From 5241211a98c0bb7ee429adf28641af6ab25791b1 Mon Sep 17 00:00:00 2001 From: Sean Mauk Date: Wed, 5 Aug 2026 12:24:17 +0000 Subject: [PATCH 1/2] fix(ci): add least-privilege permissions blocks to workflows Resolves the 11 open actions/missing-workflow-permissions code-scanning alerts. Workflow-level contents: read on ci/release/add-to-project; the changes job additionally gets pull-requests: read for dorny/paths-filter, and release.yml's publish job keeps its stricter id-token block. Signed-off-by: Sean Mauk --- .github/workflows/add-to-project.yml | 3 +++ .github/workflows/ci.yml | 7 +++++++ .github/workflows/release.yml | 4 ++++ 3 files changed, 14 insertions(+) diff --git a/.github/workflows/add-to-project.yml b/.github/workflows/add-to-project.yml index 234e99a4..b0463860 100644 --- a/.github/workflows/add-to-project.yml +++ b/.github/workflows/add-to-project.yml @@ -2,6 +2,9 @@ name: Add issues to project on: issues: types: [opened, reopened] +# The job authenticates with ADD_TO_PROJECT_PAT; GITHUB_TOKEN needs nothing. +permissions: + contents: read jobs: add-to-project: runs-on: ubuntu-latest diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 642816d7..be09815d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -5,6 +5,9 @@ on: push: branches: [main] +permissions: + contents: read + concurrency: group: ci-${{ github.ref }} cancel-in-progress: true @@ -21,6 +24,10 @@ jobs: changes: runs-on: ubuntu-latest timeout-minutes: 5 + permissions: + contents: read + # dorny/paths-filter reads the PR's changed-file list via the API. + pull-requests: read outputs: code: ${{ steps.filter.outputs.code }} engine: ${{ steps.filter.outputs.engine }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 264718f3..9351fda9 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,6 +5,10 @@ on: tags: ["v*.*.*"] workflow_dispatch: # allow manual re-runs without re-tagging +# Least-privilege default; the publish job grants itself id-token: write. +permissions: + contents: read + jobs: build: name: Build sdist + wheel From 224a3302f5e5c09bf2bad9bb090a4325fa3d75dd Mon Sep 17 00:00:00 2001 From: Sean Mauk Date: Wed, 5 Aug 2026 12:24:17 +0000 Subject: [PATCH 2/2] fix(deps): bump gitpython 3.1.54 -> 3.1.58 Clears GHSA-3f7w-8rr8-f37f (high), GHSA-539m-9xh6-q6rr and GHSA-p538-c434-8v24 (medium). Transitive via streamlit; lock-only change. Signed-off-by: Sean Mauk --- uv.lock | 66 ++++++++++++++++++++++++++++----------------------------- 1 file changed, 33 insertions(+), 33 deletions(-) diff --git a/uv.lock b/uv.lock index efb6cee8..d23719d6 100644 --- a/uv.lock +++ b/uv.lock @@ -1370,14 +1370,14 @@ wheels = [ [[package]] name = "gitpython" -version = "3.1.54" +version = "3.1.58" source = { registry = "https://pypi.org/simple" } dependencies = [ { name = "gitdb" }, ] -sdist = { url = "https://files.pythonhosted.org/packages/5e/d5/3da0b92033887033f4c27f2dd109a303c4ca62813c7b3bb2511edb4777de/gitpython-3.1.54.tar.gz", hash = "sha256:53f2085e24a2cda300eed7c3fc5f1559ae289634b725e98acaf4791940247aa0", size = 225076, upload-time = "2026-07-22T04:08:51.403Z" } +sdist = { url = "https://files.pythonhosted.org/packages/26/d6/5f358ff283325580c2003a6d953aea18cfe10ae87b46f5ebc80fa3a386dc/gitpython-3.1.58.tar.gz", hash = "sha256:621416df10ef3fd0e19fabf9172ddeed0fa704d353d04f194eec56a625a95b22", size = 228498, upload-time = "2026-08-04T15:05:49.47Z" } wheels = [ - { url = "https://files.pythonhosted.org/packages/d1/b9/876f442a28df5c068ca69b0122d5c35e65fd2d2fa9992ea5cb5944ea00a6/gitpython-3.1.54-py3-none-any.whl", hash = "sha256:b90d7b3d9bc0238681d24369130826f0dcdb0ceaa45db67cf1d4ffa4c302dedf", size = 216575, upload-time = "2026-07-22T04:08:50.05Z" }, + { url = "https://files.pythonhosted.org/packages/ec/0c/9d8752098bc442f0726e64aa6135940b3a96809915d1aa4206c1bb97881d/gitpython-3.1.58-py3-none-any.whl", hash = "sha256:d331e722577f0fd7fc1f857419b3ecc07af66282b933d2a4d95f84a042fdd50f", size = 220183, upload-time = "2026-08-04T15:05:48.025Z" }, ] [[package]] @@ -1673,7 +1673,7 @@ name = "jaraco-classes" version = "3.4.0" source = { registry = "https://pypi.org/simple" } dependencies = [ - { name = "more-itertools" }, + { name = "more-itertools", marker = "platform_machine != 's390x'" }, ] sdist = { url = "https://files.pythonhosted.org/packages/06/c0/ed4a27bc5571b99e3cff68f8a9fa5b56ff7df1c2251cc715a652ddd26402/jaraco.classes-3.4.0.tar.gz", hash = "sha256:47a024b51d0239c0dd8c8540c6c7f484be3b8fcf0b2d85c13825780d3b3f3acd", size = 11780, upload-time = "2024-03-31T07:27:36.643Z" } wheels = [ @@ -1694,7 +1694,7 @@ name = "jaraco-functools" version = "4.4.0" source = { registry = "https://pypi.org/simple" } dependencies = [ - { name = "more-itertools" }, + { name = "more-itertools", marker = "platform_machine != 's390x'" }, ] sdist = { url = "https://files.pythonhosted.org/packages/0f/27/056e0638a86749374d6f57d0b0db39f29509cce9313cf91bdc0ac4d91084/jaraco_functools-4.4.0.tar.gz", hash = "sha256:da21933b0417b89515562656547a77b4931f98176eb173644c0d35032a33d6bb", size = 19943, upload-time = "2025-12-21T09:29:43.6Z" } wheels = [ @@ -1856,12 +1856,12 @@ name = "keyring" version = "25.7.0" source = { registry = "https://pypi.org/simple" } dependencies = [ - { name = "jaraco-classes" }, - { name = "jaraco-context" }, - { name = "jaraco-functools" }, - { name = "jeepney", marker = "sys_platform == 'linux'" }, - { name = "pywin32-ctypes", marker = "sys_platform == 'win32'" }, - { name = "secretstorage", marker = "sys_platform == 'linux'" }, + { name = "jaraco-classes", marker = "platform_machine != 's390x'" }, + { name = "jaraco-context", marker = "platform_machine != 's390x'" }, + { name = "jaraco-functools", marker = "platform_machine != 's390x'" }, + { name = "jeepney", marker = "platform_machine != 's390x' and sys_platform == 'linux'" }, + { name = "pywin32-ctypes", marker = "platform_machine != 's390x' and sys_platform == 'win32'" }, + { name = "secretstorage", marker = "platform_machine != 's390x' and sys_platform == 'linux'" }, ] sdist = { url = "https://files.pythonhosted.org/packages/43/4b/674af6ef2f97d56f0ab5153bf0bfa28ccb6c3ed4d1babf4305449668807b/keyring-25.7.0.tar.gz", hash = "sha256:fe01bd85eb3f8fb3dd0405defdeac9a5b4f6f0439edbb3149577f244a2e8245b", size = 63516, upload-time = "2025-11-16T16:26:09.482Z" } wheels = [ @@ -4323,8 +4323,8 @@ name = "secretstorage" version = "3.5.0" source = { registry = "https://pypi.org/simple" } dependencies = [ - { name = "cryptography" }, - { name = "jeepney" }, + { name = "cryptography", marker = "platform_machine != 's390x' and sys_platform != 'darwin' and sys_platform != 'win32'" }, + { name = "jeepney", marker = "platform_machine != 's390x' and sys_platform != 'darwin' and sys_platform != 'win32'" }, ] sdist = { url = "https://files.pythonhosted.org/packages/1c/03/e834bcd866f2f8a49a85eaff47340affa3bfa391ee9912a952a1faa68c7b/secretstorage-3.5.0.tar.gz", hash = "sha256:f04b8e4689cbce351744d5537bf6b1329c6fc68f91fa666f60a380edddcd11be", size = 19884, upload-time = "2025-11-23T19:02:53.191Z" } wheels = [ @@ -5034,13 +5034,13 @@ resolution-markers = [ "python_full_version < '3.14' and platform_machine != 's390x' and sys_platform == 'darwin'", ] dependencies = [ - { name = "filelock" }, - { name = "fsspec" }, - { name = "jinja2" }, - { name = "networkx" }, - { name = "setuptools" }, - { name = "sympy" }, - { name = "typing-extensions" }, + { name = "filelock", marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, + { name = "fsspec", marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, + { name = "jinja2", marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, + { name = "networkx", marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, + { name = "setuptools", marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, + { name = "sympy", marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, + { name = "typing-extensions", marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, ] wheels = [ { url = "https://download-r2.pytorch.org/whl/cpu/torch-2.13.0-cp313-cp313-macosx_14_0_arm64.whl", hash = "sha256:33449899ce5496c1b84b4853179d94fd102028ae1407314d9fb956bb79e70d09", upload-time = "2026-07-08T12:26:23Z" }, @@ -5065,13 +5065,13 @@ resolution-markers = [ "python_full_version < '3.14' and platform_machine == 's390x' and sys_platform == 'darwin'", ] dependencies = [ - { name = "filelock" }, - { name = "fsspec" }, - { name = "jinja2" }, - { name = "networkx" }, - { name = "setuptools" }, - { name = "sympy" }, - { name = "typing-extensions" }, + { name = "filelock", marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, + { name = "fsspec", marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, + { name = "jinja2", marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, + { name = "networkx", marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, + { name = "setuptools", marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, + { name = "sympy", marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, + { name = "typing-extensions", marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, ] wheels = [ { url = "https://download-r2.pytorch.org/whl/cpu/torch-2.13.0%2Bcpu-cp313-cp313-linux_s390x.whl", hash = "sha256:966d020354f465672dc7dd10d3a5c6cd17d7eb48620aa1d265b48a1f78f06898", upload-time = "2026-07-08T19:29:30Z" }, @@ -5102,9 +5102,9 @@ resolution-markers = [ "python_full_version < '3.14' and platform_machine != 's390x' and sys_platform == 'darwin'", ] dependencies = [ - { name = "numpy" }, - { name = "pillow" }, - { name = "torch", version = "2.13.0", source = { registry = "https://download.pytorch.org/whl/cpu" } }, + { name = "numpy", marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, + { name = "pillow", marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, + { name = "torch", version = "2.13.0", source = { registry = "https://download.pytorch.org/whl/cpu" }, marker = "platform_machine != 's390x' and sys_platform == 'darwin'" }, ] wheels = [ { url = "https://download-r2.pytorch.org/whl/cpu/torchvision-0.28.0-cp313-cp313-macosx_14_0_arm64.whl", hash = "sha256:d483b4aa3f5237569053f749cd1a2b5bb548ca456e40461a5dd087f21149d123", upload-time = "2026-07-08T12:26:40Z" }, @@ -5129,9 +5129,9 @@ resolution-markers = [ "python_full_version < '3.14' and platform_machine == 's390x' and sys_platform == 'darwin'", ] dependencies = [ - { name = "numpy" }, - { name = "pillow" }, - { name = "torch", version = "2.13.0+cpu", source = { registry = "https://download.pytorch.org/whl/cpu" } }, + { name = "numpy", marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, + { name = "pillow", marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, + { name = "torch", version = "2.13.0+cpu", source = { registry = "https://download.pytorch.org/whl/cpu" }, marker = "platform_machine == 's390x' or sys_platform != 'darwin'" }, ] wheels = [ { url = "https://download-r2.pytorch.org/whl/cpu/torchvision-0.28.0%2Bcpu-cp313-cp313-manylinux_2_28_aarch64.whl", hash = "sha256:879ae6d4e2e3651582fb7187eafd535601cb5d019595d47e2c874262a000e88e", upload-time = "2026-07-08T12:26:39Z" },