Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
83 commits
Select commit Hold shift + click to select a range
45c0903
add
juliannguyen4 Jan 8, 2026
ba4e7c7
WIP dry run
juliannguyen4 Jan 8, 2026
4af7f76
Merge remote-tracking branch 'origin/dev' into CLIENT-4051-cicd-allow…
juliannguyen4 Jan 15, 2026
d1b4327
Merge remote-tracking branch 'origin/dev' into CLIENT-4051-cicd-allow…
juliannguyen4 Jan 16, 2026
a1405e0
Merge remote-tracking branch 'origin/dev' into CLIENT-4051-cicd-allow…
juliannguyen4 Jan 21, 2026
8e19597
Need registry name to test qe nightly builds
juliannguyen4 Jan 21, 2026
3cf8e8d
Add skeleton code to disable tagging
juliannguyen4 Jan 21, 2026
e0ed822
finish
juliannguyen4 Jan 22, 2026
070591d
Support dry run flag for uploading to jfrog workflow
juliannguyen4 Jan 22, 2026
297944f
Add implementation and first rough draft of test case. TODO: needs ed…
juliannguyen4 Mar 23, 2026
cc5475f
[pre-commit.ci] auto fixes from pre-commit.com hooks
pre-commit-ci[bot] Mar 23, 2026
8519ae2
Fix test syntax.
juliannguyen4 Mar 23, 2026
71f84e7
Revert c changes. Sets need to belong to a namespace
juliannguyen4 Mar 24, 2026
142c0eb
Merge remote-tracking branch 'origin/dev' into CLIENT-4313-support-cr…
juliannguyen4 Apr 3, 2026
3c89436
Rename since we will have set index creation logic in here
juliannguyen4 Apr 3, 2026
24ac4c5
fix test. This should be its own method
juliannguyen4 Apr 3, 2026
52e5328
Implement index_set_create
juliannguyen4 Apr 6, 2026
ac49a08
Fix compiler error
juliannguyen4 Apr 6, 2026
f15587e
add type stub
juliannguyen4 Apr 6, 2026
44c8075
Have sindex test case log in as user with only sindex-admin role.
juliannguyen4 Apr 6, 2026
41acfa8
Update c client to address segv from dereferencing NULL ptr
juliannguyen4 Apr 6, 2026
441aff0
Update c client again.
juliannguyen4 Apr 7, 2026
a08dd29
Fix incorrect kwarg. TODO need to fix type stubs as well...
juliannguyen4 Apr 7, 2026
fae5bdb
Fix test not cleaning up after new user
juliannguyen4 Apr 7, 2026
204957d
Have test start with known environment
juliannguyen4 Apr 7, 2026
5a30969
Explicitly set index_type to AS_INDEX_TYPE_SET and index_datatype to …
juliannguyen4 Apr 7, 2026
76691c6
Type stubs: fix admin commands having incorrect kwarg username. Stubt…
juliannguyen4 Apr 7, 2026
7ff71c6
Fix test syntax
juliannguyen4 Apr 7, 2026
0905b0d
Skip test for CE. But also running on server < 8.1.2 to see what happens
juliannguyen4 Apr 7, 2026
2540025
Fix regression where methods were removed from type stubs..
juliannguyen4 Apr 7, 2026
c5538a4
Pull c client again to address segv when running against server 8.1.1
juliannguyen4 Apr 8, 2026
21785c6
Pull c client to fix linker error
juliannguyen4 Apr 8, 2026
486775f
Align with c client's config provider interval default of 5000
juliannguyen4 Apr 8, 2026
65b487c
Fix test
juliannguyen4 Apr 8, 2026
4115420
Update c client again to fix test error
juliannguyen4 Apr 8, 2026
9287ff9
Fix
juliannguyen4 Apr 8, 2026
9491241
Test should expect server error on < 8.1.2
juliannguyen4 Apr 8, 2026
33a0b65
Cherry pick ci/cd changes from other 8.1.2 branches
juliannguyen4 Apr 8, 2026
53bfc81
Add test case for code coverage.
juliannguyen4 Apr 8, 2026
7e8ca48
Point c client back to stage now that set index creation is there
juliannguyen4 Apr 9, 2026
1f0c4de
Revert for now. Create a separate PR/jira ticket for this
juliannguyen4 Apr 9, 2026
60adad8
jf docker pull fails because it can't connect to the Docker daemon fo…
juliannguyen4 Apr 9, 2026
2f8b47d
Fix bad syntax
juliannguyen4 Apr 9, 2026
d98a655
Strong consistency requires features.conf
juliannguyen4 Apr 9, 2026
1776e44
Fix CE tests by always pulling from docker.io for now. There's no sha…
juliannguyen4 Apr 9, 2026
8c31958
Test feature branch from shared workflows to fix tls not working
juliannguyen4 Apr 9, 2026
b62aef3
Fix wrong output name
juliannguyen4 Apr 9, 2026
5505ccc
Fix user agent job
juliannguyen4 Apr 9, 2026
fa8f4ab
Fix tls paths. TODO this will probably fail for cibuildwheel manylinu…
juliannguyen4 Apr 9, 2026
bb0d281
Fix workflow
juliannguyen4 Apr 9, 2026
6c1a487
Point to my feature branch in shared workflows repo to fix TLS connec…
juliannguyen4 Apr 9, 2026
6cb90c7
Fix not creating superuser. Forgot to include this after migrating
juliannguyen4 Apr 9, 2026
4826825
Fix workflow
juliannguyen4 Apr 9, 2026
06672e7
Fix bad syntax..
juliannguyen4 Apr 9, 2026
2b679aa
Fix workflow..
juliannguyen4 Apr 9, 2026
8a45404
Fix workflow
juliannguyen4 Apr 9, 2026
c1955c0
Use Mirza's branch
juliannguyen4 Apr 9, 2026
962bc79
Fix test since we aren't creating superuser anymore
juliannguyen4 Apr 9, 2026
a79055b
Pull mirza's latest changes to fix tls name not matching cluster name
juliannguyen4 Apr 9, 2026
fcececa
Fix workflow..
juliannguyen4 Apr 9, 2026
10c4539
Fix workflow
juliannguyen4 Apr 9, 2026
bf6fc36
Pull mirza's latest changes to fix action failing if only security is…
juliannguyen4 Apr 9, 2026
3b879db
Just pull 8.1.x manually, latest tag is pointing to 8.1.0.0-start-75-…
juliannguyen4 Apr 9, 2026
0ab2ba7
Just uncomment to get tests to pass.
juliannguyen4 Apr 9, 2026
0ede309
Replace latest tag since its borked in the jfrog repo
juliannguyen4 Apr 9, 2026
74601c0
Merge remote-tracking branch 'origin/CLIENT-4051-cicd-allow-running-d…
juliannguyen4 Apr 10, 2026
f21bb15
update ci/cd to not depend on latest tag. this means every manual wor…
juliannguyen4 Apr 10, 2026
fa356b0
Read source code for shared action, this could be why?
juliannguyen4 Apr 10, 2026
f47e3ef
Make action work inside a docker container
juliannguyen4 Apr 10, 2026
4fc4c03
Fix syntax
juliannguyen4 Apr 10, 2026
916290a
Use this syntax to support hyphens.
juliannguyen4 Apr 10, 2026
a54f9aa
Google AI's suggestion didn't work
juliannguyen4 Apr 10, 2026
936ff6b
Forgot to remove quotes.
juliannguyen4 Apr 10, 2026
9d92f10
Can't find a setting in cibuildwheel to create the container on the b…
juliannguyen4 Apr 10, 2026
abc7b51
Revert "Can't find a setting in cibuildwheel to create the container …
juliannguyen4 Apr 10, 2026
6b6b518
Send server container network name to cibuildwheel
juliannguyen4 Apr 10, 2026
80d619d
Fix build-wheels failing due to printing logs from incorrect containe…
juliannguyen4 Apr 10, 2026
d370d5d
Fix same issue in smoke tests
juliannguyen4 Apr 10, 2026
970e807
Fix valgrind failing if wheel is not found
juliannguyen4 Apr 10, 2026
aaf4c60
only connect to server's network if running tests
juliannguyen4 Apr 10, 2026
3337378
Also mount docker host's root directory onto container so it can acce…
juliannguyen4 Apr 10, 2026
762b9bb
Revert all ci/cd changes to dev branch. Try using static token to acc…
juliannguyen4 Apr 10, 2026
743cc1e
Revert standalone test. TODO should move this to .github
juliannguyen4 Apr 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/build-sdist.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down Expand Up @@ -49,7 +49,7 @@ jobs:
run: python3 -m build --sdist

