Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
167 commits
Select commit Hold shift + click to select a range
1e4a66a
chore: sync develop after v1.2.1 release
Aug 29, 2026
17f55a6
Merge pull request #128 from pullboxapp/feature/sync-develop-1.2.1
DeusExTaco Aug 29, 2026
e6f7f9f
fix(import): preserve folder grouping and exact issue numbers
Aug 30, 2026
e1a0007
feat(import): add versioned source layout analysis
Aug 30, 2026
292a661
feat(import): add read-only layout preview API
Aug 30, 2026
d0a948a
feat(import): persist durable layout choices
Aug 30, 2026
67fa9de
feat(import): apply selected source layouts
Aug 30, 2026
e74a428
feat(import): add source layout setup UI
Aug 30, 2026
7c51bd7
feat(import): review selected layout outliers
Aug 30, 2026
e235df7
feat(import): establish referenced file ownership
Aug 30, 2026
d05c120
feat(import): enable safe in-place adoption
Aug 30, 2026
3bd081e
fix(library): keep referenced repairs read only
Aug 30, 2026
4fd5060
feat(library): add per-root naming policy foundation
Aug 30, 2026
799a023
feat(import): activate adopted root policy safely
Aug 30, 2026
6e9f872
feat(library): expose per-root naming policy controls
Aug 30, 2026
88a8ffe
feat(import): add future layout setup
Aug 30, 2026
0ea4735
feat(import): apply selected layouts to Mylar paths
Aug 30, 2026
abfc1c2
feat(import): expose Mylar source layout controls
Aug 30, 2026
75e747e
feat(import): surface unsafe Mylar path mappings
Aug 30, 2026
7ed4a79
feat(import): reconcile trusted Mylar metadata
Aug 30, 2026
f0b19b1
test(import): cover multiple Mylar path roots
Aug 30, 2026
f0ab70a
feat(import): establish story arc evidence foundation
Aug 30, 2026
34595f5
feat(import): add first-class story arc domain
Aug 30, 2026
ecd22c2
feat(import): harden story arc placement and sync
Aug 30, 2026
72eae6b
feat(import): confirm story arc policy and references
Aug 30, 2026
49314de
feat(import): make story arc placement handoff durable
Aug 30, 2026
afd0ab5
perf(import): bound scanner and rollback work
Aug 30, 2026
9f18446
feat(import): close story arc review gaps
Aug 30, 2026
a56ca76
perf(import): page matching and deduplication
Aug 30, 2026
58ee6f9
perf(import): bound execution benchmark reports
Aug 30, 2026
883c220
feat(story-arcs): make managed reorder crash safe
Aug 30, 2026
55eb7f3
feat(import): add bounded bulk safety review
Aug 30, 2026
6ad179d
fix(import): expose partial bulk safety eligibility
Aug 30, 2026
6ca53cf
perf(import): bound safety review summaries
Aug 30, 2026
20e69c2
perf(import): standardize target scale evidence
Aug 30, 2026
03a0a5c
feat(import): add bulk safety review UI
Aug 30, 2026
01b95dc
perf(import): bound file matching and conflict rebuild
Aug 30, 2026
b297f86
feat(story-arcs): prepare policy migration safely
Aug 30, 2026
6f091f5
fix(import): restore validation and SQL safety contracts
Aug 30, 2026
a2cf261
fix(story-arcs): contain placement roots
Aug 30, 2026
7c0ab7f
perf(import): spool inventory and bound scanner work
Aug 30, 2026
547afaa
docs(import): clarify testing candidate limits
Aug 30, 2026
a5bde0b
chore(ci): refresh import fixture secret-scan baseline
Aug 30, 2026
09f306b
test(import): isolate migration and align regression fixtures
Aug 30, 2026
f47c1dd
feat: complete import adoption and story arc discovery
Aug 30, 2026
3331611
ci: stabilize selection coverage and preserve failed smoke containers
Aug 30, 2026
1263163
ci: align local security gates and refresh reviewed baselines
Aug 30, 2026
35e7579
fix(import): make conflict queries and arc cleanup portable
Aug 31, 2026
8edf978
ci: install browser dependencies and isolate UI fixtures
Aug 31, 2026
bd6bc1e
test: cover utility queue snapshot polling states
Aug 31, 2026
5705384
ci(deps): bump the actions-all group with 4 updates (#134)
dependabot[bot] Aug 31, 2026
69b5efd
fix(import): preserve exact identities and enforce preview boundaries
Aug 31, 2026
a7c785c
ci: sync updated action pins from develop
Aug 31, 2026
806e443
Merge pull request #133 from pullboxapp/feature/import-update
DeusExTaco Aug 31, 2026
3a8c018
chore: bump development version to 1.3.0-dev
Aug 31, 2026
e1f3220
chore(dev): resolve hooks from worktree environment
Aug 31, 2026
e09fe77
feat(story-arcs): gate manual creation behind feature flag
Aug 31, 2026
a7e44db
