Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
54 commits
Select commit Hold shift + click to select a range
7ac3398
apply dependabot insights
alain-sv May 13, 2026
22d50aa
minor
alain-sv May 13, 2026
2a89660
chore(ci): SHA-pin actions/checkout and actions/setup-python (#43)
alain-sv May 13, 2026
297d98e
docs(changelog): add unreleased dependency security refresh entry (#44)
alain-sv May 13, 2026
1c41f54
chore(ci): add uv cache-suffix per Python version + update AGENTS.md …
alain-sv May 13, 2026
00aad5e
Merge branch 'main' into develop
alain-sv May 13, 2026
1f5c176
supervaizer-v2-mvp-contracts (#47)
alain-sv May 17, 2026
d7c98b9
Minor
alain-sv May 17, 2026
b192229
Merge branch 'main' into develop
alain-sv May 17, 2026
789b0c6
chore: update changelog for Supervaizer v2 enhancements and API key v…
alain-sv May 17, 2026
da4b00d
Merge branch 'main' into develop
alain-sv May 17, 2026
c977b6e
workspace-agent-grants (#50)
alain-sv May 19, 2026
a12b628
minor
alain-sv May 19, 2026
a761421
Merge branch 'main' into develop
alain-sv May 20, 2026
1f20b22
feat(logging): implement structured logging for Cloud Logging compati…
alain-sv May 20, 2026
746a04f
Merge branch 'main' into develop
alain-sv May 24, 2026
75a3a0d
Minor
alain-sv May 24, 2026
612001f
Merge branch 'main' into develop
alain-sv May 26, 2026
3324db5
codex/supervaizer-lifespan-cleanup (#54)
alain-sv May 26, 2026
e7834a2
codex/refactor-server-modules (#55)
alain-sv May 26, 2026
4fed877
minor
alain-sv May 26, 2026
afaf602
codex/agent-interviewer-workspace-jobs-refresh (#56)
alain-sv May 26, 2026
ceede13
Refactor pre-commit configuration and enhance agent validation
alain-sv May 26, 2026
62f299d
Merge branch 'main' into develop
alain-sv May 27, 2026
ea6ce6c
chore(deps): bump uv from 0.11.14 to 0.11.15 (#58)
dependabot[bot] May 30, 2026
770a668
chore(deps): bump starlette from 0.50.0 to 1.0.1 (#60)
dependabot[bot] Jun 6, 2026
15e586e
chore(deps): bump trufflesecurity/trufflehog from 3.95.3 to 3.95.5 (#61)
dependabot[bot] Jun 9, 2026
4d5703a
feat(.agents): add skill symlinks from runwaize skills cookbook
alain-sv Jun 17, 2026
f197480
chore(deps): bump astral-sh/setup-uv from 8.1.0 to 8.2.0 (#62)
dependabot[bot] Jun 20, 2026
b50b3e9
chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#63)
dependabot[bot] Jun 20, 2026
4461b3e
chore(deps): bump starlette from 1.0.1 to 1.3.1 (#66)
dependabot[bot] Jun 20, 2026
287b498
chore(deps): bump cryptography from 48.0.0 to 48.0.1 (#67)
dependabot[bot] Jun 20, 2026
d3dcc08
chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#68)
dependabot[bot] Jul 2, 2026
5712dfd
chore(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.1 (#69)
dependabot[bot] Jul 2, 2026
b64d982
chore(deps): bump trufflesecurity/trufflehog from 3.95.5 to 3.95.6 (#70)
dependabot[bot] Jul 2, 2026
dbd4e3f
codex/managed-context-sdk (#65)
alain-sv Jul 2, 2026
665ef50
✨ feat(contracts): add V2ContextAssignment for context.assign (#71)
alain-sv Jul 2, 2026
ec535d1
feat: bump version to1.3.0 and update deps; iterate nested (#73)
alain-sv Jul 2, 2026
4e8fc0f
changelog
alain-sv Jul 2, 2026
a09ef1a
chore(deps): bump actions/setup-python from 6.2.0 to 6.3.0 (#75)
dependabot[bot] Jul 7, 2026
6a53535
chore(deps): bump trufflesecurity/trufflehog from 3.95.6 to 3.95.7 (#76)
dependabot[bot] Jul 7, 2026
9bf38b0
Merge branch 'main' into develop
alain-sv Jul 7, 2026
fe1d11d
security: review summary (redacted) + safe P0/P1 hardening (#77)
alain-sv Jul 7, 2026
7cdb2d9
chore(deps): bump trufflesecurity/trufflehog from 3.95.7 to 3.95.9 (#81)
dependabot[bot] Aug 26, 2026
a0453f0
chore(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2 (#82)
dependabot[bot] Aug 26, 2026
705bddb
chore(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.2 (#83)
dependabot[bot] Aug 26, 2026
334da0e
chore(deps): bump pyasn1 from 0.6.3 to 0.6.4 (#84)
dependabot[bot] Aug 26, 2026
1dfad10
chore(deps): bump actions/setup-python from 6.3.0 to 7.0.0 (#85)
dependabot[bot] Aug 26, 2026
d373ff6
chore(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (…
dependabot[bot] Aug 26, 2026
b14aaaf
chore(deps): bump cryptography from 49.0.0 to 50.0.0 (#87)
dependabot[bot] Aug 26, 2026
96c2789
feat: add generic job setup contract (#89)
alain-sv Aug 26, 2026
9b0e72a
doc
alain-sv Aug 28, 2026
595f33a
Merge branch 'main' into develop
alain-sv Aug 28, 2026
5d7244c
[MINOR] chore: merge develop to main
alain-sv Aug 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 0 additions & 7 deletions .agent/project.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,13 +6,6 @@ Supervaizer is the open-source controller library and FastAPI server that AI age

This repo is public and packaged for external users, so API compatibility, typed payloads, generated documentation, and clear tests matter more than local convenience.

## Local Glossary / Terminology

- **Controller**: The Supervaizer FastAPI service embedded with or run alongside an AI agent.
- **Studio**: The Supervaize SaaS platform that receives registration/events and operates mapped agents.
- **Mapped agent**: An agent capability exposed through Supervaizer for Studio control.
- **Registration payload**: The `server.register` payload consumed by Studio.

## Data Sensitivity Notes

- Do not log or commit API keys, server secrets, workspace tokens, or customer data.
Expand Down
1 change: 1 addition & 0 deletions .claude/skills/gitnexus/gitnexus-cli/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ Run from the project root. This parses all source files, builds the knowledge gr
| `--force` | Force full re-index even if up to date |
| `--embeddings` | Enable embedding generation for semantic search (off by default) |
| `--drop-embeddings` | Drop existing embeddings on rebuild. By default, an `analyze` without `--embeddings` preserves them. |
| `--pdg` | Build the program-dependence layers used by `explain` and `pdg_query` (taint, CDG, and REACHING_DEF). |

**When to run:** First time in a project, after major code changes, or when `gitnexus://repo/{name}/context` reports the index is stale. In Claude Code, a PostToolUse hook detects staleness after `git commit` and `git merge` and notifies the agent to run `analyze` — the hook does not run analyze itself, to avoid blocking the agent for up to 120s and risking KuzuDB corruption on timeout.

Expand Down
20 changes: 16 additions & 4 deletions .claude/skills/gitnexus/gitnexus-debugging/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,10 @@ description: "Use when the user is debugging a bug, tracing an error, or asking
## Workflow

```
1. query({query: "<error or symptom>"}) → Find related execution flows
1. query({search_query: "<error or symptom>"}) → Find related execution flows
2. context({name: "<suspect>"}) → See callers/callees/processes
3. READ gitnexus://repo/{name}/process/{name} → Trace execution flow
4. cypher({query: "MATCH path..."}) → Custom traces if needed
4. cypher({statement: "MATCH path..."}) → Custom traces if needed
```

> If "Index is stale" → run `node .gitnexus/run.cjs analyze` in terminal.
Expand All @@ -45,13 +45,14 @@ description: "Use when the user is debugging a bug, tracing an error, or asking
| Intermittent failure | `context` → look for external calls, async deps |
| Performance issue | `context` → find symbols with many callers (hot paths) |
| Recent regression | `detect_changes` to see what your changes affect |
| "How does A reach B?" | `trace` between the two symbols — shortest call chain in one call |

## Tools

**query** — find code related to error:

```
query({query: "payment validation error"})
query({search_query: "payment validation error"})
→ Processes: CheckoutFlow, ErrorHandling
→ Symbols: validatePayment, handlePaymentError, PaymentException
```
Expand All @@ -72,10 +73,21 @@ MATCH path = (a)-[:CodeRelation {type: 'CALLS'}*1..2]->(b:Function {name: "valid
RETURN [n IN nodes(path) | n.name] AS chain
```

**trace** — shortest call chain between two symbols ("how does A reach B?"), one call instead of chaining `context` hops:

