Repository navigation
DEVOPS-1154: address warnings upon publishing Python packages from GitHub - #166
Conversation
There was a problem hiding this comment.
Pull request overview
Updates GitHub Actions workflows to address warnings when publishing Python packages from GitHub, shifting PyPI/TestPyPI publishing to OIDC trusted publishing (run in-repo) and aligning workflow calls to updated CI-tools implementations.
Changes:
- Switch PyPI/TestPyPI publishing to an in-workflow job that uses a composite action for OIDC trusted publishing.
- Remove reliance on
PYPI_TOKEN/TEST_PYPI_TOKENsecrets for publishing. - Update multiple reusable workflow
uses:references to CI-toolsDEVOPS-1154.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 5 comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/security_scan.yml | Updates CI-tools reusable workflow refs for Zizmor scanning jobs. |
| .github/workflows/python_deploy_prod.yml | Adds a dedicated in-repo PyPI publish job (OIDC) and updates CI-tools workflow refs. |
| .github/workflows/python_deploy_dev.yml | Adds a dedicated in-repo TestPyPI publish job (OIDC) and updates CI-tools workflow refs. |
| .github/workflows/pr_jira_actions.yml | Updates CI-tools reusable workflow ref for PR→Jira automation. |
| .github/workflows/issue_to_jira.yml | Updates CI-tools reusable workflow ref for issue→Jira automation. |
Suppressed comments (5)
.github/workflows/security_scan.yml:45
- Using a moving branch ref (
@DEVOPS-1154) for a reusable workflow makes the CI supply chain mutable (the branch can be force-pushed/deleted) and can break reproducibility/auditing. Prefer pinning to an immutable commit SHA (or a released tag once available).
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-zizmor-annotate.yml@DEVOPS-1154
.github/workflows/python_deploy_prod.yml:44
- Using a moving branch ref (
@DEVOPS-1154) for a reusable workflow makes the CI supply chain mutable (the branch can be force-pushed/deleted) and can break reproducibility/auditing. Prefer pinning to an immutable commit SHA (or a released tag once available).
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-release_pypi_assets.yml@DEVOPS-1154
.github/workflows/python_deploy_prod.yml:69
- Using a moving branch ref (
@DEVOPS-1154) for the composite action makes the publish step mutable and harder to audit. Prefer pinning to an immutable commit SHA (or a released tag once the CI-tools changes are released).
uses: MiraGeoscience/CI-tools/.github/actions/reusable-python-publish_to_pypi@DEVOPS-1154
.github/workflows/python_deploy_dev.yml:32
- Using a moving branch ref (
@DEVOPS-1154) for a reusable workflow makes the CI supply chain mutable (the branch can be force-pushed/deleted) and can break reproducibility/auditing. Prefer pinning to an immutable commit SHA (or a released tag once available).
uses: MiraGeoscience/CI-tools/.github/workflows/reusable-python-publish_pypi_package.yml@DEVOPS-1154
.github/workflows/python_deploy_dev.yml:59
- Using a moving branch ref (
@DEVOPS-1154) for the composite action makes the publish step mutable and harder to audit. Prefer pinning to an immutable commit SHA (or a released tag once the CI-tools changes are released).
uses: MiraGeoscience/CI-tools/.github/actions/reusable-python-publish_to_pypi@DEVOPS-1154
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
sebhmg
left a comment
There was a problem hiding this comment.
use shorter comment to explain about not using reusable worklfow for pypi publish
7aacdb1 to
8e58e45
Compare
|
|
DEVOPS-1154 - address warnings upon publishing Python packages from GitHub