chore(dev): add isolated worktree bootstrap
Aug 31, 2026
87586a0
feat(story-arcs): align registry and add flow
Aug 31, 2026
6cfe160
feat(story-arcs): align registry with series views
Aug 31, 2026
4dd9114
feat(story-arcs): preserve breadcrumb hierarchy
Aug 31, 2026
33129d5
feat(story-arcs): align detail page with series
Sep 1, 2026
b654461
fix(story-arcs): align detail controls and statuses
Sep 1, 2026
65e63ff
feat(import): harden multi-library and Mylar workflows
Sep 1, 2026
9f960e4
fix(import): harden restart and rollback recovery
Sep 1, 2026
d1d722b
perf(import): harden large-library workflows
Sep 1, 2026
06664fe
fix(import): preserve sidecar folder identity
Sep 1, 2026
b54e0d7
test(import): align progress logs with download contract
Sep 1, 2026
a4102eb
fix(story-arcs): stabilize paginated fallback cover
Sep 1, 2026
b42b5b4
ci: gate coverage on production Python
Sep 1, 2026
429fa1a
Merge pull request #135 from pullboxapp/feature/import-scale-certific…
DeusExTaco Sep 1, 2026
a91fd4b
feat(story-arcs): unify monitoring and discover new members
Sep 2, 2026
a603979
feat(story-arcs): centralize file defaults and gate manual editing
Sep 2, 2026
cd9b0dd
feat(settings): unify global and library naming editors
Sep 2, 2026
b37a720
feat(story-arcs): align provider update review with detail page UI
Sep 2, 2026
4657793
fix(import): expose Mylar path exceptions and keep diagnostics respon…
Sep 2, 2026
094d966
fix(import): keep Mylar scans responsive and progress accurate
Sep 2, 2026
5511a08
fix(import): preserve supported Unicode in Mylar paths
Sep 2, 2026
623d2bc
fix(import): optimize large-library review and size warnings
Sep 2, 2026
30f0df2
fix(import): unify source identity and comic content review
Sep 2, 2026
000a063
fix(search): match four-digit issues using catalog publication dates
Sep 2, 2026
8287a36
fix(sabnzbd): bound slow NZB retrieval separately from client requests
Sep 2, 2026
6709bc4
fix(search): complete automatic AirDC++ acquisition and failure repor…
Sep 2, 2026
cf11d56
fix(import): safely reconcile stale Mylar file references
Sep 2, 2026
2998098
ci(security): bound temporary Safety NLTK risk acceptance
Sep 3, 2026
edffb37
test(import): mark synthetic cohort identity as non-secret
Sep 3, 2026
900841d
test(e2e): stabilize story arc settings toggle setup
Sep 3, 2026
11e7aa9
fix(search): preserve lifecycle evidence in Story Arc targets
Sep 3, 2026
89418f2
Merge pull request #136 from pullboxapp/feature/v1.3-followup-fixes
DeusExTaco Sep 3, 2026
0c0d4df
perf(import): bound archive inspection and reduce scan overhead
Sep 3, 2026
90f4148
fix: stabilize import scan and review progress estimates
Sep 3, 2026
2724325
fix: calculate import ETA from precise weighted work
Sep 3, 2026
766750a
fix: clear completed recovery activity and publish live progress
Sep 3, 2026
289d660
fix: prioritize catalog hydration during metadata sync
Sep 3, 2026
270bc59
perf: accelerate post-import metadata hydration
Sep 4, 2026
426e010
fix: harden large import recovery and reconciliation
Sep 4, 2026
fcd4cd8
fix: revalidate changed import sources on retry
Sep 4, 2026
6d2eb2d
ci: refresh reviewed DHI zlib exception
Sep 4, 2026
b32e08d
fix: harden import recovery batch boundaries
Sep 4, 2026
b0a5299
test: remove scanner progress timing assumption
Sep 4, 2026
d0cb630
security: harden issue parsing and document API key fingerprint
Sep 4, 2026
1e35d01
Merge pull request #137 from pullboxapp/feature/import-scan-performance
DeusExTaco Sep 4, 2026
4d1210c
feat: add completed import recovery cleanup
Sep 5, 2026
b75374a
fix: scope completed import recovery actions safely
Sep 5, 2026
caa8280
Merge pull request #138 from pullboxapp/feature/import-recovery-cleanup
DeusExTaco Sep 5, 2026
3119238
feat: safely remove disabled library roots
Sep 5, 2026
acff1d5
fix: show reading progress for large compendiums
Sep 5, 2026
9bf0309
fix(import): harden large Mylar recovery
Sep 6, 2026
3b671fa
feat(import): add clean library recovery workflow
Sep 7, 2026
d02402c
fix(import): align dropdowns with shared UI contract
Sep 8, 2026
c6011e8
feat(import): simplify guided collection workflow
Sep 9, 2026
2c0aeb3
feat(import): simplify Mylar preflight issue resolution
Sep 9, 2026
7f8b6ae
feat(import): simplify managed destination choices
Sep 9, 2026
84770c6
fix(import): prevent preflight controls from flashing
Sep 9, 2026
cac9183
feat(import): recover misplaced Mylar issue files
Sep 9, 2026
a540264
fix(import): streamline review step controls
Sep 9, 2026
6d18556
fix(import): reconcile misplaced Mylar series
Sep 10, 2026
3f8430b
fix(import): reconcile stale Mylar issue IDs
Sep 10, 2026
48dbbec
fix(import): reconcile unqualified Mylar volume identities
Sep 10, 2026
1bd61aa
fix(import): recover safety-approved review items
Sep 10, 2026
e6cdde6
fix(import): reconcile renamed Mylar issue files
Sep 10, 2026
2a86fb3
feat(import): centralize completed import follow-up
Sep 10, 2026
47c8edb
build(ui): refresh generated Tailwind styles
Sep 10, 2026
75f0d84
fix(ci): restore import review contracts
Sep 10, 2026
4d99cff
fix(ui): restore async workflow state
Sep 10, 2026
a67cc3b
test(ci): restore required coverage
Sep 10, 2026
2ace463
ci(security): review current DHI Expat findings
Sep 10, 2026
5ed0d68
fix(import): restore archived history toggle
Sep 10, 2026
ed0655f
feat(import): run clean library builds in background
Sep 10, 2026
d7f2dd1
fix(settings): align library root actions
Sep 10, 2026
afd3559
fix(import): resolve folder in-place root setup
Sep 11, 2026
4a1a6e5
fix(ci): restore full release gate compliance
Sep 11, 2026
e15a7e1
fix(security): escape import rematch poll target
Sep 11, 2026
5127b62
fix(import): resume hydration and refresh arc recovery
Sep 11, 2026
dce2d88
test(import): await hydration worker shutdown
Sep 11, 2026
d1fd907
fix(import): preserve adoption file dependents
Sep 11, 2026
7cc76b8
fix(import): align follow-up action eligibility
Sep 11, 2026
c5e87eb
fix(import): guard clean library execution
Sep 11, 2026
9eebbc2
Merge pull request #141 from pullboxapp/feature/v1.3-edge-fixes
DeusExTaco Sep 11, 2026
8dcd7ec
feat(ui): add selectable header creation action
Sep 11, 2026
b098b59
fix(ui): unify Comic Vine search loading states
Sep 11, 2026
04e913f
feat(story-arcs): unify Comic Vine discovery and reading-order review
Sep 12, 2026
3befe48
fix(ui): unify story arc search and streamline reading order
Sep 12, 2026
ca882a2
fix(ui): remove initial arc files card from story arc details
Sep 12, 2026
d0b142a
fix(import): recover trusted identities from completed legacy imports
Sep 13, 2026
d1abde5
fix(downloads): upload torrent metadata instead of private indexer URLs
Sep 13, 2026
095ec31
ci: renew scoped DHI runtime vulnerability exceptions
Sep 13, 2026
f023c6f
fix: address import recovery and story arc cache review findings
Sep 13, 2026
62e1626
Merge pull request #142 from pullboxapp/feature/story-arc-improvements
DeusExTaco Sep 13, 2026
1dd9027
feat: add verified local Comic Vine catalog downloads and matching
Sep 13, 2026
a3c502b
fix: harden local catalog recovery and settings order
Sep 14, 2026
a468d14
fix: preserve new focus choices during story arc reordering
Sep 14, 2026
959768a
fix: prevent stale dropdown focus restoration
Sep 14, 2026
32abc0b
Merge pull request #143 from pullboxapp/feature/catalog-v2-client
DeusExTaco Sep 14, 2026
9b37740
fix(import): restore terminal recovery actions
Sep 14, 2026
6dc336e
Merge pull request #145 from pullboxapp/feature/import-recovery-healt…
DeusExTaco Sep 14, 2026
b0b5c66
fix(import): recover terminal follow-up outcomes
Sep 14, 2026
c2e5e79
feat(import): add resumable deferred file recovery
Sep 14, 2026
094cb2a
fix(import): tighten deferred recovery evidence
Sep 14, 2026
d32ce7e
fix(import): secure follow-up recovery scope
Sep 14, 2026
c2b60b3
Merge pull request #146 from pullboxapp/feature/import-recovery-follo…
DeusExTaco Sep 14, 2026
8d599b7
fix(import): harden recovery checkpoints and retries
Sep 14, 2026
9e6ae68
fix(import): revalidate recheck rows before apply
Sep 14, 2026
456e20c
Merge pull request #147 from pullboxapp/feature/import-recovery-check…
DeusExTaco Sep 14, 2026
edf8825
chore: prepare v1.3.0 release
Sep 16, 2026
19ca718
ci: retain approved libc runtime exception
Sep 16, 2026
e3ff077
ci: record approved exact strfmon runtime exception
Sep 16, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
4 changes: 4 additions & 0 deletions .env.dev.example
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,10 @@ PULLBOX_LOG_LEVEL=INFO
PULLBOX_LOG_SIZE_LIMIT_MB=1
PULLBOX_LOG_BACKUP_COUNT=5

# Manual creation of empty Story Arcs is experimental. Provider and import
# creation remain available while this is disabled.
PULLBOX_STORY_ARC_MANUAL_CREATE_ENABLED=false

# ── Embedded Comic Reader ───────────────────────────────────────────
# Default-on emergency gate. Disabling it preserves comics and resume state.
PULLBOX_READER_ENABLED=true
Expand Down
226 changes: 226 additions & 0 deletions .github/scripts/validate-development-image.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,226 @@
"""Require completed, same-commit development validation before publishing edge.

Only explicit runs of the four trusted workflows on develop are accepted. PR
aggregates (including preflight and release-sync fast paths) are not evidence
that the exact commit being packaged passed the full validation suite.
"""

from __future__ import annotations

import json
import os
import re
import subprocess
import sys
from typing import Any
from urllib.parse import urlencode

REQUIRED_JOBS: dict[str, dict[str, tuple[str, ...]]] = {
"ci.yml": {
"Quality Gate": ("Ruff lint", "Ruff format check", "Check for uncommitted CSS changes"),
"Type Check": ("Mypy",),
"Migration Check": (
"Verify migrations apply from empty DB",
"Verify app boots after migration",
),
"Test (Python 3.12)": ("Run tests with coverage",),
"Test (Python 3.13)": ("Run tests with coverage",),
"Test (Python 3.14)": ("Run tests with coverage",),
"Accessibility Checks": ("Run contrast audit", "Run accessibility browser tests"),
"E2E Tests (chromium)": ("Run E2E tests",),
"E2E Tests (firefox)": ("Run E2E tests",),
"CI Required": (),
},
"security.yml": {
"Gitleaks": ("Run gitleaks on current tree",),
"pip-audit": ("Run pip-audit",),
"Safety Check": ("Run safety check",),
"Bandit": ("Run Bandit", "Upload Bandit report"),
"Security Required": (),
},
"workflow-hygiene.yml": {
"actionlint": ("Run actionlint",),
"Workflow Hygiene Required": (),
},
"docker-validate.yml": {
"Production Docker Validate (trusted)": (
"Build production Docker image",
"Verify container security runtime",
"Run Grype scan",
"Verify packaged static assets",
"Wait for healthy",
),
"Docker Validate Required": (),
},
}


class ValidationError(ValueError):
"""The available evidence cannot authorize a development publication."""


def _object(value: Any) -> dict[str, Any]:
if not isinstance(value, dict):
raise ValidationError("GitHub returned an unexpected response shape.")
return value


def _positive_id(value: Any) -> int:
if type(value) is not int or value <= 0:
raise ValidationError("GitHub returned an invalid run or check identifier.")
return value


def latest_run(runs: list[dict[str, Any]]) -> dict[str, Any]:
if not runs:
raise ValidationError("No manual develop validation run exists for this commit.")
return max(runs, key=lambda run: _positive_id(run.get("id")))


def validate_evidence(
workflow: str,
run: dict[str, Any],
suite: dict[str, Any],
jobs: list[dict[str, Any]],
repository: str,
sha: str,
) -> None:
expected = {
"path": f".github/workflows/{workflow}",
"event": "workflow_dispatch",
"head_sha": sha,
"head_branch": "develop",
"status": "completed",
"conclusion": "success",
}
if any(run.get(key) != value for key, value in expected.items()):
raise ValidationError(
f"{workflow}: latest run is not a successful exact-commit develop run."
)
for field in ("repository", "head_repository"):
if _object(run.get(field)).get("full_name") != repository:
raise ValidationError(f"{workflow}: validation came from another repository.")
app = _object(suite.get("app"))
if (
suite.get("id") != _positive_id(run.get("check_suite_id"))
or suite.get("head_sha") != sha
or app.get("slug") != "github-actions"
or _object(app.get("owner")).get("login") != "github"
):
raise ValidationError(f"{workflow}: missing trusted GitHub Actions check provenance.")

run_id = _positive_id(run.get("id"))
attempt = _positive_id(run.get("run_attempt"))
for name, required_steps in REQUIRED_JOBS[workflow].items():
matches = [job for job in jobs if job.get("name") == name]
if len(matches) != 1:
raise ValidationError(f"{workflow}: required job {name!r} is missing or duplicated.")
job = matches[0]
if any(
job.get(key) != value
for key, value in {
"run_id": run_id,
"run_attempt": attempt,
"head_sha": sha,
"status": "completed",
"conclusion": "success",
}.items()
):
raise ValidationError(
f"{workflow}: required job {name!r} did not succeed in this attempt."
)
steps = job.get("steps")
if not isinstance(steps, list):
raise ValidationError(f"{workflow}: job {name!r} has no step evidence.")
for step_name in required_steps:
selected = [_object(step) for step in steps if _object(step).get("name") == step_name]
# Preserve the existing advisory Bandit policy, but require that it
# actually ran and that its report job succeeded. Skipped is never OK.
conclusions = {"success"}
if (workflow, name, step_name) == ("security.yml", "Bandit", "Run Bandit"):
conclusions.add("failure")
if (
len(selected) != 1
or selected[0].get("status") != "completed"
or selected[0].get("conclusion") not in conclusions
):
raise ValidationError(
f"{workflow}: required step {step_name!r} did not run successfully."
)


def get_json(endpoint: str) -> dict[str, Any]:
result = subprocess.run(
["gh", "api", "--hostname", "github.com", "--method", "GET", endpoint],
capture_output=True,
text=True,
check=False,
timeout=30,
)
if result.returncode:
# Do not forward CLI errors or response bodies into release logs.
raise ValidationError("Unable to read GitHub validation evidence; publication is blocked.")
return _object(json.loads(result.stdout))


def list_all(endpoint: str, field: str) -> list[dict[str, Any]]:
"""Fail closed on incomplete pagination instead of accepting a partial job set."""
records: list[dict[str, Any]] = []
separator = "&" if "?" in endpoint else "?"
for page in range(1, 11):
payload = get_json(f"{endpoint}{separator}per_page=100&page={page}")
values = payload.get(field)
count = payload.get("total_count")
if not isinstance(values, list) or type(count) is not int or not 0 <= count <= 1000:
raise ValidationError(
"GitHub validation evidence is malformed or exceeds the bounded query."
)
records.extend(_object(value) for value in values)
if len(records) == count:
return records
if len(values) != 100 or len(records) > count:
break
raise ValidationError("GitHub returned incomplete validation evidence.")


def main() -> int:
try:
repository = os.environ["GITHUB_REPOSITORY"]
sha = os.environ["GITHUB_SHA"]
if (
os.environ.get("GITHUB_EVENT_NAME") != "workflow_dispatch"
or os.environ.get("GITHUB_REF") != "refs/heads/develop"
or not re.fullmatch(r"[A-Za-z0-9_.-]+/[A-Za-z0-9_.-]+", repository)
or not re.fullmatch(r"[0-9a-f]{40}", sha)
):
raise ValidationError("Development publication requires a trusted develop dispatch.")
query = urlencode({"head_sha": sha, "event": "workflow_dispatch", "branch": "develop"})
for workflow in REQUIRED_JOBS:
base = f"repos/{repository}"
run = latest_run(
list_all(f"{base}/actions/workflows/{workflow}/runs?{query}", "workflow_runs")
)
run_id = _positive_id(run.get("id"))
attempt = _positive_id(run.get("run_attempt"))
suite_id = _positive_id(run.get("check_suite_id"))
suite = get_json(f"{base}/check-suites/{suite_id}")
jobs = list_all(f"{base}/actions/runs/{run_id}/attempts/{attempt}/jobs", "jobs")
validate_evidence(workflow, run, suite, jobs, repository, sha)
print(f"Validated {workflow}: run {run_id}, attempt {attempt}, commit {sha}")
except (
ValidationError,
KeyError,
OSError,
subprocess.TimeoutExpired,
json.JSONDecodeError,
) as exc:
message = (
str(exc) if isinstance(exc, ValidationError) else "Unable to load validation evidence."
)
print(f"::error::{message}", file=sys.stderr)
return 1
return 0


if __name__ == "__main__":
raise SystemExit(main())
22 changes: 19 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -171,6 +171,8 @@ jobs:

# ──────────────────────────────────────────────
# Job 3: Tests + Coverage (matrix: 3.12, 3.13, 3.14)
# Every version runs the complete suite and publishes coverage. The blocking
# 90% release gate follows the production/default Python 3.14 runtime.
# ──────────────────────────────────────────────
test:
name: Test (Python ${{ matrix.python-version }})
Expand All @@ -183,7 +185,13 @@ jobs:
strategy:
fail-fast: false
matrix:
python-version: ["3.12", "3.13", "3.14"]
include:
- python-version: "3.12"
coverage_fail_under: 0
- python-version: "3.13"
coverage_fail_under: 0
- python-version: "3.14"
coverage_fail_under: 90
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

Expand All @@ -206,10 +214,11 @@ jobs:
--cov=pullbox \
--cov-report=xml \
--cov-report=term-missing \
--cov-fail-under=90 \
--cov-fail-under="${COVERAGE_FAIL_UNDER}" \
--junitxml=test-results.xml \
-v
env:
COVERAGE_FAIL_UNDER: ${{ matrix.coverage_fail_under }}
PULLBOX_SECRET_KEY: test-ci-key
PYTEST_WORKERS: ${{ env.PYTEST_WORKERS }}

Expand Down Expand Up @@ -391,8 +400,15 @@ jobs:
- name: Setup runner-local venv
run: .github/scripts/setup-runner-venv.sh "dev,e2e"

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24"

- name: Install Node dependencies
run: npm ci

- name: Runner preflight
run: .github/scripts/preflight-runner.sh python playwright
run: .github/scripts/preflight-runner.sh python node playwright

- name: Install Playwright browsers
run: playwright install ${{ matrix.browser }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/codeql-branch-probe.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,14 +33,14 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Initialize CodeQL
uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
languages: python
queries: +security-extended
config-file: ./.github/codeql/codeql-config.yml

- name: Perform CodeQL analysis
uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v4.37.9
with:
category: "/language:python"

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/docker-release-benchmark.yml
Original file line number Diff line number Diff line change
Expand Up @@ -353,7 +353,7 @@ jobs:
< scripts/verify_container_security_runtime.py

- name: Run Grype scan
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 # v7.4.0
uses: anchore/scan-action@27805bf3b4e84b4a5c980df22ed233c00390a439 # v7.4.2
with:
image: ${{ env.LOCAL_IMAGE }}
fail-build: true
Expand Down
Loading
Loading