diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..59094f6 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,27 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +version: 2 + +updates: + # Update the GitHub actions used in the workflows. + # This allows maintaining the pin by SHA + version comment. + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: weekly + groups: + github-actions: + group-by: dependency-name + + # Update the pip dependencies declared in requirements.txt + # and requirements-dev.txt. + - package-ecosystem: "pip" + directories: + - "/" + schedule: + interval: weekly + groups: + pip-dependencies: + group-by: dependency-name diff --git a/.github/workflows/cleanup.yml b/.github/workflows/cleanup.yml index 72f8618..b4a5137 100644 --- a/.github/workflows/cleanup.yml +++ b/.github/workflows/cleanup.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: Cleanup Old Workflow Runs on: @@ -22,7 +26,7 @@ jobs: steps: - name: Delete old workflow runs - uses: actions/github-script@v7 + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 with: script: | const owner = context.repo.owner; @@ -66,4 +70,4 @@ jobs: } } - console.log(`Deleted ${deletedCount} workflow runs, ${failedCount} failures`); \ No newline at end of file + console.log(`Deleted ${deletedCount} workflow runs, ${failedCount} failures`); diff --git a/.github/workflows/pull_request.yml b/.github/workflows/pull_request.yml index e9f8687..e2f5985 100644 --- a/.github/workflows/pull_request.yml +++ b/.github/workflows/pull_request.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: Pull request on: @@ -15,14 +19,14 @@ concurrency: jobs: test: - uses: ./.github/workflows/test.yaml + uses: ./.github/workflows/test.yml scan: uses: ./.github/workflows/scan.yml pull-request: - needs: [test, scan] + needs: test name: Pull request success runs-on: ubuntu-latest steps: - - run: "true" \ No newline at end of file + - run: "true" diff --git a/.github/workflows/push.yml b/.github/workflows/push.yml index 08722e5..d321a54 100644 --- a/.github/workflows/push.yml +++ b/.github/workflows/push.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: Push on: @@ -11,7 +15,4 @@ permissions: jobs: test: - uses: ./.github/workflows/test.yaml - - scan: - uses: ./.github/workflows/scan.yml \ No newline at end of file + uses: ./.github/workflows/test.yml \ No newline at end of file diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8c13585..10be1bb 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: Release # IMPORTANT: PyPI validates against the filename (release.yml), @@ -23,12 +27,14 @@ jobs: contents: read steps: - - uses: actions/checkout@v4 + # The hashes correspond to the most recent versions at the time of this + # analysis; update via Dependabot (see dependabot.yml). + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@v5 + uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0 with: python-version: '3.11' cache: 'pip' @@ -46,5 +52,5 @@ jobs: # registered publisher. There are no secrets to rotate or leak. - name: Publish to PyPI if: startsWith(github.ref, 'refs/tags/') - uses: pypa/gh-action-pypi-publish@release/v1 - # attestations: true # optional: generate PEP 740 attestations (supply chain) \ No newline at end of file + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 + # attestations: true # optional: generate PEP 740 attestations (supply chain) diff --git a/.github/workflows/scan.yml b/.github/workflows/scan.yml index e0bf1e2..e613718 100644 --- a/.github/workflows/scan.yml +++ b/.github/workflows/scan.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: "Security vulnerability scan" on: @@ -13,18 +17,19 @@ permissions: contents: read jobs: - scan: + pip-audit: + name: pip-audit runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ inputs.ref }} fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@v5 + uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0 with: python-version: '3.11' cache: 'pip' @@ -44,4 +49,4 @@ jobs: run: pip-audit -r requirements.txt - name: Audit installed environment - run: pip-audit \ No newline at end of file + run: pip-audit diff --git a/.github/workflows/vulnerability-scan.yml b/.github/workflows/scheduled-scan.yml similarity index 62% rename from .github/workflows/vulnerability-scan.yml rename to .github/workflows/scheduled-scan.yml index d293592..38d5d6d 100644 --- a/.github/workflows/vulnerability-scan.yml +++ b/.github/workflows/scheduled-scan.yml @@ -1,8 +1,12 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: "Scheduled vulnerability scan" on: schedule: - - cron: "27 3 * * *" + - cron: "20 3 * * *" workflow_dispatch: permissions: @@ -27,9 +31,16 @@ jobs: fi echo "value=${tag}" >> "${GITHUB_OUTPUT}" - scan: + scan-release: name: Scan ${{ needs.latest-release-version.outputs.tag_name }} needs: latest-release-version uses: ./.github/workflows/scan.yml with: - ref: ${{ needs.latest-release-version.outputs.tag_name }} \ No newline at end of file + ref: ${{ needs.latest-release-version.outputs.tag_name }} + + # This job runs on the `main` branch and scans the `main` branch at the default branch's HEAD. + # Without it, vulnerabilities introduced in `main` + # but not yet released would go unnoticed until the next release. + scan-latest: + name: Scan latest + uses: ./.github/workflows/scan.yml diff --git a/.github/workflows/scheduled.yml b/.github/workflows/scheduled.yml new file mode 100644 index 0000000..5e46c7f --- /dev/null +++ b/.github/workflows/scheduled.yml @@ -0,0 +1,17 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +name: Scheduled build + +on: + schedule: + - cron: "5 4 * * 0" # Sunday 04:05 UTC + workflow_dispatch: + +permissions: + contents: read + +jobs: + main: + uses: ./.github/workflows/test.yml diff --git a/.github/workflows/test.yaml b/.github/workflows/test.yaml deleted file mode 100644 index 066b475..0000000 --- a/.github/workflows/test.yaml +++ /dev/null @@ -1,31 +0,0 @@ -name: Test - -on: - workflow_call: - -permissions: - contents: read - -jobs: - test: - runs-on: ubuntu-latest - timeout-minutes: 25 - - steps: - - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - - name: Set up Python - uses: actions/setup-python@v5 - with: - python-version: '3.11' - cache: 'pip' - - - name: Install dependencies - run: | - python -m pip install --upgrade pip - python -m pip install -r requirements.txt -r requirements-dev.txt - - - name: Run tests - run: python -m pytest -q \ No newline at end of file diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml new file mode 100644 index 0000000..d66a220 --- /dev/null +++ b/.github/workflows/test.yml @@ -0,0 +1,96 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +name: Test + +on: + workflow_call: + inputs: + ref: + description: Branch, tag or SHA to test. + type: string + required: false + default: "" + +permissions: + contents: read + +jobs: + test: + name: Unit test + runs-on: ubuntu-latest + timeout-minutes: 25 + steps: + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + with: + ref: ${{ inputs.ref }} + fetch-depth: 0 + - name: Set up Python + uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0 + with: + python-version: '3.11' + cache: 'pip' + - name: Install dependencies + run: | + python -m pip install --upgrade pip + python -m pip install -r requirements.txt -r requirements-dev.txt + - name: Run tests + run: python -m pytest -q + + # TODO: If you have integration tests against a real Fabric peer, + # uncomment this job and adjust the paths. It is the equivalent of the + # `integrationtest` job in the Java workflow. + # integrationtest: + # name: Integration test + # runs-on: ubuntu-latest + # timeout-minutes: 45 + # steps: + # - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + # with: + # ref: ${{ inputs.ref }} + # fetch-depth: 0 + # - name: Set up Python + # uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0 + # with: + # python-version: '3.11' + # cache: 'pip' + # - name: Install dependencies + # run: | + # python -m pip install --upgrade pip + # python -m pip install -r requirements.txt -r requirements-dev.txt + # - name: Ensure that the Peer/weft tools are available + # run: | + # curl -sSL https://raw.githubusercontent.com/hyperledger/fabric/main/scripts/install-fabric.sh | bash -s -- binary + # npm install -g @hyperledger-labs/weft + # echo "FABRIC_CFG_PATH=$GITHUB_WORKSPACE/config" >> $GITHUB_ENV + # echo "$GITHUB_WORKSPACE/bin" >> $GITHUB_PATH + # - name: versions + # run: | + # peer version + # weft --version + # - name: Integration Tests + # run: python -m pytest -q integration_test/ + + # TODO: If you publish a base Docker image for Python chaincode, + # uncomment this job. It is the equivalent of the Java `docker` job. + # docker: + # name: Build Docker image + # runs-on: ubuntu-latest + # timeout-minutes: 30 + # permissions: + # contents: read + # packages: write + # steps: + # - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + # with: + # ref: ${{ inputs.ref }} + # - name: Set up Docker Buildx + # uses: docker/setup-buildx-action@c7c853bb5d3c0d0de6c775bda84e8f9be9bed9339 # v3.10.0 + # - name: Build image + # uses: docker/build-push-action@v6 + # with: + # context: . + # file: ./Dockerfile + # push: false + # tags: fabric-pythonenv:latest