Skip to content

[FIX, TEMPLATE] bump vulnerable dependencies (anyio, urllib3, PyJWT) #12

[FIX, TEMPLATE] bump vulnerable dependencies (anyio, urllib3, PyJWT)

[FIX, TEMPLATE] bump vulnerable dependencies (anyio, urllib3, PyJWT) #12

name: Template PR Inspection
on:
pull_request:
paths:
- 'src/fastapi_fastkit/fastapi_project_template/**'
types:
- opened
- synchronize
permissions:
contents: read
pull-requests: write
jobs:
inspect-changed-templates:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 0 # Fetch all history for git diff
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Setup PDM
uses: pdm-project/setup-pdm@v4
with:
# Pin the interpreter: without this PDM may resolve a newer runtime
# than the one actions/setup-python provisioned.
python-version: "3.12"
- name: Install dependencies
run: pdm install -G dev
- name: Verify Python version
run: pdm run python --version
- name: Setup UV
uses: astral-sh/setup-uv@v7
- name: Verify Docker and Compose
run: |
docker --version
docker compose version
- name: Inspect changed templates
# --offline keeps PR runs deterministic: dependency freshness is
# advisory and belongs to the weekly scheduled inspection.
run: pdm run python scripts/inspect-changed-templates.py --offline
- name: Create or Update PR Comment
if: always()
uses: actions/github-script@v7
with:
script: |
const marker = '<!-- template-inspection-bot -->';
const success = '${{ job.status }}' === 'success';
const successBody = `${marker}
✅ **Template Inspection Passed**
All changed templates have been validated successfully.
---
*Last updated: ${new Date().toISOString()}*`;
const failureBody = `${marker}
❌ **Template Inspection Failed**
Please check the workflow logs for details on what needs to be fixed.
[View Logs](${context.payload.repository.html_url}/actions/runs/${context.runId})
---
*Last updated: ${new Date().toISOString()}*`;
const body = success ? successBody : failureBody;
// Find existing bot comment
const { data: comments } = await github.rest.issues.listComments({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number
});
const botComment = comments.find(comment =>
comment.body.includes(marker)
);
if (botComment) {
// Update existing comment
await github.rest.issues.updateComment({
owner: context.repo.owner,
repo: context.repo.repo,
comment_id: botComment.id,
body: body
});
console.log('Updated existing comment');
} else {
// Create new comment
await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number,
body: body
});
console.log('Created new comment');
}