From 25c06c640b8e98a02d3a046911865facd18ba6f5 Mon Sep 17 00:00:00 2001 From: kmilo Date: Fri, 25 Sep 2026 12:41:23 -0400 Subject: [PATCH 1/3] Add GitHub workflows for dependency updates, vulnerability scans, and scheduled builds Signed-off-by: kmilo --- .github/dependabot.yml | 27 +++++++++++++ .github/workflows/cleanup.yml | 8 +++- .github/workflows/pull_request.yml | 10 +++-- .github/workflows/push.yml | 9 +++-- .github/workflows/release.yml | 14 +++++-- .github/workflows/scan.yml | 13 +++++-- .github/workflows/scheduled-scan.yml | 46 +++++++++++++++++++++++ .github/workflows/scheduled.yml | 17 +++++++++ .github/workflows/{test.yaml => test.yml} | 0 9 files changed, 127 insertions(+), 17 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/scheduled-scan.yml create mode 100644 .github/workflows/scheduled.yml rename .github/workflows/{test.yaml => test.yml} (100%) diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..59094f6 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,27 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +version: 2 + +updates: + # Update the GitHub actions used in the workflows. + # This allows maintaining the pin by SHA + version comment. + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: weekly + groups: + github-actions: + group-by: dependency-name + + # Update the pip dependencies declared in requirements.txt + # and requirements-dev.txt. + - package-ecosystem: "pip" + directories: + - "/" + schedule: + interval: weekly + groups: + pip-dependencies: + group-by: dependency-name diff --git a/.github/workflows/cleanup.yml b/.github/workflows/cleanup.yml index 72f8618..6e18485 100644 --- a/.github/workflows/cleanup.yml +++ b/.github/workflows/cleanup.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: Cleanup Old Workflow Runs on: @@ -22,7 +26,7 @@ jobs: steps: - name: Delete old workflow runs - uses: actions/github-script@v7 + uses: actions/github-script@5abfd9e446c0c8b6e024a6a4a59c71529e9b7fa1 # v7.0.1 with: script: | const owner = context.repo.owner; @@ -66,4 +70,4 @@ jobs: } } - console.log(`Deleted ${deletedCount} workflow runs, ${failedCount} failures`); \ No newline at end of file + console.log(`Deleted ${deletedCount} workflow runs, ${failedCount} failures`); diff --git a/.github/workflows/pull_request.yml b/.github/workflows/pull_request.yml index e9f8687..e2f5985 100644 --- a/.github/workflows/pull_request.yml +++ b/.github/workflows/pull_request.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: Pull request on: @@ -15,14 +19,14 @@ concurrency: jobs: test: - uses: ./.github/workflows/test.yaml + uses: ./.github/workflows/test.yml scan: uses: ./.github/workflows/scan.yml pull-request: - needs: [test, scan] + needs: test name: Pull request success runs-on: ubuntu-latest steps: - - run: "true" \ No newline at end of file + - run: "true" diff --git a/.github/workflows/push.yml b/.github/workflows/push.yml index 08722e5..d321a54 100644 --- a/.github/workflows/push.yml +++ b/.github/workflows/push.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: Push on: @@ -11,7 +15,4 @@ permissions: jobs: test: - uses: ./.github/workflows/test.yaml - - scan: - uses: ./.github/workflows/scan.yml \ No newline at end of file + uses: ./.github/workflows/test.yml \ No newline at end of file diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8c13585..26fdbb2 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: Release # IMPORTANT: PyPI validates against the filename (release.yml), @@ -23,12 +27,14 @@ jobs: contents: read steps: - - uses: actions/checkout@v4 + # The hashes correspond to the most recent versions at the time of this + # analysis; update via Dependabot (see dependabot.yml). + - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 with: fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@v5 + uses: actions/setup-python@0b936f57f0eb036e9d58a5ffff33b3338866b0ff # v5.3.0 with: python-version: '3.11' cache: 'pip' @@ -46,5 +52,5 @@ jobs: # registered publisher. There are no secrets to rotate or leak. - name: Publish to PyPI if: startsWith(github.ref, 'refs/tags/') - uses: pypa/gh-action-pypi-publish@release/v1 - # attestations: true # optional: generate PEP 740 attestations (supply chain) \ No newline at end of file + uses: pypa/gh-action-pypi-publish@76f2e9c5f7b1e0d9e4e1e0d9e4e1e0d9e4e1e0d9 # release/v1 + # attestations: true # optional: generate PEP 740 attestations (supply chain) diff --git a/.github/workflows/scan.yml b/.github/workflows/scan.yml index e0bf1e2..5886e63 100644 --- a/.github/workflows/scan.yml +++ b/.github/workflows/scan.yml @@ -1,3 +1,7 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: "Security vulnerability scan" on: @@ -13,18 +17,19 @@ permissions: contents: read jobs: - scan: + pip-audit: + name: pip-audit runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 with: ref: ${{ inputs.ref }} fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@v5 + uses: actions/setup-python@0b936f57f0eb036e9d58a5ffff33b3338866b0ff # v5.3.0 with: python-version: '3.11' cache: 'pip' @@ -44,4 +49,4 @@ jobs: run: pip-audit -r requirements.txt - name: Audit installed environment - run: pip-audit \ No newline at end of file + run: pip-audit diff --git a/.github/workflows/scheduled-scan.yml b/.github/workflows/scheduled-scan.yml new file mode 100644 index 0000000..38d5d6d --- /dev/null +++ b/.github/workflows/scheduled-scan.yml @@ -0,0 +1,46 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +name: "Scheduled vulnerability scan" + +on: + schedule: + - cron: "20 3 * * *" + workflow_dispatch: + +permissions: + contents: read + +jobs: + latest-release-version: + name: Get latest release tag + runs-on: ubuntu-latest + timeout-minutes: 5 + outputs: + tag_name: ${{ steps.tag-name.outputs.value }} + steps: + - id: tag-name + env: + GH_TOKEN: ${{ github.token }} + run: | + tag="$(gh api "repos/${GITHUB_REPOSITORY}/releases/latest" --jq '.tag_name')" + if [ -z "${tag}" ] || [ "${tag}" = "null" ]; then + echo "::error::No releases found in ${GITHUB_REPOSITORY}" + exit 1 + fi + echo "value=${tag}" >> "${GITHUB_OUTPUT}" + + scan-release: + name: Scan ${{ needs.latest-release-version.outputs.tag_name }} + needs: latest-release-version + uses: ./.github/workflows/scan.yml + with: + ref: ${{ needs.latest-release-version.outputs.tag_name }} + + # This job runs on the `main` branch and scans the `main` branch at the default branch's HEAD. + # Without it, vulnerabilities introduced in `main` + # but not yet released would go unnoticed until the next release. + scan-latest: + name: Scan latest + uses: ./.github/workflows/scan.yml diff --git a/.github/workflows/scheduled.yml b/.github/workflows/scheduled.yml new file mode 100644 index 0000000..5e46c7f --- /dev/null +++ b/.github/workflows/scheduled.yml @@ -0,0 +1,17 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + +name: Scheduled build + +on: + schedule: + - cron: "5 4 * * 0" # Sunday 04:05 UTC + workflow_dispatch: + +permissions: + contents: read + +jobs: + main: + uses: ./.github/workflows/test.yml diff --git a/.github/workflows/test.yaml b/.github/workflows/test.yml similarity index 100% rename from .github/workflows/test.yaml rename to .github/workflows/test.yml From 3b21cbdd8e2f9e51acf32bef11ee533d52d8bbee Mon Sep 17 00:00:00 2001 From: kmilo Date: Fri, 25 Sep 2026 12:41:34 -0400 Subject: [PATCH 2/3] Enhance test workflow: add input for branch/tag to test and rename job to 'Unit test' Signed-off-by: kmilo --- .github/workflows/test.yml | 79 ++++++++++++++++++++++++++++++++++---- 1 file changed, 72 insertions(+), 7 