- name: Upload source distribution to GitHub
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
with:
path: ./dist/*.tar.gz
name: sdist.build
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/build-wheels.yml
Original file line number Diff line number Diff line change
Expand Up @@ -154,7 +154,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down Expand Up @@ -186,7 +186,7 @@ jobs:
CUSTOM_IMAGE_NAME: ghcr.io/aerospike/manylinux_2_28_{0}@sha256:{1}
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand All @@ -210,7 +210,7 @@ jobs:

- name: 'Windows: Add msbuild to PATH'
if: ${{ inputs.platform-tag == 'win_amd64' }}
uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2.0.0
uses: microsoft/setup-msbuild@30375c66a4eea26614e0d39710365f22f8b0af57 # v3.0.0

- name: 'Windows: Install C client deps'
if: ${{ inputs.platform-tag == 'win_amd64' }}
Expand Down Expand Up @@ -349,7 +349,7 @@ jobs:
shell: bash

- name: Upload wheels to GitHub
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
if: ${{ !cancelled() }}
with:
path: ./wheelhouse/*.whl
Expand Down Expand Up @@ -377,7 +377,7 @@ jobs:
BUILD_IDENTIFIER: "${{ matrix.python-tag }}-${{ inputs.platform-tag }}"
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down Expand Up @@ -411,7 +411,7 @@ jobs:
where-is-client-connecting-from: ${{ inputs.platform-tag == 'win_amd64' && 'remote-connection' || 'docker-host' }}

- name: Download wheel
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ env.BUILD_IDENTIFIER }}.build

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/bump-version.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ jobs:
steps:
# Checkout the branch where we want to bump the new version
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand All @@ -70,7 +70,7 @@ jobs:
steps:
# Checkout branch where workflow is being called from
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/delete-artifacts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,11 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

- name: Remove artifacts with dev version
uses: geekyeggo/delete-artifact@f275313e70c08f6120db482d7a6b98377786765b # v5.1.0
uses: geekyeggo/delete-artifact@176a747ab7e287e3ff4787bf8a148716375ca118 # v6.0.0
with:
name: '*.build'
2 changes: 1 addition & 1 deletion .github/workflows/dev-to-stage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/doc-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ jobs:
- 'linkcheck -v . links'
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/fast-forward-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down
40 changes: 20 additions & 20 deletions .github/workflows/smoke-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ jobs:

steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down Expand Up @@ -90,7 +90,7 @@ jobs:
run: echo WHEEL_GH_ARTIFACT_NAME=${{ env.WHEEL_GH_ARTIFACT_NAME }}-sanitizer >> $GITHUB_ENV

- name: Send wheel to test jobs
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
with:
name: ${{ env.WHEEL_GH_ARTIFACT_NAME }}
path: ./dist/*.whl
Expand All @@ -99,7 +99,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down Expand Up @@ -134,7 +134,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down Expand Up @@ -219,7 +219,7 @@ jobs:

- name: Upload coverage report folder to Github
if: ${{ !cancelled() }}
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
with:
name: coverage-report
path: build/temp*/src/main/
Expand All @@ -230,20 +230,20 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
submodules: recursive

- uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: coverage-report
path: ./coverage-report

- uses: codecov/codecov-action@5a1091511ad55cbe89839c7260b706298ca349f7 # v5.5.1
- uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v6.0.0
with:
directory: coverage-report
verbose: true # optional (default = false)
Expand All @@ -256,7 +256,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand All @@ -269,7 +269,7 @@ jobs:
python-version: ${{ env.LOWEST_SUPPORTED_PY_VERSION }}
architecture: 'x64'

- uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: wheel-${{ env.LOWEST_SUPPORTED_PY_VERSION }}

Expand All @@ -293,7 +293,7 @@ jobs:
needs: build
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand All @@ -312,7 +312,7 @@ jobs:
- if: ${{ matrix.type != 'sanitizer' }}
run: echo WHEEL_GH_ARTIFACT_NAME=wheel-${{ env.LOWEST_SUPPORTED_PY_VERSION }} >> $GITHUB_ENV

- uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ env.WHEEL_GH_ARTIFACT_NAME }}

Expand Down Expand Up @@ -364,7 +364,7 @@ jobs:

steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand All @@ -380,7 +380,7 @@ jobs:

- run: echo WHEEL_GH_ARTIFACT_NAME=wheel-${{ matrix.py-version }} >> $GITHUB_ENV

- uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ env.WHEEL_GH_ARTIFACT_NAME }}

Expand Down Expand Up @@ -416,7 +416,7 @@ jobs:
needs: build
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand All @@ -429,7 +429,7 @@ jobs:
python-version: "3.13"
architecture: 'x64'

- uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: wheel-3.13

Expand Down Expand Up @@ -469,7 +469,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand All @@ -478,7 +478,7 @@ jobs:
with:
python-version: ${{ env.LOWEST_SUPPORTED_PY_VERSION }}
architecture: 'x64'
- uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: wheel-${{ env.LOWEST_SUPPORTED_PY_VERSION }}
- run: python3 -m pip install *.whl
Expand All @@ -500,7 +500,7 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand All @@ -509,7 +509,7 @@ jobs:
with:
python-version: ${{ env.LOWEST_SUPPORTED_PY_VERSION }}
architecture: 'x64'
- uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: wheel-${{ env.LOWEST_SUPPORTED_PY_VERSION }}
- run: python3 -m pip install *.whl
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/stage-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -83,7 +83,7 @@ jobs:
# TODO: the checkout code is also duplicated in the macOS stage tests
# But it's only a few lines of code so I didn't bother to create a composite action for it.
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down Expand Up @@ -199,7 +199,7 @@ jobs:
runs-on: ${{ matrix.runner-os-and-arch[0] }}
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/stage-to-master.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,19 +41,19 @@ jobs:
needs: build-artifacts
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@a90bcbc6539c36a85cdfeb73f7e2f433735f215b # v2.15.0
uses: step-security/harden-runner@f808768d1510423e83855289c910610ca9b43176 # v2.17.0
with:
egress-policy: audit

- name: Download and store all artifacts to single folder
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
path: artifacts
merge-multiple: true

# TODO: fix
- name: Publish package distributions to PyPI
uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # release/v1
uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # release/v1
with:
packages-dir: artifacts/
password: ${{ secrets.PYPI_API_TOKEN }}
Expand Down
Loading
Loading