-
Notifications
You must be signed in to change notification settings - Fork 5
169 lines (155 loc) · 5.76 KB
/
Copy pathpython-publish.yml
File metadata and controls
169 lines (155 loc) · 5.76 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
# This workflows will upload a Python Package using Twine when a release is created
# For more information see: https://help.github.com/en/actions/language-and-framework-guides/using-python-with-github-actions#publishing-to-package-registries
name: Upload Python Package
on:
release:
types: [published] # Once manually verified, draft is released
# No support for reusable workflows (yet): https://github.com/pypi/warehouse/issues/11096
pull_request:
types: [opened, synchronize, reopened]
permissions:
contents: read
jobs:
build:
name: Build distribution 📦
runs-on: ubuntu-latest
permissions:
contents: read
attestations: write
id-token: write
steps:
- name: "Harden the runner (Block egress traffic: Only allow calls to allowed endpoints)"
uses: step-security/harden-runner@05e31511f85b41b11d1cf0ef85d0992719546e2c # v2.21.0
with:
egress-policy: block
allowed-endpoints: >+
github.com:443
api.github.com:443
release-assets.githubusercontent.com:443
pypi.org:443
files.pythonhosted.org:443
fulcio.sigstore.dev:443
rekor.sigstore.dev:443
tuf-repo-cdn.sigstore.dev:443
api.osv.dev:443
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
fetch-depth: 0 # Fetches all history and tags
- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: '3.x'
- name: Install dependencies
run: python -m pip install .[wheel]
- name: Audit runtime dependencies for CVEs (C-043)
run: |
pip install .[cve-audit]
pip-audit --vulnerability-service osv .
- name: Build a binary wheel and a source tarball
run: python3 -m build
- name: Generate SBOM for Python distribution
run: python script/create_sbom.py --py --output-dir dist-sbom
- name: Generate OSCAL Component Definition
run: |
mkdir -p dist-oscal
VERSION=$(python -c "import importlib.metadata; print(importlib.metadata.version('dfetch'))")
python -m security.compliance \
--component dist-oscal/dfetch.component-definition.json \
--version "$VERSION" \
--track-b-only
- name: Store the distribution packages
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: python-package-distributions
path: dist/
- name: Find SBOM path
id: find-sbom
run: |
SBOM=$(find dist-sbom -name '*.cdx.json' -maxdepth 1 | head -1)
echo "path=$SBOM" >> "$GITHUB_OUTPUT"
- name: Attest Python distribution with SBOM
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-path: 'dist/*.whl,dist/*.tar.gz'
predicate-type: 'https://cyclonedx.org/bom'
predicate-path: ${{ steps.find-sbom.outputs.path }}
- name: Store the SBOM
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: python-sbom
path: dist-sbom/
- name: Attest OSCAL build provenance
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-path: dist-oscal/dfetch.component-definition.json
- name: Store the OSCAL Component Definition
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: oscal-component-definition
path: dist-oscal/
publish-to-testpypi:
name: Publish Python distribution 📦 to TestPyPI
needs:
- build
runs-on: ubuntu-latest
environment:
name: testpypi
url: https://test.pypi.org/p/dfetch
permissions:
id-token: write
steps:
- name: Download all the dists
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: python-package-distributions
path: dist/
- name: Publish distribution 📦 to TestPyPI
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1
with:
repository-url: https://test.pypi.org/legacy/
skip-existing: true
- name: Test install from TestPyPI
run: |
pip install --pre --index-url https://test.pypi.org/simple/ dfetch --extra-index-url https://pypi.org/simple --user
dfetch --help
deploy:
if: github.event_name == 'release'
runs-on: ubuntu-latest
needs:
- build
environment:
name: pypi
url: https://pypi.org/p/dfetch
permissions:
id-token: write
contents: write
steps:
- name: Download all the dists
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: python-package-distributions
path: dist/
- name: Publish distribution 📦 to PyPI
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1
with:
skip-existing: true
- name: Download SBOM
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: python-sbom
path: dist-sbom/
- name: Download OSCAL Component Definition
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: oscal-component-definition
path: dist-oscal/
- name: Upload SBOM and OSCAL to GitHub Release
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v2.5.0
with:
tag_name: ${{ github.event.release.tag_name }}
files: |
dist-sbom/*
dist-oscal/*
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}