Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin hashes in requirements #7081

Merged
merged 20 commits into from
Apr 23, 2024
Merged

Conversation

matmair
Copy link
Contributor

@matmair matmair commented Apr 22, 2024

This PR introduces requirement hash pinning. This secures against supply chain attacks in which dependencies are replaced with malicious versions.
It also switches workflows over to use a requirement files.

@matmair matmair added CI CI / unit testing ecosystem security Relates to a security issue labels Apr 22, 2024
@matmair matmair self-assigned this Apr 22, 2024
Copy link

netlify bot commented Apr 22, 2024

Deploy Preview for inventree-web-pui-preview canceled.

Name Link
🔨 Latest commit bd30d62
🔍 Latest deploy log https://app.netlify.com/sites/inventree-web-pui-preview/deploys/66274a857fc3730008e51821

@matmair matmair marked this pull request as ready for review April 22, 2024 18:33
Copy link

codecov bot commented Apr 22, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 83.37%. Comparing base (3e52e5f) to head (bd30d62).

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #7081   +/-   ##
=======================================
  Coverage   83.37%   83.37%           
=======================================
  Files        1039     1039           
  Lines       45731    45731           
  Branches     1279     1279           
=======================================
  Hits        38129    38129           
  Misses       7329     7329           
  Partials      273      273           
Flag Coverage Δ
backend 85.46% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@SchrodingersGat
Copy link
Member

Why does each package get multiple hashes in the requirements file?

@matmair
Copy link
Contributor Author

matmair commented Apr 22, 2024

@SchrodingersGat it dependes on how many files/distributions are offered, this can be seen on Pypi itself too:https://pypi.org/project/certifi/#copy-hash-modal-205cb7d5-a79a-4f73-aeb7-f5c1c778db8c

@matmair
Copy link
Contributor Author

matmair commented Apr 22, 2024

Most packages nowaday release 2 files: a source tarball and a wheel (that is a pre-build distribution format)

@SchrodingersGat
Copy link
Member

Ok! Please fix the conflict and I'll merge straight away

@matmair
Copy link
Contributor Author

matmair commented Apr 23, 2024

@SchrodingersGat mergefix is in

@SchrodingersGat SchrodingersGat merged commit 938c724 into inventree:master Apr 23, 2024
27 checks passed
@SchrodingersGat SchrodingersGat deleted the ci-use-reqs-file branch April 23, 2024 07:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CI CI / unit testing ecosystem security Relates to a security issue
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants