Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 7 additions & 6 deletions .github/workflows/check.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -213,15 +213,15 @@ jobs:
DIFF_AGAINST: HEAD
- name: 馃摛 Store macOS crash reports
if: always() && matrix.diagnostics && runner.os == 'macOS'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: crash-reports-${{ matrix.py }}-${{ matrix.os }}
path: ~/Library/Logs/DiagnosticReports/
if-no-files-found: ignore
retention-days: 14
- name: 馃摛 Store pytest diagnostics
if: always() && matrix.diagnostics
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: hang-diagnostics-${{ matrix.py }}-${{ matrix.os }}
path: |
Expand All @@ -230,10 +230,10 @@ jobs:
.tox/3.13t/log/
.tox/junit.3.13t.xml
include-hidden-files: true
if-no-files-found: warn
if-no-files-found: ignore
retention-days: 14
- name: 馃摛 Store coverage data
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: coverage-${{ matrix.py }}-${{ matrix.os }}-${{ strategy.job-index }}
# combined .coverage.<env> files and the per-process files of envs that do not combine them
Expand Down Expand Up @@ -262,7 +262,7 @@ jobs:
- name: 馃摝 Install tox
run: uv tool install --python-preference only-managed --python 3.14 "tox>=4.45" --with tox-uv
- name: 馃摜 Download coverage data
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
# one directory per test run: runs on different OSes write the same .coverage.<env> file name
pattern: coverage-*
Expand Down Expand Up @@ -336,14 +336,15 @@ jobs:
runs-on: ubuntu-24.04
permissions:
contents: read # check out the queries and their test fixtures
security-events: read # codeql-action needs it to reach its API endpoints
steps:
- name: 馃摜 Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: 馃攷 Install CodeQL
id: codeql
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: python
- name: 馃弮 Run query tests
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/codeql.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -27,13 +27,13 @@ jobs:
with:
persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: ${{ matrix.language }}
config-file: ./.github/codeql/codeql-config.yml
# the custom pack holds Python queries only, so the actions analysis must not load it
queries: ${{ matrix.language == 'python' && '+./.github/codeql/queries' || '' }}
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: "/language:${{ matrix.language }}"
4 changes: 2 additions & 2 deletions .github/workflows/pre-release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ jobs:
"$RUNNER_TEMP/release/bin/python" tasks/release.py --version "$BUMP" --no-push
echo "version=$(git describe --tags --exact-match)" >> "$GITHUB_OUTPUT"
- name: Store the changelog
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: release-changelog
path: docs/changelog.rst
Expand All @@ -78,7 +78,7 @@ jobs:
allowed-endpoints: >-
api.github.com:443
- name: Download the changelog
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: release-changelog
path: ${{ runner.temp }}/changelog
Expand Down
16 changes: 8 additions & 8 deletions .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -77,19 +77,19 @@ jobs:
subject-path: virtualenv.pyz
sbom-path: virtualenv.pyz.cdx.json
- name: Store the distribution packages
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ${{ env.dists-artifact-name }}
path: dist/*
- name: Store the SBOM
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: virtualenv-sbom
path: |
virtualenv.cdx.json
virtualenv.spdx.json
- name: Store the zipapp
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: virtualenv-zipapp
path: |
Expand Down Expand Up @@ -119,7 +119,7 @@ jobs:
fetch-depth: 0
persist-credentials: false
- name: Download all the dists
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ env.dists-artifact-name }}
path: dist/
Expand All @@ -128,11 +128,11 @@ jobs:
with:
attestations: true
- name: Download the zipapp
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: virtualenv-zipapp
- name: Download the SBOMs
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: virtualenv-sbom
# immutable releases reject assets added after creation, so every asset goes into this one call
Expand Down Expand Up @@ -201,12 +201,12 @@ jobs:
uv venv --python 3.14 --python-preference only-managed "$RUNNER_TEMP/tools"
uv pip sync --python "$RUNNER_TEMP/tools" --require-hashes tasks/release-requirements.txt
- name: Download expected distributions
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ env.dists-artifact-name }}
path: expected/
- name: Download expected SBOMs
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: virtualenv-sbom
path: expected/
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/scorecard.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:
analysis:
name: 馃攷 scorecard analysis
if: github.repository_owner == 'pypa'
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions:
actions: read # read workflow runs for the Packaging check
checks: read # read check runs for the CI-Tests and SAST checks
Expand All @@ -33,6 +33,6 @@ jobs:
results_file: results.sarif
results_format: sarif
publish_results: true
- uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
- uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
sarif_file: results.sarif
16 changes: 9 additions & 7 deletions .github/workflows/upgrade.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -24,15 +24,17 @@ jobs:
disable-sudo-and-containers: true
allowed-endpoints: >-
api.github.com:443 files.pythonhosted.org:443 github.com:443 pypi.org:443 raw.githubusercontent.com:443 registry.npmjs.org:443 release-assets.githubusercontent.com:443 releases.astral.sh:443
- name: Install uv
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
- name: Install tox
run: uv tool install --python-preference only-managed --python 3.14 "tox>=4.32" --with tox-uv
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Install uv
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
enable-cache: false # the egress allowlist above blocks the cache service
- name: Install tox
run: uv tool install --python-preference only-managed --python 3.14 "tox>=4.32" --with tox-uv
- name: Fetch upstream tags for versioning
run: git fetch --force --tags https://github.com/pypa/virtualenv.git
- name: Pin the newest CI test tools
Expand Down Expand Up @@ -75,7 +77,7 @@ jobs:
run: git diff --cached --binary --no-ext-diff --no-textconv > "$RUNNER_TEMP/upgrade.patch"
- name: Store upgrade patch
if: steps.upgrade.outputs.changed == 'true' && steps.age-check.outputs.skip == 'false'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: upgrade-patch
path: ${{ runner.temp }}/upgrade.patch
Expand Down Expand Up @@ -106,15 +108,15 @@ jobs:
fetch-depth: 0
persist-credentials: true # zizmor: ignore[artipacked] create-pull-request and the changelog rename push with it
- name: Download upgrade patch
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: upgrade-patch
path: ${{ runner.temp }}/upgrade-patch
- name: Validate and apply upgrade patch
run: python tasks/apply_upgrade_patch.py "$RUNNER_TEMP/upgrade-patch/upgrade.patch"
- name: Create Pull Request
id: cpr
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
commit-message: "Upgrade embedded dependencies"
# the checkout pins github.sha, a detached HEAD, so the action cannot infer the base branch
Expand Down
20 changes: 10 additions & 10 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
@@ -1,35 +1,35 @@
repos:
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: 3e8a8703264a2f4a69428a0aa4dcb512790b2c8c # frozen: v6.0.0
rev: v6.0.0
hooks:
- id: end-of-file-fixer
- id: trailing-whitespace
- repo: https://github.com/python-jsonschema/check-jsonschema
rev: 4f85d46a92dc17713078e5de73f8a13190edf6fc # frozen: 0.38.2
rev: "0.38.2"
hooks:
- id: check-github-workflows
args: ["--verbose"]
- repo: https://github.com/codespell-project/codespell
rev: 57b21406f092110c18776e39b0bda50d37c945c8 # frozen: v2.4.3
rev: v2.4.3
hooks:
- id: codespell
args: ["--write-changes"]
- repo: https://github.com/tox-dev/tox-toml-fmt
rev: "2863761a0c1b4a6e9fea638b27657b81f400543b" # frozen: v1.10.3
rev: "v1.10.3"
hooks:
- id: tox-toml-fmt
- repo: https://github.com/tox-dev/pyproject-fmt
rev: "59e7b26529dc6f15c43063064b8b06ded60d0910" # frozen: v2.29.4
rev: "v2.29.4"
hooks:
- id: pyproject-fmt
- repo: https://github.com/astral-sh/ruff-pre-commit
rev: "a56c0b927e6465d37cae3e97d35d4d18ab2b96cd" # frozen: v0.16.9
rev: "v0.16.10"
hooks:
- id: ruff-format
- id: ruff
args: ["--fix", "--unsafe-fixes", "--exit-non-zero-on-fix"]
- repo: https://github.com/google/yamlfmt
rev: "b5ca1890231d5e1e5181fef75a1be609d1e25029" # frozen: v0.21.0
rev: "v0.21.0"
hooks:
- id: yamlfmt
- repo: local
Expand All @@ -51,17 +51,17 @@ repos:
files: '^docs/changelog/'
exclude: '^docs/changelog/(examples\.rst|template\.jinja2|\d+\.(feature|bugfix|doc|deprecation|removal)\.rst)$'
- repo: https://github.com/LilSpazJoekp/docstrfmt
rev: c1813841673cdcd6cf602dde1edb78a5d5e45235 # frozen: v2.2.1
rev: v2.2.1
hooks:
- id: docstrfmt
args: ["-l", "120"]
additional_dependencies: ["sphinx>=9.1"]
- repo: https://github.com/zizmorcore/zizmor-pre-commit
rev: fa412071e4f5d44d44f9e365f4676f9df92456a2 # frozen: v1.30.1
rev: v1.30.1
hooks:
- id: zizmor
- repo: https://github.com/crate-ci/typos
rev: 4141ff14cb566df76c473c786332c186a4fd71d1 # frozen: v1.50.3
rev: typos-dict-v0.14.2
hooks:
- id: typos
- repo: meta
Expand Down
Loading
Loading