Conversation
Bumps Macaron GitHub Action to v0.24.0 and update the docs. We also ignore GHSA-58qw-9mgm-455v for now until a patch is available. Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
… only individual distribution files (#1387) Signed-off-by: Jens Troeger <jens.troeger@light-speed.de>
Signed-off-by: Jens Troeger <jens.troeger@light-speed.de>
This PR updates how we resolve commits when an attestation/provenance is present. In some cases, the provenance captures the workflow commit that triggered the release, while the actual release tag points to a different commit that is automatically generated and pushed afterward. This leads to inconsistencies when identifying the “true” commit. Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Add companion documentation for the Macaron BuildSpec schema and link it from the gen-build-spec CLI docs. Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
…1388) Semgrep rules for detection common virtual MAC addresses, windows defender evasion, and IP information gathering. Signed-off-by: Carl Flottmann <carl.flottmann@oracle.com>
Fix PyPI package temp directory cleanup leaks during malware/source analysis. Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Fixed deprecated OpenSSL URL use. Signed-off-by: Abhinav Pradeep <abhinav.pradeep@oracle.com>
Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
This PR updates the go dependencies and adjusts the dataflow analysis. Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
…argv array and direct execution (#1424) Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
… code formatters and linter hooks (#1419) This change replaces black, bandit, isort, flake8, and pyupgrade git hooks with a single ruff hook. Signed-off-by: Jens Troeger <jens.troeger@light-speed.de>
…=8.3.3 (#1432) Signed-off-by: Abhinav Pradeep <abhinav.pradeep@oracle.com>
…aries. (#1408) Modified the buildspec to introduce the concept of a SpecBuildRequirementDict. This provides a richer description of build dependencies. Added inference for the maturin build tool in specific. Rust-related build dependancies are read from the Cargo.lock/toml and the right Rust toolchain versions are inferred. Signed-off-by: Abhinav Pradeep <abhinav.pradeep@oracle.com>
) This PR addresses the advisories for the mcp transitive dependency. The semgrep package that uses this dependency currently pins this package and we are not able to use a fixed version. Since we do not use the mcp package directly, we will ignore the advisories for now. Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
Update semgrep to the latest version and remove the ignored advisories found in its dependencies. This PR also improves some of the tests that would fail on Python 3.14. Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.