Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion .github/workflows/test_cc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,10 @@ jobs:
python-version: "3.11"
cache: "pip"
- uses: lukka/get-cmake@latest
- run: python -m pip install uv
- name: Install uv
uses: astral-sh/setup-uv@v7

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Locate all workflows that use astral-sh/setup-uv
rg -n --hidden --glob '.github/workflows/*' 'uses:\s*astral-sh/setup-uv@' .github/workflows || true

# Print the surrounding lines for each match (to capture the exact ref)
rg -n --hidden --glob '.github/workflows/*' -U 'uses:\s*astral-sh/setup-uv@' .github/workflows \
  | sed -E 's/^([^:]+):([0-9]+):.*/\1:\2/' \
  | sort -u \
  | while IFS=: read -r file line; do
      echo "---- $file:$line ----"
      # Show ~3 lines around the usage
      nl -ba "$file" | awk -v L="$line" 'NR>=L-3 && NR<=L+3 {print}'
    done

Repository: deepmodeling/deepmd-kit

Length of output: 407


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# List all usages of the setup-uv action across workflows
rg -n --hidden --glob '.github/workflows/*' 'uses:\s*astral-sh/setup-uv@' .github/workflows

echo
echo "=== References (unique) ==="
rg --hidden --glob '.github/workflows/*' 'uses:\s*astral-sh/setup-uv@' .github/workflows \
  | sed -E 's/^.*uses:\s*//' \
  | sort -u

Repository: deepmodeling/deepmd-kit

Length of output: 341


Pin astral-sh/setup-uv to an immutable commit SHA (avoid @v7)
Unpinned uses: references create a shared supply-chain risk across workflows.

  • .github/workflows/test_cc.yml#L45: uses: astral-sh/setup-uv@v7
  • .github/workflows/test_python.yml#L30: uses: astral-sh/setup-uv@v7
  • .github/workflows/copilot-setup-steps.yml#L41: uses: astral-sh/setup-uv@v7

Pin astral-sh/setup-uv to a full commit SHA (and use the same SHA across all workflows).

🧰 Tools
🪛 zizmor (1.25.2)

[error] 45-45: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

📍 Affects 2 files
  • .github/workflows/test_cc.yml#L45-L45 (this comment)
  • .github/workflows/test_python.yml#L30-L30
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/test_cc.yml at line 45, Replace the floating tag for
astral-sh/setup-uv with a pinned full commit SHA in both places; specifically,
in .github/workflows/test_cc.yml (lines 45-45) change `uses:
astral-sh/setup-uv@v7` to `uses: astral-sh/setup-uv@<FULL_COMMIT_SHA>` and in
.github/workflows/test_python.yml (lines 30-30) make the identical change using
the same <FULL_COMMIT_SHA> value so both workflows reference the same immutable
commit SHA.

Source: Linters/SAST tools

with:
enable-cache: true
- name: Install Python dependencies
run: |
source/install/uv_with_retry.sh pip install --system --group pin_tensorflow_cpu --group pin_pytorch_cpu --group pin_jax_cpu --torch-backend cpu
Expand All @@ -63,6 +66,7 @@ jobs:
TF_INTRA_OP_PARALLELISM_THREADS: 1
TF_INTER_OP_PARALLELISM_THREADS: 1
CMAKE_GENERATOR: Ninja
CTEST_PARALLEL_LEVEL: 3
CXXFLAGS: ${{ matrix.check_memleak && '-fsanitize=leak' || '' }}
LSAN_OPTIONS: suppressions=${{ github.workspace }}/.github/workflows/suppr.txt
ENABLE_TENSORFLOW: ${{ matrix.enable_tensorflow && 'TRUE' || 'FALSE' }}
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/test_cuda.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,8 @@ jobs:
DP_ENABLE_NATIVE_OPTIMIZATION: 1
DP_ENABLE_PYTORCH: 1
- run: dp --version
- run: python -m pytest source/tests
- name: Test Python on CUDA
run: python -m pytest source/tests --ignore=source/tests/pt_expt
env:
NUM_WORKERS: 0
CUDA_VISIBLE_DEVICES: 0
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/test_python.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,10 @@ jobs:
- uses: actions/setup-python@v6
with:
python-version: ${{ matrix.python }}
- run: python -m pip install -U uv
- name: Install uv
uses: astral-sh/setup-uv@v7
with:
enable-cache: true
- run: |
source/install/uv_with_retry.sh pip install --system openmpi --group pin_tensorflow_cpu --group pin_pytorch_cpu --torch-backend cpu
export TENSORFLOW_ROOT=$(python -c 'import importlib.util,pathlib;print(pathlib.Path(importlib.util.find_spec("tensorflow").origin).parent)')
Expand Down
2 changes: 1 addition & 1 deletion source/install/test_cc_local.sh
Original file line number Diff line number Diff line change
Expand Up @@ -102,4 +102,4 @@ if [ "${ENABLE_PADDLE:-TRUE}" == "TRUE" ]; then
PADDLE_INFERENCE_DIR=${BUILD_TMP_DIR}/paddle_inference_install_dir
export LD_LIBRARY_PATH=${LD_LIBRARY_PATH}:${PADDLE_INFERENCE_DIR}/third_party/install/onednn/lib:${PADDLE_INFERENCE_DIR}/third_party/install/mklml/lib
fi
ctest --output-on-failure
ctest --output-on-failure --parallel "${CTEST_PARALLEL_LEVEL:-1}"
Loading