Skip to content

build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 #1446

build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0

build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 #1446

Workflow file for this run

# This workflows will upload a Python Package using Twine when a release is created
# For more information see: https://help.github.com/en/actions/language-and-framework-guides/using-python-with-github-actions#publishing-to-package-registries
name: Upload Python Package
on:
release:
types: [published] # Once manually verified, draft is released
# No support for reusable workflows (yet): https://github.com/pypi/warehouse/issues/11096
pull_request:
types: [opened, synchronize, reopened]
permissions:
contents: read
jobs:
build:
name: Build distribution 📦
runs-on: ubuntu-latest
permissions:
contents: read
attestations: write
id-token: write
steps:
- name: "Harden the runner (Block egress traffic: Only allow calls to allowed endpoints)"
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: block
allowed-endpoints: >+
github.com:443
api.github.com:443
release-assets.githubusercontent.com:443
pypi.org:443
files.pythonhosted.org:443
fulcio.sigstore.dev:443
rekor.sigstore.dev:443
tuf-repo-cdn.sigstore.dev:443
api.osv.dev:443
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
fetch-depth: 0 # Fetches all history and tags
- name: Set up Python
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: '3.x'
- name: Install dependencies
run: python -m pip install .[wheel]
- name: Audit runtime dependencies for CVEs (C-043)
run: |
pip install .[cve-audit]
pip-audit --vulnerability-service osv .
- name: Build a binary wheel and a source tarball
run: python3 -m build
- name: Generate SBOM for Python distribution
run: python script/create_sbom.py --py --output-dir dist-sbom
- name: Generate OSCAL Component Definition
run: |
mkdir -p dist-oscal
VERSION=$(python -c "import importlib.metadata; print(importlib.metadata.version('dfetch'))")
python -m security.compliance \
--component dist-oscal/dfetch.component-definition.json \
--version "$VERSION" \
--track-b-only
- name: Store the distribution packages
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: python-package-distributions
path: dist/
- name: Find SBOM path
id: find-sbom
run: |
SBOM=$(find dist-sbom -name '*.cdx.json' -maxdepth 1 | head -1)
echo "path=$SBOM" >> "$GITHUB_OUTPUT"
- name: Attest Python distribution with SBOM
uses: actions/attest@a1948c3f048ba23858d222213b7c278aabede763 # v4.1.1
with:
subject-path: 'dist/*.whl,dist/*.tar.gz'
predicate-type: 'https://cyclonedx.org/bom'
predicate-path: ${{ steps.find-sbom.outputs.path }}
- name: Store the SBOM
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: python-sbom
path: dist-sbom/
- name: Attest OSCAL build provenance
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
with:
subject-path: dist-oscal/dfetch.component-definition.json
- name: Store the OSCAL Component Definition
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: oscal-component-definition
path: dist-oscal/
publish-to-testpypi:
name: Publish Python distribution 📦 to TestPyPI
needs:
- build
runs-on: ubuntu-latest
environment:
name: testpypi
url: https://test.pypi.org/p/dfetch
permissions:
id-token: write
steps:
- name: Download all the dists
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: python-package-distributions
path: dist/
- name: Publish distribution 📦 to TestPyPI
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1
with:
repository-url: https://test.pypi.org/legacy/
skip-existing: true
- name: Test install from TestPyPI
run: |
pip install --pre --index-url https://test.pypi.org/simple/ dfetch --extra-index-url https://pypi.org/simple --user
dfetch --help
deploy:
if: github.event_name == 'release'
runs-on: ubuntu-latest
needs:
- build
environment:
name: pypi
url: https://pypi.org/p/dfetch
permissions:
id-token: write
contents: write
steps:
- name: Download all the dists
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: python-package-distributions
path: dist/
- name: Publish distribution 📦 to PyPI
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1
with:
skip-existing: true
- name: Download SBOM
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: python-sbom
path: dist-sbom/
- name: Download OSCAL Component Definition
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: oscal-component-definition
path: dist-oscal/
- name: Upload SBOM and OSCAL to GitHub Release
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v2.5.0
with:
tag_name: ${{ github.event.release.tag_name }}
files: |
dist-sbom/*
dist-oscal/*
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}