```
trace({ from: "processCheckout", to: "fetchRates" })
→ status: ok, hopCount: 3
→ hops: processCheckout → validatePayment → verifyCard → fetchRates
→ edges: CALLS (1.0), CALLS (0.95), CALLS (1.0)
```

When no path exists, `trace` reports the furthest reachable node — exactly where the chain breaks (dynamic dispatch, reflection, or an external boundary).

## Example: "Payment endpoint returns 500 intermittently"

```
1. query({query: "payment error handling"})
1. query({search_query: "payment error handling"})
→ Processes: CheckoutFlow, ErrorHandling
→ Symbols: validatePayment, handlePaymentError

Expand Down
6 changes: 3 additions & 3 deletions .claude/skills/gitnexus/gitnexus-exploring/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ description: "Use when the user asks how code works, wants to understand archite
```
1. READ gitnexus://repos → Discover indexed repos
2. READ gitnexus://repo/{name}/context → Codebase overview, check staleness
3. query({query: "<what you want to understand>"}) → Find related execution flows
3. query({search_query: "<what you want to understand>"}) → Find related execution flows
4. context({name: "<symbol>"}) → Deep dive on specific symbol
5. READ gitnexus://repo/{name}/process/{name} → Trace full execution flow
```
Expand Down Expand Up @@ -50,7 +50,7 @@ description: "Use when the user asks how code works, wants to understand archite
**query** — find execution flows related to a concept:

```
query({query: "payment processing"})
query({search_query: "payment processing"})
→ Processes: CheckoutFlow, RefundFlow, WebhookHandler
→ Symbols grouped by flow with file locations
```
Expand All @@ -68,7 +68,7 @@ context({name: "validateUser"})

```
1. READ gitnexus://repo/my-app/context → 918 symbols, 45 processes
2. query({query: "payment processing"})
2. query({search_query: "payment processing"})
→ CheckoutFlow: processPayment → validateCard → chargeStripe
→ RefundFlow: initiateRefund → calculateRefund → processRefund
3. context({name: "processPayment"})
Expand Down
47 changes: 45 additions & 2 deletions .claude/skills/gitnexus/gitnexus-guide/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,9 +35,19 @@ For any task involving code understanding, debugging, impact analysis, or refact
| `query` | Process-grouped code intelligence — execution flows related to a concept |
| `context` | 360-degree symbol view — categorized refs, processes it participates in |
| `impact` | Symbol blast radius — what breaks at depth 1/2/3 with confidence |
| `trace` | Shortest path between two symbols — "how does A reach B?" in one call |
| `detect_changes` | Git-diff impact — what do your current changes affect |
| `rename` | Multi-file coordinated rename with confidence-tagged edits |
| `cypher` | Raw graph queries (read `gitnexus://repo/{name}/schema` first) |
| `explain` | Persisted taint findings — source→sink data flows (needs `analyze --pdg`) |
| `pdg_query` | Control/data dependence — what gates X (CDG) / where Y flows (REACHING_DEF); needs `analyze --pdg` |
| `check` | Check graph invariants such as circular imports |
| `route_map` | API route map — which components/hooks fetch which endpoints, and the handler files that serve them |
| `shape_check` | Response-shape drift — keys each route returns vs keys its consumers access (flags MISMATCH) |
| `api_impact` | Pre-change report for an API route — consumers, middleware, shape mismatches, risk level |
| `tool_map` | MCP/RPC tool definitions and the files that handle them |
| `group_list` | List configured multi-repo groups, or one group's config |
| `group_sync` | Rebuild a group's Contract Registry (cross-repo HTTP contract links); run after `group.yaml` changes or member re-index |
| `list_repos` | Discover indexed repos (paginated — `limit`/`offset`) |

### Paginating `list_repos`
Expand Down Expand Up @@ -71,6 +81,37 @@ list_repos { offset: 400 } → repos 401–437, hasMore false

Notes: `offset` ≥ `total` returns an empty page (with `total` still reported). Out-of-range or malformed `limit`/`offset` (non-integer, `limit` outside `[1, 200]`, `offset < 0`) are rejected with a clear error — `limit` above the max is rejected, not silently capped. The order is deterministic (lower-cased name, then path), so paging never skips or duplicates an entry while the registry is unchanged.

### Taint findings (`explain`)

`explain` returns taint findings recorded by `gitnexus analyze --pdg` — intra-procedural `TAINTED` edges plus cross-function `TAINT_PATH` hops where the interprocedural taint phase found a function-level source→sink chain. Each finding includes a sink category (command-injection, code-injection, path-traversal, sql-injection, xss), source/sink lines, and the ordered hop path with the variable carried on each hop.

