Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 15 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -316,10 +316,23 @@ jobs:
targets: wasm32-unknown-unknown, wasm32-wasip1
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
- name: install wasmtime (executes the wasip1 test binary)
# Pinned release + sha256 verification, instead of `curl | bash` of an
# unpinned install script (Scorecard Pinned-Dependencies / supply chain).
# Arch-derived so the job survives a switch to an ARM Ubuntu runner.
env:
WASMTIME_VERSION: v45.0.0
run: |
set -euo pipefail
curl -sSfL https://wasmtime.dev/install.sh | bash
echo "${HOME}/.wasmtime/bin" >> "${GITHUB_PATH}"
case "$(uname -m)" in
x86_64) arch=x86_64; sha256=9d92e6dc04630f617e0e5d532327a5a917ac4898587e07f4fb7a5fc7fffef760 ;;
aarch64) arch=aarch64; sha256=4a27083ba8d3c64526b2d469f50e6539cb4c1dd9d08336e0d8953bca616737e3 ;;
*) echo "::error::unsupported runner architecture: $(uname -m)"; exit 1 ;;
esac
tarball="wasmtime-${WASMTIME_VERSION}-${arch}-linux.tar.xz"
curl -sSfLO "https://github.com/bytecodealliance/wasmtime/releases/download/${WASMTIME_VERSION}/${tarball}"
echo "${sha256} ${tarball}" | sha256sum -c -
tar xJf "${tarball}"
echo "${PWD}/wasmtime-${WASMTIME_VERSION}-${arch}-linux" >> "${GITHUB_PATH}"
# RUSTFLAGS is overridden here (dropping the workflow-level -D warnings)
# so a warning in rayon's wasm-only code path can't fail the build; the
# crate's own code is held to -D warnings by the lint/test jobs on the
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/python.yml
Original file line number Diff line number Diff line change
Expand Up @@ -93,7 +93,7 @@ jobs:
toolchain: stable
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
- name: install build + test deps
run: python -m pip install --upgrade pip maturin numpy pytest
run: python -m pip install --require-hashes -r ordvec-python/requirements-dev.txt
- name: build the wheel (abi3, release)
working-directory: ordvec-python
run: maturin build --release --out dist
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/release-python.yml
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@ jobs:
shell: bash
run: |
set -euo pipefail
python -m pip install --upgrade pip pytest numpy
python -m pip install --require-hashes -r ordvec-python/requirements-dev.txt
python -m pip install ordvec-python/dist/*.whl
python -m pytest ordvec-python/tests -q
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
Expand Down Expand Up @@ -112,7 +112,7 @@ jobs:
shell: bash
run: |
set -euo pipefail
python -m pip install --upgrade pip pytest numpy
python -m pip install --require-hashes -r ordvec-python/requirements-dev.txt
python -m pip install ordvec-python/dist/*.tar.gz
python -m pytest ordvec-python/tests -q
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/zizmor.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,6 @@ jobs:
with:
python-version: "3.13"
- name: Install zizmor (pinned)
run: pip install zizmor==1.25.2
run: pip install --require-hashes -r .github/zizmor-requirements.txt
- name: Audit workflows
run: zizmor --offline --persona=regular .github/workflows/
19 changes: 19 additions & 0 deletions .github/zizmor-requirements.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Hash-pinned zizmor for the workflow-audit CI job (resolved for Python 3.13).
# Generated by: uv pip compile --generate-hashes --python-version 3.13.
# Installed via `pip install --require-hashes -r` (Scorecard Pinned-Dependencies).

# This file was autogenerated by uv via the following command:
# uv pip compile /tmp/ziz.in --generate-hashes --python-version 3.13 -o /tmp/ziz-req.txt
zizmor==1.25.2 \
--hash=sha256:0beba1601be08bd00c9277e6ed4b026e125b26b379d86d6d98eb708409b3050d \
--hash=sha256:17cc8cfd9d472e8b11945a869c198d25cfdf4a33f36fa7a1f9674099f5fb509d \
--hash=sha256:aa9f4c43b499c55339c3ef2e885133c5017cd9a18d76d9335541203cfa5ae1e7 \
--hash=sha256:af55bd9bd119ea8cbce2a7addc3922503019de32c1fe31106d70b3dc77d77908 \
--hash=sha256:b75c84d7387389f95edadbe859fb2aaf0a360c5b080932cc53e92ae1db6f09ef \
--hash=sha256:c4246f1344d8dbeffc044d7bb11b131773a7db7eb57d9073c45942dfd3543a1f \
--hash=sha256:cf64374149b567c9373228b76c8e77a389b4071899f84b82c36ee50fab894e79 \
--hash=sha256:d3e301eb4465e2da77857cf01ab4ef0184cf3818e826800b270ab01ae7338977 \
--hash=sha256:d670a1e2f00b3cd56febd145bc1a0b2c4caf1cbe5dad8128721843fa877e2d2e \
--hash=sha256:dbb1b5c85b8de8eaa0227c6620f06c8e4fbd0a4da2086e218bc225c0bef0923d \
--hash=sha256:f26ffeb16659c8922c7b08203ca5a4f8bf5e1a7e8d190734961c40877cf778ea
# via -r /tmp/ziz.in
Loading
Loading