From 2b67634d15ab9f9203945c1c07f34456225cd58d Mon Sep 17 00:00:00 2001 From: Nishtha Date: Wed, 23 Sep 2026 08:59:09 +0100 Subject: [PATCH 1/6] Fix Python setup for dependency updates Configure the setup action to install Python 3.11 before running the dependency update command. The justfile defaults to python3.11, so the workflow [failed](https://github.com/opensafely/documentation/actions/runs/35734406042/job/107089817671) with "python3.11: command not found" before it could update any dependencies. Also align the workflow with [reports](https://github.com/opensafely-core/reports/blob/main/.github/workflows/update-dependencies.yml) by using the latest Ubuntu runner and limiting the GitHub App token to contents and pull-request write permissions. --- .github/workflows/update-python-dependencies.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/update-python-dependencies.yml b/.github/workflows/update-python-dependencies.yml index e8c68293..ffce2f12 100644 --- a/.github/workflows/update-python-dependencies.yml +++ b/.github/workflows/update-python-dependencies.yml @@ -10,7 +10,7 @@ permissions: jobs: update-dependencies: - runs-on: ubuntu-24.04 + runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -18,6 +18,7 @@ jobs: - uses: opensafely-core/setup-action@d9171097dd0d37bdb7bed58f701eb03ff317ed17 # v1.7.0 with: + python-version: "3.11" install-just: true - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 @@ -25,8 +26,10 @@ jobs: with: app-id: ${{ vars.CREATE_PR_APP_ID }} private-key: ${{ secrets.CREATE_PR_APP_PRIVATE_KEY }} + permission-contents: write + permission-pull-requests: write - - uses: bennettoxford/update-dependencies-action@b77a22bcfe1d06020d908e64c9828fe944da3a5e + - uses: bennettoxford/update-dependencies-action@b77a22bcfe1d06020d908e64c9828fe944da3a5e # v1 id: update with: token: ${{ steps.generate-token.outputs.token }} From e1b3a65e816111e2425e228f240da6b9ee480086 Mon Sep 17 00:00:00 2001 From: Thomas O'Dwyer Date: Wed, 23 Sep 2026 12:01:23 +0100 Subject: [PATCH 2/6] Replace 'app-id' with 'client-id' Warning: Input 'app-id' has been deprecated with message: Use 'client-id' instead. --- .github/workflows/update-python-dependencies.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/update-python-dependencies.yml b/.github/workflows/update-python-dependencies.yml index ffce2f12..b97e4758 100644 --- a/.github/workflows/update-python-dependencies.yml +++ b/.github/workflows/update-python-dependencies.yml @@ -24,7 +24,7 @@ jobs: - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 id: generate-token with: - app-id: ${{ vars.CREATE_PR_APP_ID }} + client-id: ${{ vars.CREATE_PR_APP_ID }} private-key: ${{ secrets.CREATE_PR_APP_PRIVATE_KEY }} permission-contents: write permission-pull-requests: write From 6aadc3ef8b35ffb4c89b3a8d51b1b38d72350154 Mon Sep 17 00:00:00 2001 From: Thomas O'Dwyer Date: Wed, 23 Sep 2026 12:03:13 +0100 Subject: [PATCH 3/6] Format with Prettier --- .../workflows/update-python-dependencies.yml | 38 +++++++++---------- 1 file changed, 19 insertions(+), 19 deletions(-) diff --git a/.github/workflows/update-python-dependencies.yml b/.github/workflows/update-python-dependencies.yml index b97e4758..eae6ea1a 100644 --- a/.github/workflows/update-python-dependencies.yml +++ b/.github/workflows/update-python-dependencies.yml @@ -3,7 +3,7 @@ name: Update Python dependencies on: workflow_dispatch: schedule: - - cron: "16 7 * * MON" + - cron: "16 7 * * MON" permissions: contents: read @@ -12,24 +12,24 @@ jobs: update-dependencies: runs-on: ubuntu-latest steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - - uses: opensafely-core/setup-action@d9171097dd0d37bdb7bed58f701eb03ff317ed17 # v1.7.0 - with: - python-version: "3.11" - install-just: true + - uses: opensafely-core/setup-action@d9171097dd0d37bdb7bed58f701eb03ff317ed17 # v1.7.0 + with: + python-version: "3.11" + install-just: true - - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 - id: generate-token - with: - client-id: ${{ vars.CREATE_PR_APP_ID }} - private-key: ${{ secrets.CREATE_PR_APP_PRIVATE_KEY }} - permission-contents: write - permission-pull-requests: write + - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 + id: generate-token + with: + client-id: ${{ vars.CREATE_PR_APP_ID }} + private-key: ${{ secrets.CREATE_PR_APP_PRIVATE_KEY }} + permission-contents: write + permission-pull-requests: write - - uses: bennettoxford/update-dependencies-action@b77a22bcfe1d06020d908e64c9828fe944da3a5e # v1 - id: update - with: - token: ${{ steps.generate-token.outputs.token }} + - uses: bennettoxford/update-dependencies-action@b77a22bcfe1d06020d908e64c9828fe944da3a5e # v1 + id: update + with: + token: ${{ steps.generate-token.outputs.token }} From 08b03d51b5d9fa7cc0c4b572f2d1628fcf77d680 Mon Sep 17 00:00:00 2001 From: Thomas O'Dwyer Date: Wed, 23 Sep 2026 12:04:32 +0100 Subject: [PATCH 4/6] Fix issues raised by zizmor --- .github/workflows/update-python-dependencies.