- `explain {}` — enumerate all findings for the repo (bounded by `limit`, deterministic order)
- `explain { target: "src/vuln.ts" }` — findings in a file (suffix path match accepted)
- `explain { target: "runUserCommand" }` — findings in a function (resolved like `context`; ambiguous names return ranked candidates)

A repo indexed without `--pdg` returns a clear "no taint layer" note. Caveats: closure/callback, property/field, and implicit flows are not modeled, and interprocedural findings are function-level `TAINT_PATH` hops rather than statement-level path proof, so the absence of a finding is **not** proof of safety. `SANITIZES` (sanitizer-kill) edges are queryable via `cypher`.

### Control & data dependence (`pdg_query`)

`pdg_query` reads the control/data-dependence layers `gitnexus analyze --pdg` records (CDG + REACHING_DEF, basic-block granular) — the control/data analog of `explain`. It is **always anchored** (a `target` file path or symbol, resolved like `context`) and has two modes:

- `pdg_query { mode: "controls", target: "..." }` — CDG: "under what condition does X run?". Each edge is a controlling predicate block → dependent block with the branch sense (`'T'`/`'F'`) in `reason`; an edge into an early `return`/`throw` is flagged `guard: true` (guard-clause discovery — the sense depends on the predicate, so don't filter guards by a fixed label).
- `pdg_query { mode: "flows", target: "...", variable?: "..." }` — REACHING_DEF def→use edges within the function; pass `variable` to trace one binding.

A repo indexed without `--pdg` returns a "no PDG layer" note (or "status unknown" when the layer can't be confirmed). Intra-procedural only — cross-function flow is taint's domain (`explain`). The raw CDG/REACHING_DEF edges are also queryable via `cypher`. See the `gitnexus-pdg-query` skill for the full query surface.

### Shortest path between two symbols (`trace`)

`trace` answers "how does A reach B?" in one call — the shortest directed path over `CALLS` (plus `HAS_METHOD`, so a class-rooted trace descends into its methods) instead of chaining 3–8 `context`/`impact` hops by hand.

- `trace { from: "validateUser", to: "executeQuery" }` — shortest path between two symbols.
- Disambiguate common names with `from_uid`/`to_uid` (zero-ambiguity) or `from_file`/`to_file`; an ambiguous name returns ranked candidates.
- `maxDepth` (default 10, max 30) bounds the search; `includeTests` (default false) lets the traversal pass through test-file symbols.

Returns ordered `hops` (each `{ name, filePath, startLine }`) and an aligned `edges[]` of `{ relType, confidence }`, so call hops and containment (`HAS_METHOD`) hops stay distinguishable. When no path exists it reports the **furthest** reachable node (where the chain breaks) and sets `truncated: true` if a traversal cap was hit first. Every result carries a `status`: `ok` / `no_path` / `ambiguous` / `not_found` / `error`.

Cross-repo (experimental): pass `repo: "@groupName"` to trace across a group's member repos — the path may cross **one** `ContractLink` boundary (reported as a `CONTRACT_LINK` hop with the bridged contract in `crossings[]`). Omit `to` entirely to follow `from`'s outgoing HTTP call to whatever provider endpoint it lands on. Groups are configured via `group_list` / `group_sync`.

## Resources Reference

Lightweight reads (~100-500 tokens) for navigation:
Expand All @@ -86,8 +127,10 @@ Lightweight reads (~100-500 tokens) for navigation:

## Graph Schema

**Nodes:** File, Function, Class, Interface, Method, Community, Process
**Edges (via CodeRelation.type):** CALLS, IMPORTS, EXTENDS, IMPLEMENTS, DEFINES, MEMBER_OF, STEP_IN_PROCESS
**Nodes:** File, Folder, Function, Class, Interface, Method, CodeElement, Community, Process, Route, Tool, plus language-specific types (Struct, Enum, Trait, Impl, Namespace, Module, …) and BasicBlock (`--pdg` indexes only). The full node list lives in `gitnexus://repo/{name}/schema`.
**Edges (via CodeRelation.type):** CALLS, IMPORTS, EXTENDS, IMPLEMENTS, DEFINES, CONTAINS, MEMBER_OF, HAS_METHOD, HAS_PROPERTY, ACCESSES, METHOD_OVERRIDES, METHOD_IMPLEMENTS, STEP_IN_PROCESS, HANDLES_ROUTE, FETCHES, HANDLES_TOOL, ENTRY_POINT_OF, WRAPS, QUERIES, INJECTS, plus `--pdg`-only types (CFG, REACHING_DEF, TAINTED, SANITIZES, TAINT_PATH, CDG — zero rows on a default index).

Read `gitnexus://repo/{name}/schema` before writing Cypher — it is the authoritative schema for the indexed repo.

```cypher
MATCH (caller)-[:CodeRelation {type: 'CALLS'}]->(f:Function {name: "myFunc"})
Expand Down
10 changes: 5 additions & 5 deletions .claude/skills/gitnexus/gitnexus-refactoring/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ description: "Use when the user wants to rename, extract, split, move, or restru

```
1. impact({target: "X", direction: "upstream"}) → Map all dependents
2. query({query: "X"}) → Find execution flows involving X
2. query({search_query: "X"}) → Find execution flows involving X
3. context({name: "X"}) → See all incoming/outgoing refs
4. Plan update order: interfaces → implementations → callers → tests
```
Expand All @@ -30,7 +30,7 @@ description: "Use when the user wants to rename, extract, split, move, or restru

```
- [ ] rename({symbol_name: "oldName", new_name: "newName", dry_run: true}) — preview all edits
- [ ] Review graph edits (high confidence) and ast_search edits (review carefully)
- [ ] Review graph edits (high confidence) and text_search edits (review carefully)
- [ ] If satisfied: rename({..., dry_run: false}) — apply edits
- [ ] detect_changes() — verify only expected files changed
- [ ] Run tests for affected processes
Expand Down Expand Up @@ -66,7 +66,7 @@ description: "Use when the user wants to rename, extract, split, move, or restru
```
rename({symbol_name: "validateUser", new_name: "authenticateUser", dry_run: true})
→ 12 edits across 8 files
→ 10 graph edits (high confidence), 2 ast_search edits (review)
→ 10 graph edits (high confidence), 2 text_search edits (review)
→ Changes: [{file_path, edits: [{line, old_text, new_text, confidence}]}]
```

Expand Down Expand Up @@ -107,10 +107,10 @@ RETURN caller.name, caller.filePath ORDER BY caller.filePath

```
1. rename({symbol_name: "validateUser", new_name: "authenticateUser", dry_run: true})
→ 12 edits: 10 graph (safe), 2 ast_search (review)
→ 12 edits: 10 graph (safe), 2 text_search (review)
→ Files: validator.ts, login.ts, middleware.ts, config.json...

2. Review ast_search edits (config.json: dynamic reference!)
2. Review text_search edits (config.json: dynamic reference!)

3. rename({symbol_name: "validateUser", new_name: "authenticateUser", dry_run: false})
→ Applied 12 edits across 8 files
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/publish-pypi.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,12 +35,12 @@ jobs:
token: ${{ secrets.GITHUB_TOKEN }}

- name: Set up Python
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.13"

- name: Install uv
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
with:
enable-cache: true

Expand Down Expand Up @@ -78,7 +78,7 @@ jobs:
run: hatch build

- name: Publish to PyPI
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0
uses: pypa/gh-action-pypi-publish@ba38be9e461d3875417946c167d0b5f3d385a247 # v1.14.1
with:
packages-dir: dist/

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Set up Python
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.13"

Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/python-package.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,10 +78,10 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.13"
- uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
- name: Install dependencies
run: uv sync --frozen --extra dev
- name: Run pre-commit hooks
Expand Down Expand Up @@ -109,11 +109,11 @@ jobs:
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python-version }}
- name: Install uv
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
with:
# Avoid parallel matrix jobs racing on the same Actions cache reservation
cache-suffix: py-${{ matrix.python-version }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
fetch-depth: 0 # Required for generating release notes

- name: Create Release
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v3.0.1
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
with:
generate_release_notes: true
draft: false
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/trufflehog-full-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@ jobs:

- name: Full Repository Scan
if: inputs.scan_type == 'full-repo'
uses: trufflesecurity/trufflehog@f446421baf832d6356c42c1743d99abff52ff334 # v3.95.7
uses: trufflesecurity/trufflehog@27b0417c16317ca9a472a9a8092acce143b49c55 # v3.95.9
with:
extra_args: --results=verified,unknown
2 changes: 1 addition & 1 deletion .github/workflows/trufflehog-security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,6 @@ jobs:
fetch-depth: 0 # Required for TruffleHog to scan git history

- name: Secret Scanning
uses: trufflesecurity/trufflehog@f446421baf832d6356c42c1743d99abff52ff334 # v3.95.7
uses: trufflesecurity/trufflehog@27b0417c16317ca9a472a9a8092acce143b49c55 # v3.95.9
with:
extra_args: --results=verified,unknown
Loading
Loading