39 ++----------------------- .github/workflows/dependency-review.yml | 9 +----- .pre-commit-config.yaml | 6 ++-- 3 files changed, 5 insertions(+), 49 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index bf8c642..799c486 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,21 +1,9 @@ -# For most projects, this workflow file will not need changing; you simply need -# to commit it to your repository. -# -# You may wish to alter this file to override the set of languages analyzed, -# or to provide custom queries or build logic. -# -# ******** NOTE ******** -# We have attempted to detect the languages in your repository. Please check -# the `language` matrix defined below to confirm you have the correct set of -# supported CodeQL languages. -# name: "CodeQL" on: push: branches: ["master"] pull_request: - # The branches below must be a subset of the branches above branches: ["master"] schedule: - cron: "0 0 * * 1" @@ -34,10 +22,6 @@ jobs: strategy: fail-fast: false - matrix: - language: ["python"] - # CodeQL supports [ $supported-codeql-languages ] - # Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support steps: - name: Harden Runner @@ -48,31 +32,12 @@ jobs: - name: Checkout repository uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0 - # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL uses: github/codeql-action/init@d958b976dc5b990f802df244f2dc5d807113327f # v2.25.11 with: - languages: ${{ matrix.language }} - # If you wish to specify custom queries, you can do so here or in a config file. - # By default, queries listed here will override any specified in a config file. - # Prefix the list here with "+" to use these queries and those in the config file. - - # Autobuild attempts to build any compiled languages (C/C++, C#, or Java). - # If this step fails, then you should remove it and run the build manually (see below) - - name: Autobuild - uses: github/codeql-action/autobuild@d958b976dc5b990f802df244f2dc5d807113327f # v2.25.11 - - # ℹī¸ Command-line programs to run using the OS shell. - # 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun - - # If the Autobuild fails above, remove it and uncomment the following three lines. - # modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance. - - # - run: | - # echo "Run, Build Application using script" - # ./location_of_script_within_repo/buildscript.sh + languages: python - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@d958b976dc5b990f802df244f2dc5d807113327f # v2.25.11 with: - category: "/language:${{matrix.language}}" + category: "/language:python" diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index ce491d1..a85ccfb 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -1,11 +1,3 @@ -# Dependency Review Action -# -# This Action will scan dependency manifest files that change as part of a Pull Request, -# surfacing known-vulnerable versions of the packages declared or updated in the PR. -# Once installed, if the workflow run is marked as required, -# PRs introducing known-vulnerable packages will be blocked from merging. -# -# Source repository: https://github.com/actions/dependency-review-action name: 'Dependency Review' on: [pull_request] @@ -23,5 +15,6 @@ jobs: - name: 'Checkout Repository' uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3.6.0 + - name: 'Dependency Review' uses: actions/dependency-review-action@0efb1d1d84fc9633afcdaad14c485cbbc90ef46c # v2.5.1 diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index bb6ae5c..aa4a2c3 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -46,15 +46,13 @@ repos: hooks: - id: pyroma additional_dependencies: ["poetry"] + - repo: https://github.com/gitleaks/gitleaks rev: v8.16.3 hooks: - id: gitleaks + - repo: https://github.com/jumanjihouse/pre-commit-hooks rev: 3.0.0 hooks: - id: shellcheck - - repo: https://github.com/pylint-dev/pylint - rev: v2.17.2 - hooks: - - id: pylint