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/update-python-dependencies.yml b/.github/workflows/update-python-dependencies.yml index eae6ea1a..38dd5108 100644 --- a/.github/workflows/update-python-dependencies.yml +++ b/.github/workflows/update-python-dependencies.yml @@ -8,8 +8,13 @@ on: permissions: contents: read +concurrency: + group: update-python-dependencies + cancel-in-progress: false + jobs: update-dependencies: + name: Update dependencies runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 From 558bf23d4d44b3228947c10794ec866a1829f0a4 Mon Sep 17 00:00:00 2001 From: Thomas O'Dwyer Date: Wed, 23 Sep 2026 12:06:00 +0100 Subject: [PATCH 5/6] Quote all YAML strings To prevent YAML parsing issues before they become a problem --- .../workflows/update-python-dependencies.yml | 32 +++++++++---------- 1 file changed, 16 insertions(+), 16 deletions(-) diff --git a/.github/workflows/update-python-dependencies.yml b/.github/workflows/update-python-dependencies.yml index 38dd5108..3c4bf26f 100644 --- a/.github/workflows/update-python-dependencies.yml +++ b/.github/workflows/update-python-dependencies.yml @@ -1,4 +1,4 @@ -name: Update Python dependencies +name: "Update Python dependencies" on: workflow_dispatch: @@ -6,35 +6,35 @@ on: - cron: "16 7 * * MON" permissions: - contents: read + contents: "read" concurrency: - group: update-python-dependencies + group: "update-python-dependencies" cancel-in-progress: false jobs: update-dependencies: - name: Update dependencies - runs-on: ubuntu-latest + name: "Update dependencies" + runs-on: "ubuntu-latest" steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: "actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1" # v7.0.1 with: persist-credentials: false - - uses: opensafely-core/setup-action@d9171097dd0d37bdb7bed58f701eb03ff317ed17 # v1.7.0 + - uses: "opensafely-core/setup-action@d9171097dd0d37bdb7bed58f701eb03ff317ed17" # v1.7.0 with: python-version: "3.11" install-just: true - - uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 - id: generate-token + - uses: "actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1" # v3.2.0 + id: "generate-token" with: - client-id: ${{ vars.CREATE_PR_APP_ID }} - private-key: ${{ secrets.CREATE_PR_APP_PRIVATE_KEY }} - permission-contents: write - permission-pull-requests: write + client-id: "${{ vars.CREATE_PR_APP_ID }}" + private-key: "${{ secrets.CREATE_PR_APP_PRIVATE_KEY }}" + permission-contents: "write" + permission-pull-requests: "write" - - uses: bennettoxford/update-dependencies-action@b77a22bcfe1d06020d908e64c9828fe944da3a5e # v1 - id: update + - uses: "bennettoxford/update-dependencies-action@b77a22bcfe1d06020d908e64c9828fe944da3a5e" # v1 + id: "update" with: - token: ${{ steps.generate-token.outputs.token }} + token: "${{ steps.generate-token.outputs.token }}" From 61bda53af4d67a3d86c3e09f58883476e51af88f Mon Sep 17 00:00:00 2001 From: Thomas O'Dwyer Date: Wed, 23 Sep 2026 12:09:45 +0100 Subject: [PATCH 6/6] Add owner and repo to create-github-app-token GitHub Action runner reports: Inputs 'owner' and 'repositories' are not set. Creating token for this repository (opensafely/documentation). --- .github/workflows/update-python-dependencies.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/update-python-dependencies.yml b/.github/workflows/update-python-dependencies.yml index 3c4bf26f..5d57dbcc 100644 --- a/.github/workflows/update-python-dependencies.yml +++ b/.github/workflows/update-python-dependencies.yml @@ -31,6 +31,8 @@ jobs: with: client-id: "${{ vars.CREATE_PR_APP_ID }}" private-key: "${{ secrets.CREATE_PR_APP_PRIVATE_KEY }}" + owner: "opensafely" + repositories: "documentation" permission-contents: "write" permission-pull-requests: "write"