Skip to content

ci: add a lint check and Dependabot config - #29

Open
davidberenstein1957 wants to merge 15 commits into
mainfrom
ci/default-check-and-dependabot
Open

davidberenstein1957 wants to merge 15 commits into
mainfrom
ci/default-check-and-dependabot

Conversation

@davidberenstein1957

@davidberenstein1957 davidberenstein1957 commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

What and why

The branch ruleset on main requires a status check named default, but no workflow in this repository reports it, so every merge has needed an admin bypass. This PR adds .github/workflows/ci.yml with a lint job that runs on every pull request and needs no secrets. The job is named after what it runs, and the ruleset should require lint instead of default.

lint job

  • uv run --python 3.12 python -m compileall over the whole repository (syntax check)
  • uv pip compile for every tracked requirements*.txt and pyproject.toml, each resolved from its own folder for Python 3.12 on Linux with the PyTorch CUDA index available. New folders are picked up without editing the workflow.

Every action in ci.yml is pinned to a full commit SHA, with the version in a trailing comment. Dependabot's github-actions updates keep the SHA and the comment current.

Dependabot

.github/dependabot.yml uses directory globs where several folders share an ecosystem, so new folders are covered without a config change. It runs weekly, groups minor and patch updates into one PR per ecosystem, and keeps GitHub's default limit of 5 open pull requests (security updates don't count toward it). Dependabot PRs get no Actions secrets, which is why the lint job uses none.

  • pip: /
  • github-actions: /

Hardening

  • The Dependabot docker entry for /.github/workflows is removed. No workflow here uses a container image now that Semgrep has moved out.

Semgrep

This PR no longer adds a Semgrep job. Semgrep runs from .github/workflows/semgrep.yml in PrunaAI/.github (PrunaAI/.github#1), which an org ruleset will require on every repository's default branch.

Before merging

Change the required status check in this repository's ruleset from default to lint first. Until then this PR fails its own required check. The org and repo rule changes are tracked in PrunaAI/prunatree#639.

Testing

  • dependabot.yml validated with check-jsonschema --builtin-schema vendor.dependabot.
  • ci.yml checked with actionlint; the ruleset must require lint before this PR can merge.
  • The lint steps were run locally on main unless a note above says otherwise.

Commits

  • 3a00c99 ci: add default status check and Dependabot config
  • 2c412f3 ci: pin actions in default workflow to commit SHAs
  • a70069e ci: check that pinned dependencies resolve
  • be8f7aa ci: raise the Dependabot open pull request limit to 50
  • a4e17e2 ci: effectively remove the Dependabot open pull request limit
  • ec4de14 ci: find Python manifests instead of listing them
  • f2eade3 ci: add a Semgrep job for findings a pull request adds
  • 0d84f43 ci: write resolved requirements to the runner temp dir
  • 77f56f7 ci: drop the PyTorch CUDA index from the resolve step
  • 7048459 ci: add a 7-day Dependabot cooldown and track the Semgrep image
  • 515774b ci: move Semgrep to the org ruleset and name the CI job
  • e239140 ci: drop the unused Dependabot docker entry for workflows
  • 0ca157c ci: cap Dependabot open pull requests at 50
  • f0e49a6 ci: report the lint check as lint, not default
  • b23cbe2 ci: use the default Dependabot open pull request limit

The default check now syntax-checks the whole repository and resolves every requirements file and pyproject.toml that git tracks, resolved from its own folder with the PyTorch CUDA index available. MANIFESTS and EXCLUDE narrow it where needed.
Runs p/default and p/trailofbits at ERROR severity with --baseline-commit set to the pull request base, so existing findings do not fail it. The image and checkout are pinned by digest and SHA.
uv writes a temp file next to the -o path, which fails under /dev.
pyproject.toml pins no CUDA torch builds, so the cu128 index and
unsafe-best-match only widen the resolver's sources.
Every ecosystem waits 7 days before proposing a new release. The Semgrep
job uses the container image: form, and a docker entry for
/.github/workflows lets Dependabot bump its tag and digest.
@davidberenstein1957 davidberenstein1957 changed the title ci: add default status check and Dependabot config ci: add a lint check and Dependabot config Sep 28, 2026
@davidberenstein1957
davidberenstein1957 force-pushed the ci/default-check-and-dependabot branch from 6e10e9e to f0e49a6 Compare September 29, 2026 10:35
Drop open-pull-requests-limit: 50 so each entry falls back to the
default of 5. The weekly schedule and grouping stay the same, and
security updates are not subject to the limit.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant