Skip to content

ci: audit DiffBio's lock through substrax's audit-lock action - #31

Merged
mahdi-shafiei merged 1 commit into
mainfrom
ci/audit-lock
Oct 1, 2026
Merged

mahdi-shafiei merged 1 commit into
mainfrom
ci/audit-lock

Conversation

@mahdi-shafiei

Copy link
Copy Markdown
Collaborator

Why

The Security job ran uv run --with pip-audit pip-audit --local --desc. That command audits the environment pip-audit itself runs in, not DiffBio's lock. A green result therefore said nothing about DiffBio's dependencies, and no extra outside that environment was ever audited.

What

  • security.yml: the audit is now substrax's audit-lock action, avitai/substrax/.github/actions/audit-lock@13e98b78127606be04437bd7c5de894fb765a28e. It is pinned by commit like the already-tested gate and runs after setup-diffbio, which installs uv. The action exports every extra in uv.lock, in groups that respect [tool.uv] conflicts, and audits each export with pip-audit 2.10.1 through uvx, using a fresh advisory cache. It fails on any advisory that [tool.substrax.audit-lock.ignore] in pyproject.toml does not name, and on any ignore entry that no advisory matches. DiffBio needs no ignores, so the table is absent.

  • Bandit keeps its exact command but moves into its own step with if: ${{ !cancelled() }}, so it still runs after a failed audit. A failure in either step fails the job. The uploaded artifact now holds only bandit-report.json.

  • Lock changes. The whole-lock audit of main found four advisories, all in the docs extra:

    • mkdocs-material 9.7.6 -> 9.7.7 closes PYSEC-2026-3864, an XSS in search.suggest.
    • pymdown-extensions 10.21.2 -> 12.1 closes PYSEC-2026-2999 (snippets path restriction), PYSEC-2026-3609 (b64 path traversal) and PYSEC-2026-3654 (regex backtracking). The fixed releases are 10.21.3, 11.0.0 and 11.0.1, and 12.1 is the latest version the declared floors allow.

    Only these two packages moved (uv lock --upgrade-package ... --refresh-package ...).

  • CHANGELOG [Unreleased] entries.

Tests

  • tests/test_ci_security.py (new) checks four things: the audit is the shared action pinned to a full SHA, uv is set up before it, no step runs pip-audit, and bandit runs after a failed audit with no captured exit status. All four tests failed before the workflow change and pass after it.
  • pytest tests/test_ci_security.py tests/test_ci_concurrency.py tests/test_ci_docs.py --no-cov: 21 passed. pre-commit run --all-files: exit 0. uv lock --check: exit 0. bandit -c pyproject.toml -r src/diffbio/: no issues.
  • Docs: docs.yml is path-filtered and does not run on a change to uv.lock alone, so the strict build was run locally from a scratch environment synced from this lock. mkdocs build --clean --strict exits 0. Its 128 HTML pages match a build with the old versions, apart from the theme version string and the asset hashes.
  • The action's script from substrax 13e98b7, run locally: on main it reports the four advisories (exit 1); on this branch it reports none (exit 0).

The Security job ran `uv run --with pip-audit pip-audit --local`, which
audits the environment pip-audit runs in, not DiffBio's lock, so a
green audit said nothing about DiffBio's dependencies. The job now uses
substrax's audit-lock action, pinned by commit, which exports every
extra the lock resolves and audits each export with a pinned pip-audit
and a fresh advisory cache. Bandit keeps its command in its own step,
which runs after a failed audit too; either failure fails the job.

The whole-lock audit reported four advisories, all in the docs extra,
and the lock closes each:
- mkdocs-material 9.7.6 -> 9.7.7: PYSEC-2026-3864
- pymdown-extensions 10.21.2 -> 12.1: PYSEC-2026-2999, PYSEC-2026-3609,
  PYSEC-2026-3654

`mkdocs build --strict` passes with the new lock, and its pages match
the old lock's except for the theme version and asset hashes.
@mahdi-shafiei
mahdi-shafiei merged commit ce4d486 into main Oct 1, 2026
13 checks passed
@mahdi-shafiei
mahdi-shafiei deleted the ci/audit-lock branch October 1, 2026 04:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant