chore(deps): update pypa/gh-action-pypi-publish digest to dc37677 - #363
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedReview was skipped as selected files did not have any reviewable changes. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: Your plan provides up to 8 included reviews per hour; 4 remain after this review. 📝 WalkthroughWalkthroughUpdated the pinned commit SHA for the PyPI publishing action in the CD workflow. The Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The change only retargets the pinned PyPI publishing action commit, with no evidenced configuration or behavior regression. It is ready to merge after normal workflow validation. 🚥 Pre-merge checks | ✅ 6✅ Passed checks (6 passed)
Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #363 +/- ##
=======================================
Coverage 90.00% 90.00%
=======================================
Files 211 211
Lines 12451 12451
Branches 3482 3482
=======================================
Hits 11206 11206
Misses 1242 1242
Partials 3 3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
676a24a to
8f64b4d
Compare
cc9f68d to
f9f6d24
Compare
3f74138 to
5b53809
Compare
99991d4 to
decb330
Compare
decb330 to
1579836
Compare
dec790e to
d434058
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/cd-pypi-cli.yml:
- Line 46: The Setup Bun action step (uses:
oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6) is incorrectly
attempting to use a non-existent `cache` input; change the step to pass the
correct input by adding `with: no-cache: true` to the "Setup Bun" step so Bun
caching is disabled (use the `no-cache` input rather than `cache`).
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: a23aa126-1262-4adf-8a61-1c8e4f17c8f1
📒 Files selected for processing (1)
.github/workflows/cd-pypi-cli.yml
There was a problem hiding this comment.
Caution
Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/cd-pypi-cli.yml:
- Line 46: The Setup Bun action step (uses:
oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6) is incorrectly
attempting to use a non-existent `cache` input; change the step to pass the
correct input by adding `with: no-cache: true` to the "Setup Bun" step so Bun
caching is disabled (use the `no-cache` input rather than `cache`).
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: a23aa126-1262-4adf-8a61-1c8e4f17c8f1
📒 Files selected for processing (1)
.github/workflows/cd-pypi-cli.yml
🛑 Comments failed to post (1)
.github/workflows/cd-pypi-cli.yml (1)
46-46:
⚠️ Potential issue | 🟠 Major | ⚡ Quick win🧩 Analysis chain
🏁 Script executed:
#!/bin/bash # Verify setup-bun supports cache input and its default in the pinned commit. set -euo pipefail curl -fsSL https://raw.githubusercontent.com/oven-sh/setup-bun/0c5077e51419868618aeaa5fe8019c62421857d6/action.yml \ | sed -n '1,220p' # Find all setup-bun uses and whether cache is explicitly configured. rg -n -C3 'uses:\s*oven-sh/setup-bun@' .github/workflowsRepository: deepnote/deepnote
Length of output: 3070
Disable Bun caching at Line 46 using
no-cache(notcache)
oven-sh/setup-bun@...(pinned v2) exposesno-cache(default:false); there is nocacheinput. Setwith: no-cache: trueon theSetup Bunstep.Suggested fix
- name: Setup Bun uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 with: no-cache: true🧰 Tools
🪛 zizmor (1.25.2)
[error] 46-46: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/cd-pypi-cli.yml at line 46, The Setup Bun action step (uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6) is incorrectly attempting to use a non-existent `cache` input; change the step to pass the correct input by adding `with: no-cache: true` to the "Setup Bun" step so Bun caching is disabled (use the `no-cache` input rather than `cache`).
d434058 to
ca71123
Compare
440b998 to
b78b457
Compare
8576a30 to
cc47d4b
Compare
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
cc47d4b to
e4dd168
Compare
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
e4dd168 to
7dcf2ab
Compare
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
be8333c to
e51ca79
Compare
abeda3a to
800583a
Compare
This PR contains the following updates:
ed0c539→dc37677Configuration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.