diff --git a/.github/actions/setup/action.yml b/.github/actions/setup/action.yml index ae33a94c..a5e67372 100644 --- a/.github/actions/setup/action.yml +++ b/.github/actions/setup/action.yml @@ -22,7 +22,9 @@ runs: sudo ldconfig shell: bash - - name: Install Rust - uses: dtolnay/rust-toolchain@stable - with: - components: ${{ inputs.components }} + - name: Install Rust components + if: inputs.components != '' + env: + COMPONENTS: ${{ inputs.components }} + run: rustup component add ${COMPONENTS//,/ } + shell: bash diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8c9180c7..53ed5917 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -21,8 +21,9 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true + persist-credentials: false - - uses: ./.github/actions/setup + - uses: $/.github/actions/setup - uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 with: @@ -46,8 +47,9 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true + persist-credentials: false - - uses: ./.github/actions/setup + - uses: $/.github/actions/setup with: components: rustfmt @@ -61,8 +63,9 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true + persist-credentials: false - - uses: ./.github/actions/setup + - uses: $/.github/actions/setup with: components: clippy @@ -88,8 +91,9 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true + persist-credentials: false - - uses: ./.github/actions/setup + - uses: $/.github/actions/setup - uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 with: diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index 930c7674..3c841483 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -21,8 +21,9 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true + persist-credentials: false - - uses: ./.github/actions/setup + - uses: $/.github/actions/setup - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: diff --git a/.github/workflows/git-hooks.yml b/.github/workflows/git-hooks.yml new file mode 100644 index 00000000..91d8d0ea --- /dev/null +++ b/.github/workflows/git-hooks.yml @@ -0,0 +1,28 @@ +name: "Git Hooks" + +on: + push: + branches: + - main + pull_request: ~ + +permissions: {} + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + run-prek: + name: prek run --all-files + runs-on: ubuntu-26.04 + timeout-minutes: 1 + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Run prek + uses: j178/prek-action@4e14d07f9231acabce116ccfca13b13dd9755ece # v3.0.0 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 466d830e..25ab6431 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -15,7 +15,9 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true - - uses: ./.github/actions/setup + persist-credentials: false + + - uses: $/.github/actions/setup - name: Generate type stubs run: | cargo build --release -p processing_pyo3 @@ -36,6 +38,8 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true + persist-credentials: false + - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: python-version: '3.x' @@ -85,6 +89,8 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true + persist-credentials: false + - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: python-version: '3.x' @@ -110,6 +116,8 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true + persist-credentials: false + - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 with: python-version: '3.x' @@ -135,6 +143,8 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true + persist-credentials: false + - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: name: type-stubs @@ -157,7 +167,9 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true - - uses: ./.github/actions/setup + persist-credentials: false + + - uses: $/.github/actions/setup - name: Build FFI shared library run: cargo build --release -p processing_ffi --features wayland,x11,webcam - name: Stage release files @@ -180,7 +192,8 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true - - uses: dtolnay/rust-toolchain@stable + persist-credentials: false + - name: Build FFI shared library run: cargo build --release -p processing_ffi --features webcam - name: Stage release files @@ -203,7 +216,8 @@ jobs: - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true - - uses: dtolnay/rust-toolchain@stable + persist-credentials: false + - name: Build FFI shared library run: cargo build --release -p processing_ffi --features webcam - name: Stage release files @@ -236,7 +250,7 @@ jobs: merge-multiple: true path: dist - name: Publish to PyPI - uses: pypa/gh-action-pypi-publish@release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 github-release: name: Create GitHub Release @@ -256,7 +270,7 @@ jobs: pattern: wheels-* merge-multiple: true path: release-assets - - uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2 - with: - files: release-assets/* - generate_release_notes: true + - name: Create GitHub Release + env: + GH_TOKEN: ${{ github.token }} + run: gh release create "${GITHUB_REF_NAME}" release-assets/* --generate-notes diff --git a/.github/workflows/visual-comment.yml b/.github/workflows/visual-comment.yml index b8503469..f293f07e 100644 --- a/.github/workflows/visual-comment.yml +++ b/.github/workflows/visual-comment.yml @@ -21,7 +21,7 @@ jobs: actions: read pull-requests: write steps: - - uses: actions/download-artifact@v8 + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 id: download continue-on-error: true with: @@ -48,7 +48,7 @@ jobs: - name: Post comment if: steps.pr.outputs.notable == 'true' - uses: marocchino/sticky-pull-request-comment@v3.0.5 + uses: marocchino/sticky-pull-request-comment@5770ad5eb8f42dd2c4f34da00c94c5381e49af88 # v3.0.5 with: header: visual-regression number_force: ${{ steps.pr.outputs.number }} @@ -57,7 +57,7 @@ jobs: # A clean run only refreshes an earlier comment, so passing PRs stay quiet. - name: Update comment if: steps.pr.outputs.notable == 'false' - uses: marocchino/sticky-pull-request-comment@v3.0.5 + uses: marocchino/sticky-pull-request-comment@5770ad5eb8f42dd2c4f34da00c94c5381e49af88 # v3.0.5 with: header: visual-regression number_force: ${{ steps.pr.outputs.number }} diff --git a/.github/workflows/visual.yml b/.github/workflows/visual.yml index 2a2f8174..f7cf03d5 100644 --- a/.github/workflows/visual.yml +++ b/.github/workflows/visual.yml @@ -40,25 +40,25 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 90 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: submodules: true # PR checkouts are merge commits; HEAD^1 is the main commit they're compared against. fetch-depth: 2 persist-credentials: false - - uses: ./.github/actions/setup + - uses: $/.github/actions/setup - - uses: ./.github/actions/install-mesa + - uses: $/.github/actions/install-mesa - - uses: astral-sh/setup-uv@v6 + - uses: astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6.8.0 - name: Install xvfb and odiff run: | sudo apt-get install -y --no-install-recommends xvfb npm install -g "odiff-bin@$ODIFF_VERSION" - - uses: actions/cache@v4 + - uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 with: path: | ~/.cargo/bin/ @@ -74,7 +74,7 @@ jobs: - name: Render run: xvfb-run -a -s "-screen 0 1920x1080x24" python3 tests/visual/visual.py render --out out/actual - - uses: actions/upload-artifact@v7 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: visual-screenshots path: out/actual @@ -113,7 +113,7 @@ jobs: mkdir -p out/baseline python3 tests/visual/visual.py compare --baseline out/baseline --actual out/actual --out out/report $ALLOW_CHANGES - - uses: actions/upload-artifact@v7 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 id: report if: always() && hashFiles('out/report/report.html') != '' with: @@ -137,7 +137,7 @@ jobs: echo "$PR_NUMBER" > out/comment/pr jq '[.results[] | select(.status != "pass")] | length > 0' out/report/results.json > out/comment/notable - - uses: actions/upload-artifact@v7 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: always() && hashFiles('out/comment/comment.md') != '' with: name: visual-comment diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml new file mode 100644 index 00000000..8832138c --- /dev/null +++ b/.pre-commit-config.yaml @@ -0,0 +1,6 @@ +repos: + - repo: https://github.com/zizmorcore/zizmor-pre-commit + rev: v1.30.1 + hooks: + - id: zizmor + args: ["--no-progress", "--persona=auditor"]