Skip to content

chore: create the next release - #1439

Merged
behnazh-w merged 21 commits into
releasefrom
main
Jul 26, 2026
Merged

chore: create the next release#1439
behnazh-w merged 21 commits into
releasefrom
main

Conversation

@behnazh-w

Copy link
Copy Markdown
Member

No description provided.

behnazh-w and others added 21 commits April 27, 2026 10:26
Bumps Macaron GitHub Action to v0.24.0 and update the docs. We also ignore GHSA-58qw-9mgm-455v for now until a patch is available.

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
)

Semgrep output for Macaron is more descriptive, including the stdout and stderr of Semgrep.

Signed-off-by: Carl Flottmann <carl.flottmann@oracle.com>
… only individual distribution files (#1387)

Signed-off-by: Jens Troeger <jens.troeger@light-speed.de>
Signed-off-by: Jens Troeger <jens.troeger@light-speed.de>
…#1399)

Reverts #1389

More investigation is required before we make this change permanent, based on the PRs that Dependabot openened.

Signed-off-by: Jens Troeger <jens.troeger@light-speed.de>
This PR updates how we resolve commits when an attestation/provenance is present.

In some cases, the provenance captures the workflow commit that triggered the release, while the actual release tag points to a different commit that is automatically generated and pushed afterward. This leads to inconsistencies when identifying the “true” commit.

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Add companion documentation for the Macaron BuildSpec schema and link it from the gen-build-spec CLI docs.

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
…1388)

Semgrep rules for detection common virtual MAC addresses, windows defender evasion, and IP information gathering.

Signed-off-by: Carl Flottmann <carl.flottmann@oracle.com>
Fix PyPI package temp directory cleanup leaks during malware/source analysis.

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Fixed deprecated OpenSSL URL use.

Signed-off-by: Abhinav Pradeep <abhinav.pradeep@oracle.com>
Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
)

Update cryptography to address pip-audit issue and remove the resolved advisory.

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
This PR updates the go dependencies and adjusts the dataflow analysis.

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
…argv array and direct execution (#1424)

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
… code formatters and linter hooks (#1419)

This change replaces black, bandit, isort, flake8, and pyupgrade git hooks with a single ruff hook.

Signed-off-by: Jens Troeger <jens.troeger@light-speed.de>
…=8.3.3 (#1432)

Signed-off-by: Abhinav Pradeep <abhinav.pradeep@oracle.com>
…aries. (#1408)

Modified the buildspec to introduce the concept of a SpecBuildRequirementDict. This provides a richer description of build dependencies. Added inference for the maturin build tool in specific. Rust-related build dependancies are read from the Cargo.lock/toml and the right Rust toolchain versions are inferred.

Signed-off-by: Abhinav Pradeep <abhinav.pradeep@oracle.com>
)

This PR addresses the advisories for the mcp transitive dependency. The semgrep package that uses this dependency currently pins this package and we are not able to use a fixed version. Since we do not use the mcp package directly, we will ignore the advisories for now.

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Update semgrep to the latest version and remove the ignored advisories found in its dependencies. This PR also improves some of the tests that would fail on Python 3.14.

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@oracle-contributor-agreement oracle-contributor-agreement Bot added the OCA Verified All contributors have signed the Oracle Contributor Agreement. label Jul 26, 2026
@behnazh-w
behnazh-w merged commit fc3429c into release Jul 26, 2026
40 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

OCA Verified All contributors have signed the Oracle Contributor Agreement.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants