Skip to content

Commit c04afd6

Browse files
committed
Fix codeql warnings
1 parent b42bc76 commit c04afd6

5 files changed

Lines changed: 30 additions & 13 deletions

File tree

‎.github/workflows/build-release.yml‎

Lines changed: 11 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -52,16 +52,20 @@ jobs:
5252
- name: Checkout repository
5353
uses: actions/checkout@v6
5454

55+
- name: Set up pnpm
56+
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
57+
with:
58+
version: 11.1.2
59+
5560
- name: Set up Node.js
5661
uses: actions/setup-node@v6
5762
with:
58-
node-version: "22"
59-
cache: npm
60-
cache-dependency-path: frontend/package-lock.json
63+
node-version: "24"
64+
cache: pnpm
65+
cache-dependency-path: pnpm-lock.yaml
6166

6267
- name: Install frontend dependencies
63-
working-directory: frontend
64-
run: npm ci
68+
run: pnpm install --filter=@digestengine/frontend --frozen-lockfile
6569

6670
- name: Prepare frontend env
6771
working-directory: frontend
@@ -70,12 +74,11 @@ jobs:
7074
echo "NEXTAUTH_SECRET=ci-build-secret" >> .env.local
7175
7276
- name: Build frontend
73-
working-directory: frontend
7477
env:
7578
NEXT_PUBLIC_API_URL: http://localhost:8000
7679
NEXTAUTH_URL: http://localhost:3000
7780
NEXTAUTH_SECRET: ci-build-secret
78-
run: npm run build
81+
run: pnpm --filter=@digestengine/frontend run build
7982

8083
build-backend:
8184
name: Build and scan backend image
@@ -96,6 +99,7 @@ jobs:
9699
with:
97100
image-ref: digest-engine-ci:${{ github.sha }}
98101
scan-type: image
102+
scanners: vuln
99103
severity: HIGH,CRITICAL
100104
ignore-unfixed: true
101105
exit-code: "1"

‎.github/workflows/lint.yml‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
uses: actions/checkout@v6
2323

2424
- name: Set up uv
25-
uses: astral-sh/setup-uv@v5
25+
uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5
2626
with:
2727
version: "0.8.17"
2828
enable-cache: true
@@ -31,12 +31,17 @@ jobs:
3131
run: uv python install 3.13
3232

3333
- name: Initialize Pants
34-
uses: pantsbuild/actions/init-pants@v10
34+
uses: pantsbuild/actions/init-pants@ab362158088bb31685015e7f5728a4c1df3c0e6e # v10
3535
with:
3636
gha-cache-key: cache0-py313
3737
named-caches-hash: ${{ hashFiles('3rdparty/python/default.lock', 'pants.toml') }}
3838
pants-ci-config: ""
3939

40+
- name: Set up pnpm
41+
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
42+
with:
43+
version: 11.1.0
44+
4045
- name: Set up Node.js
4146
uses: actions/setup-node@v6
4247
with:

‎.github/workflows/test.yml‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ jobs:
2222
uses: actions/checkout@v6
2323

2424
- name: Set up uv
25-
uses: astral-sh/setup-uv@v5
25+
uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5
2626
with:
2727
version: "0.8.17"
2828
enable-cache: true
@@ -31,12 +31,17 @@ jobs:
3131
run: uv python install 3.13
3232

3333
- name: Initialize Pants
34-
uses: pantsbuild/actions/init-pants@v10
34+
uses: pantsbuild/actions/init-pants@ab362158088bb31685015e7f5728a4c1df3c0e6e # v10
3535
with:
3636
gha-cache-key: cache0-py313
3737
named-caches-hash: ${{ hashFiles('3rdparty/python/default.lock', 'pants.toml') }}
3838
pants-ci-config: ""
3939

40+
- name: Set up pnpm
41+
uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4
42+
with:
43+
version: 11.1.0
44+
4045
- name: Set up Node.js
4146
uses: actions/setup-node@v6
4247
with:

‎core/permissions.py‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,9 +13,11 @@
1313
class PermissionBase(permissions.BasePermission):
1414
"""Typed shim for DRF permissions whose default methods return bool."""
1515

16-
def has_permission(self, request, view) -> bool: ...
16+
def has_permission(self, request, view) -> bool:
17+
raise NotImplementedError()
1718

18-
def has_object_permission(self, request, view, obj) -> bool: ...
19+
def has_object_permission(self, request, view, obj) -> bool:
20+
raise NotImplementedError()
1921

2022
else:
2123
PermissionBase = permissions.BasePermission

‎docker/web/Dockerfile‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@ ARG UV_VERSION=0.8.17
99
WORKDIR /app
1010

1111
RUN apt-get update \
12+
&& apt-get upgrade --yes \
1213
&& apt-get install --yes --no-install-recommends build-essential curl libpq-dev \
1314
&& rm -rf /var/lib/apt/lists/*
1415

0 commit comments

Comments
 (0)