Skip to content

chore(release): pin PyPI workflow actions#1026

Open
njzjz-bot wants to merge 2 commits into
deepmodeling:masterfrom
njzjz-bot:fix/issue-1002
Open

chore(release): pin PyPI workflow actions#1026
njzjz-bot wants to merge 2 commits into
deepmodeling:masterfrom
njzjz-bot:fix/issue-1002

Conversation

@njzjz-bot

Copy link
Copy Markdown
Contributor

Fixes #1002.

Pin release-critical checkout, Python setup, and PyPI publishing actions to version tags.

Tests: Workflow YAML inspection; release workflow is not run by unit tests.

Why existing tests missed it: Floating action refs are supply-chain configuration and ordinary Python tests cannot detect their mutation.

Coding agent: Codex
Codex version: codex-cli 0.144.4
Model: gpt-5.6-sol
Reasoning effort: xhigh

Replace mutable master refs in the release workflow with current version tags for checkout, setup-python, and the PyPI publisher. Other workflows already used versioned actions, so ordinary test coverage could not detect this release-supply-chain risk.

Coding-Agent: Codex
Codex-Version: codex-cli 0.144.4
Model: gpt-5.6-sol
Reasoning-Effort: xhigh
@dosubot dosubot Bot added size:XS This PR changes 0-9 lines, ignoring generated files. dpdata github_actions Pull requests that update GitHub Actions code labels Jul 16, 2026
@coderabbitai

coderabbitai Bot commented Jul 16, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@njzjz, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 59 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 8cb6cb47-ab8c-43ff-beb1-5e50eac0ce81

📥 Commits

Reviewing files that changed from the base of the PR and between 0416b54 and 1b3cf5e.

📒 Files selected for processing (2)
  • .github/workflows/pub-pypi.yml
  • .github/workflows/pyright.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codspeed-hq

codspeed-hq Bot commented Jul 16, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

⚠️ Unknown Walltime execution environment detected

Using the Walltime instrument on standard Hosted Runners will lead to inconsistent data.

For the most accurate results, we recommend using CodSpeed Macro Runners: bare-metal machines fine-tuned for performance measurement consistency.

✅ 2 untouched benchmarks


Comparing njzjz-bot:fix/issue-1002 (1b3cf5e) with master (d2105f6)

Open in CodSpeed

@codecov

codecov Bot commented Jul 16, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.94%. Comparing base (0416b54) to head (1b3cf5e).
⚠️ Report is 12 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #1026      +/-   ##
==========================================
+ Coverage   86.87%   86.94%   +0.07%     
==========================================
  Files          89       90       +1     
  Lines        8266     9178     +912     
==========================================
+ Hits         7181     7980     +799     
- Misses       1085     1198     +113     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@wanghan-iapcm wanghan-iapcm left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving: correct supply-chain hardening for #1002. All three pins are verified current majors (actions/checkout@v7, actions/setup-python@v6, pypa/gh-action-pypi-publish@v1.14.0) and match the tag-pinning convention every other workflow already uses; pub-pypi.yml was the last file still on @master. Tag-pinning (not SHA) is the right choice here since the repo relies on Dependabot's github-actions ecosystem to bump these, and the token-based publish path is preserved by v1.14.0. Build and codecov green (docs/readthedocs red is the unrelated emscripten-forge outage, #1035). Optional follow-ups: pyright.yml:11 still uses actions/checkout@master (the last floating ref), and migrating the publish step to OIDC Trusted Publishing (as done for codecov in #926) would drop the long-lived PYPI_API_TOKEN.

@dosubot dosubot Bot added the lgtm This PR has been approved by a maintainer label Jul 17, 2026
Pin the final floating actions/checkout reference in the Pyright workflow to the current major release.

Coding-Agent: Codex
Codex-Version: codex-cli 0.144.6
Model: gpt-5.6-sol
Reasoning-Effort: xhigh
@njzjz

njzjz commented Jul 21, 2026

Copy link
Copy Markdown
Member

Addressed the remaining floating checkout reference in commit 1b3cf5e: pyright.yml now uses actions/checkout@v7, consistent with the repository's pinned-major convention. The Pyright workflow is green. Migrating PyPI publishing credentials to OIDC is a broader release-configuration change and was intentionally left outside this focused action-pinning PR.

Coding agent: Codex
Codex version: codex-cli 0.144.6
Model: gpt-5.6-sol
Reasoning effort: xhigh

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dpdata github_actions Pull requests that update GitHub Actions code lgtm This PR has been approved by a maintainer size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Code scan] PyPI release workflow uses floating master action refs

3 participants