mirror of
https://github.com/langchain-ai/langgraph.git
synced 2026-08-27 01:52:25 +02:00
Every third-party GitHub Action in the workflows is now pinned to a full
commit SHA instead of a floating major tag, closing a supply-chain gap
where a mutable tag like `@v6` could be force-pushed to point at
malicious code. Seven actions were already SHA-pinned; this brings the
remaining first-party `actions/*` and `astral-sh/setup-uv` references in
line.
## Changes
- Pinned all previously tag-referenced actions to their current commit
SHA with the exact release as a trailing comment (the format Dependabot
reads and updates): `actions/checkout` → `v6.0.3`,
`actions/setup-python` → `v6.2.0`, `actions/github-script` → `v9.0.0`,
`actions/upload-artifact` → `v7.0.1`, `actions/download-artifact` →
`v8.0.1`, `actions/cache/{restore,save}` → `v5.0.5`,
`actions/configure-pages` → `v6.0.0`, `actions/deploy-pages` → `v5.0.0`,
`actions/upload-pages-artifact` → `v5.0.0`,
`actions/create-github-app-token` → `v3.2.0`, and `astral-sh/setup-uv` →
`v7.6.0`.
- Applied across all workflow files plus the `uv_setup` composite
action; local same-repo references (`./.github/workflows/_*.yml`,
`./.github/actions/uv_setup`) left as path refs since they resolve from
the same commit.
44 lines
1.3 KiB
YAML
44 lines
1.3 KiB
YAML
name: UV Lock Upgrade
|
|
|
|
on:
|
|
schedule:
|
|
# run at midnight every Sunday
|
|
- cron: '0 0 * * 0'
|
|
# allow manual triggering
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: write
|
|
pull-requests: write
|
|
|
|
jobs:
|
|
upgrade-dependencies:
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
|
|
|
- name: Set up uv
|
|
uses: ./.github/actions/uv_setup
|
|
with:
|
|
python-version: "3.10"
|
|
cache-suffix: "uv-lock-upgrade"
|
|
|
|
- name: Run uv lock --upgrade in all Python packages
|
|
run: make lock-upgrade
|
|
|
|
- name: Create Pull Request
|
|
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8
|
|
with:
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
commit-message: "chore(deps): upgrade dependencies with `uv lock --upgrade`"
|
|
title: "chore(deps): upgrade dependencies with `uv lock --upgrade`"
|
|
body: |
|
|
This PR updates the dependencies in all Python packages using `uv lock --upgrade`.
|
|
|
|
This is an automated PR created by the UV Lock Upgrade workflow.
|
|
branch: deps/uv-lock-upgrade
|
|
delete-branch: true
|
|
labels: |
|
|
dependencies
|