ci: add a lint check and Dependabot config - #29
Open
davidberenstein1957 wants to merge 15 commits into
Open
davidberenstein1957 wants to merge 15 commits into
davidberenstein1957 wants to merge 15 commits into
Conversation
The default check now syntax-checks the whole repository and resolves every requirements file and pyproject.toml that git tracks, resolved from its own folder with the PyTorch CUDA index available. MANIFESTS and EXCLUDE narrow it where needed.
Runs p/default and p/trailofbits at ERROR severity with --baseline-commit set to the pull request base, so existing findings do not fail it. The image and checkout are pinned by digest and SHA.
uv writes a temp file next to the -o path, which fails under /dev.
pyproject.toml pins no CUDA torch builds, so the cu128 index and unsafe-best-match only widen the resolver's sources.
Every ecosystem waits 7 days before proposing a new release. The Semgrep job uses the container image: form, and a docker entry for /.github/workflows lets Dependabot bump its tag and digest.
davidberenstein1957
force-pushed
the
ci/default-check-and-dependabot
branch
from
September 29, 2026 10:35
6e10e9e to
f0e49a6
Compare
Drop open-pull-requests-limit: 50 so each entry falls back to the default of 5. The weekly schedule and grouping stay the same, and security updates are not subject to the limit.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
The branch ruleset on
mainrequires a status check nameddefault, but no workflow in this repository reports it, so every merge has needed an admin bypass. This PR adds.github/workflows/ci.ymlwith alintjob that runs on every pull request and needs no secrets. The job is named after what it runs, and the ruleset should requirelintinstead ofdefault.lintjobuv run --python 3.12 python -m compileallover the whole repository (syntax check)uv pip compilefor every trackedrequirements*.txtandpyproject.toml, each resolved from its own folder for Python 3.12 on Linux with the PyTorch CUDA index available. New folders are picked up without editing the workflow.Every action in
ci.ymlis pinned to a full commit SHA, with the version in a trailing comment. Dependabot'sgithub-actionsupdates keep the SHA and the comment current.Dependabot
.github/dependabot.ymluses directory globs where several folders share an ecosystem, so new folders are covered without a config change. It runs weekly, groups minor and patch updates into one PR per ecosystem, and keeps GitHub's default limit of 5 open pull requests (security updates don't count toward it). Dependabot PRs get no Actions secrets, which is why thelintjob uses none.//Hardening
dockerentry for/.github/workflowsis removed. No workflow here uses a container image now that Semgrep has moved out.Semgrep
This PR no longer adds a Semgrep job. Semgrep runs from
.github/workflows/semgrep.ymlin PrunaAI/.github (PrunaAI/.github#1), which an org ruleset will require on every repository's default branch.Before merging
Change the required status check in this repository's ruleset from
defaulttolintfirst. Until then this PR fails its own required check. The org and repo rule changes are tracked in PrunaAI/prunatree#639.Testing
dependabot.ymlvalidated withcheck-jsonschema --builtin-schema vendor.dependabot.ci.ymlchecked withactionlint; the ruleset must requirelintbefore this PR can merge.lintsteps were run locally onmainunless a note above says otherwise.Commits