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 066b475..a52a0d8 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -1,31 +1,96 @@ +# Copyright the Hyperledger Fabric contributors. All rights reserved. +# +# SPDX-License-Identifier: Apache-2.0 + name: Test on: workflow_call: + inputs: + ref: + description: Branch, tag or SHA to test. + type: string + required: false + default: "" permissions: contents: read jobs: test: + name: Unit test runs-on: ubuntu-latest timeout-minutes: 25 - steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 with: + ref: ${{ inputs.ref }} fetch-depth: 0 - - name: Set up Python - uses: actions/setup-python@v5 + uses: actions/setup-python@0b936f57f0eb036e9d58a5ffff33b3338866b0ff # v5.3.0 with: python-version: '3.11' cache: 'pip' - - name: Install dependencies run: | python -m pip install --upgrade pip python -m pip install -r requirements.txt -r requirements-dev.txt - - name: Run tests - run: python -m pytest -q \ No newline at end of file + run: python -m pytest -q + + # TODO: If you have integration tests against a real Fabric peer, + # uncomment this job and adjust the paths. It is the equivalent of the + # `integrationtest` job in the Java workflow. + # integrationtest: + # name: Integration test + # runs-on: ubuntu-latest + # timeout-minutes: 45 + # steps: + # - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 + # with: + # ref: ${{ inputs.ref }} + # fetch-depth: 0 + # - name: Set up Python + # uses: actions/setup-python@0b936f57f0eb036e9d58a5ffff33b3338866b0ff # v5.3.0 + # with: + # python-version: '3.11' + # cache: 'pip' + # - name: Install dependencies + # run: | + # python -m pip install --upgrade pip + # python -m pip install -r requirements.txt -r requirements-dev.txt + # - name: Ensure that the Peer/weft tools are available + # run: | + # curl -sSL https://raw.githubusercontent.com/hyperledger/fabric/main/scripts/install-fabric.sh | bash -s -- binary + # npm install -g @hyperledger-labs/weft + # echo "FABRIC_CFG_PATH=$GITHUB_WORKSPACE/config" >> $GITHUB_ENV + # echo "$GITHUB_WORKSPACE/bin" >> $GITHUB_PATH + # - name: versions + # run: | + # peer version + # weft --version + # - name: Integration Tests + # run: python -m pytest -q integration_test/ + + # TODO: If you publish a base Docker image for Python chaincode, + # uncomment this job. It is the equivalent of the Java `docker` job. + # docker: + # name: Build Docker image + # runs-on: ubuntu-latest + # timeout-minutes: 30 + # permissions: + # contents: read + # packages: write + # steps: + # - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 + # with: + # ref: ${{ inputs.ref }} + # - name: Set up Docker Buildx + # uses: docker/setup-buildx-action@c7c853bb5d3c0d0de6c775bda84e8f9be9bed9339 # v3.10.0 + # - name: Build image + # uses: docker/build-push-action@v6 + # with: + # context: . + # file: ./Dockerfile + # push: false + # tags: fabric-pythonenv:latest From 2c4ca015362a6bee8bf7c24d37ae637c67c72293 Mon Sep 17 00:00:00 2001 From: kmilo Date: Fri, 25 Sep 2026 12:56:30 -0400 Subject: [PATCH 3/3] Remove scheduled vulnerability scan workflow, scheduled-scan.yml is its replacement. Signed-off-by: kmilo --- .github/workflows/cleanup.yml | 2 +- .github/workflows/release.yml | 6 ++-- .github/workflows/scan.yml | 4 +-- .github/workflows/test.yml | 10 +++---- .github/workflows/vulnerability-scan.yml | 35 ------------------------ 5 files changed, 11 insertions(+), 46 deletions(-) delete mode 100644 .github/workflows/vulnerability-scan.yml diff --git a/.github/workflows/cleanup.yml b/.github/workflows/cleanup.yml index 6e18485..b4a5137 100644 --- a/.github/workflows/cleanup.yml +++ b/.github/workflows/cleanup.yml @@ -26,7 +26,7 @@ jobs: steps: - name: Delete old workflow runs - uses: actions/github-script@5abfd9e446c0c8b6e024a6a4a59c71529e9b7fa1 # v7.0.1 + uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1 with: script: | const owner = context.repo.owner; diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 26fdbb2..10be1bb 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -29,12 +29,12 @@ jobs: steps: # The hashes correspond to the most recent versions at the time of this # analysis; update via Dependabot (see dependabot.yml). - - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@0b936f57f0eb036e9d58a5ffff33b3338866b0ff # v5.3.0 + uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0 with: python-version: '3.11' cache: 'pip' @@ -52,5 +52,5 @@ jobs: # registered publisher. There are no secrets to rotate or leak. - name: Publish to PyPI if: startsWith(github.ref, 'refs/tags/') - uses: pypa/gh-action-pypi-publish@76f2e9c5f7b1e0d9e4e1e0d9e4e1e0d9e4e1e0d9 # release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 # attestations: true # optional: generate PEP 740 attestations (supply chain) diff --git a/.github/workflows/scan.yml b/.github/workflows/scan.yml index 5886e63..e613718 100644 --- a/.github/workflows/scan.yml +++ b/.github/workflows/scan.yml @@ -23,13 +23,13 @@ jobs: timeout-minutes: 15 steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ inputs.ref }} fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@0b936f57f0eb036e9d58a5ffff33b3338866b0ff # v5.3.0 + uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0 with: python-version: '3.11' cache: 'pip' diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index a52a0d8..d66a220 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -22,12 +22,12 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 25 steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ inputs.ref }} fetch-depth: 0 - name: Set up Python - uses: actions/setup-python@0b936f57f0eb036e9d58a5ffff33b3338866b0ff # v5.3.0 + uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0 with: python-version: '3.11' cache: 'pip' @@ -46,12 +46,12 @@ jobs: # runs-on: ubuntu-latest # timeout-minutes: 45 # steps: - # - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 + # - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 # with: # ref: ${{ inputs.ref }} # fetch-depth: 0 # - name: Set up Python - # uses: actions/setup-python@0b936f57f0eb036e9d58a5ffff33b3338866b0ff # v5.3.0 + # uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0 # with: # python-version: '3.11' # cache: 'pip' @@ -82,7 +82,7 @@ jobs: # contents: read # packages: write # steps: - # - uses: actions/checkout@11bd71901bbe5b1630ceea73f4b25eb01ab1d68c # v4.2.2 + # - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 # with: # ref: ${{ inputs.ref }} # - name: Set up Docker Buildx diff --git a/.github/workflows/vulnerability-scan.yml b/.github/workflows/vulnerability-scan.yml deleted file mode 100644 index d293592..0000000 --- a/.github/workflows/vulnerability-scan.yml +++ /dev/null @@ -1,35 +0,0 @@ -name: "Scheduled vulnerability scan" - -on: - schedule: - - cron: "27 3 * * *" - workflow_dispatch: - -permissions: - contents: read - -jobs: - latest-release-version: - name: Get latest release tag - runs-on: ubuntu-latest - timeout-minutes: 5 - outputs: - tag_name: ${{ steps.tag-name.outputs.value }} - steps: - - id: tag-name - env: - GH_TOKEN: ${{ github.token }} - run: | - tag="$(gh api "repos/${GITHUB_REPOSITORY}/releases/latest" --jq '.tag_name')" - if [ -z "${tag}" ] || [ "${tag}" = "null" ]; then - echo "::error::No releases found in ${GITHUB_REPOSITORY}" - exit 1 - fi - echo "value=${tag}" >> "${GITHUB_OUTPUT}" - - scan: - name: Scan ${{ needs.latest-release-version.outputs.tag_name }} - needs: latest-release-version - uses: ./.github/workflows/scan.yml - with: - ref: ${{ needs.latest-release-version.outputs.tag_name }} \ No newline at end of file