Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 27 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
# Copyright the Hyperledger Fabric contributors. All rights reserved.
#
# SPDX-License-Identifier: Apache-2.0

version: 2

updates:
# Update the GitHub actions used in the workflows.
# This allows maintaining the pin by SHA + version comment.
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: weekly
groups:
github-actions:
group-by: dependency-name

# Update the pip dependencies declared in requirements.txt
# and requirements-dev.txt.
- package-ecosystem: "pip"
directories:
- "/"
schedule:
interval: weekly
groups:
pip-dependencies:
group-by: dependency-name
8 changes: 6 additions & 2 deletions .github/workflows/cleanup.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# Copyright the Hyperledger Fabric contributors. All rights reserved.
#
# SPDX-License-Identifier: Apache-2.0

name: Cleanup Old Workflow Runs

on:
Expand All @@ -22,7 +26,7 @@ jobs:

steps:
- name: Delete old workflow runs
uses: actions/github-script@v7
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
with:
script: |
const owner = context.repo.owner;
Expand Down Expand Up @@ -66,4 +70,4 @@ jobs:
}
}

console.log(`Deleted ${deletedCount} workflow runs, ${failedCount} failures`);
console.log(`Deleted ${deletedCount} workflow runs, ${failedCount} failures`);
10 changes: 7 additions & 3 deletions .github/workflows/pull_request.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# Copyright the Hyperledger Fabric contributors. All rights reserved.
#
# SPDX-License-Identifier: Apache-2.0

name: Pull request

on:
Expand All @@ -15,14 +19,14 @@ concurrency:

jobs:
test:
uses: ./.github/workflows/test.yaml
uses: ./.github/workflows/test.yml

scan:
uses: ./.github/workflows/scan.yml

pull-request:
needs: [test, scan]
needs: test
name: Pull request success
runs-on: ubuntu-latest
steps:
- run: "true"
- run: "true"
9 changes: 5 additions & 4 deletions .github/workflows/push.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# Copyright the Hyperledger Fabric contributors. All rights reserved.
#
# SPDX-License-Identifier: Apache-2.0

name: Push

on:
Expand All @@ -11,7 +15,4 @@ permissions:

jobs:
test:
uses: ./.github/workflows/test.yaml

scan:
uses: ./.github/workflows/scan.yml
uses: ./.github/workflows/test.yml
14 changes: 10 additions & 4 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# Copyright the Hyperledger Fabric contributors. All rights reserved.
#
# SPDX-License-Identifier: Apache-2.0

name: Release

# IMPORTANT: PyPI validates against the filename (release.yml),
Expand All @@ -23,12 +27,14 @@ jobs:
contents: read

steps:
- uses: actions/checkout@v4
# The hashes correspond to the most recent versions at the time of this
# analysis; update via Dependabot (see dependabot.yml).
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
fetch-depth: 0

- name: Set up Python
uses: actions/setup-python@v5
uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0
with:
python-version: '3.11'
cache: 'pip'
Expand All @@ -46,5 +52,5 @@ jobs:
# registered publisher. There are no secrets to rotate or leak.
- name: Publish to PyPI
if: startsWith(github.ref, 'refs/tags/')
uses: pypa/gh-action-pypi-publish@release/v1
# attestations: true # optional: generate PEP 740 attestations (supply chain)
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1
# attestations: true # optional: generate PEP 740 attestations (supply chain)
13 changes: 9 additions & 4 deletions .github/workflows/scan.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# Copyright the Hyperledger Fabric contributors. All rights reserved.
#
# SPDX-License-Identifier: Apache-2.0

name: "Security vulnerability scan"

on:
Expand All @@ -13,18 +17,19 @@ permissions:
contents: read

jobs:
scan:
pip-audit:
name: pip-audit
runs-on: ubuntu-latest
timeout-minutes: 15

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
ref: ${{ inputs.ref }}
fetch-depth: 0

- name: Set up Python
uses: actions/setup-python@v5
uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0
with:
python-version: '3.11'
cache: 'pip'
Expand All @@ -44,4 +49,4 @@ jobs:
run: pip-audit -r requirements.txt

- name: Audit installed environment
run: pip-audit
run: pip-audit
Original file line number Diff line number Diff line change
@@ -1,8 +1,12 @@
# Copyright the Hyperledger Fabric contributors. All rights reserved.
#
# SPDX-License-Identifier: Apache-2.0

name: "Scheduled vulnerability scan"

on:
schedule:
- cron: "27 3 * * *"
- cron: "20 3 * * *"
workflow_dispatch:

permissions:
Expand All @@ -27,9 +31,16 @@ jobs:
fi
echo "value=${tag}" >> "${GITHUB_OUTPUT}"

scan:
scan-release:
name: Scan ${{ needs.latest-release-version.outputs.tag_name }}
needs: latest-release-version
uses: ./.github/workflows/scan.yml
with:
ref: ${{ needs.latest-release-version.outputs.tag_name }}
ref: ${{ needs.latest-release-version.outputs.tag_name }}

# This job runs on the `main` branch and scans the `main` branch at the default branch's HEAD.
# Without it, vulnerabilities introduced in `main`
# but not yet released would go unnoticed until the next release.
scan-latest:
name: Scan latest
uses: ./.github/workflows/scan.yml
17 changes: 17 additions & 0 deletions .github/workflows/scheduled.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Copyright the Hyperledger Fabric contributors. All rights reserved.
#
# SPDX-License-Identifier: Apache-2.0

name: Scheduled build

on:
schedule:
- cron: "5 4 * * 0" # Sunday 04:05 UTC
workflow_dispatch:

permissions:
contents: read

jobs:
main:
uses: ./.github/workflows/test.yml
31 changes: 0 additions & 31 deletions .github/workflows/test.yaml

This file was deleted.

96 changes: 96 additions & 0 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
# Copyright the Hyperledger Fabric contributors. All rights reserved.
#
# SPDX-License-Identifier: Apache-2.0

name: Test

on:
workflow_call:
inputs:
ref:
description: Branch, tag or SHA to test.
type: string
required: false
default: ""

permissions:
contents: read

jobs:
test:
name: Unit test
runs-on: ubuntu-latest
timeout-minutes: 25
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
ref: ${{ inputs.ref }}
fetch-depth: 0
- name: Set up Python
uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0
with:
python-version: '3.11'
cache: 'pip'
- name: Install dependencies
run: |
python -m pip install --upgrade pip
python -m pip install -r requirements.txt -r requirements-dev.txt
- name: Run tests
run: python -m pytest -q

# TODO: If you have integration tests against a real Fabric peer,
# uncomment this job and adjust the paths. It is the equivalent of the
# `integrationtest` job in the Java workflow.
# integrationtest:
# name: Integration test
# runs-on: ubuntu-latest
# timeout-minutes: 45
# steps:
# - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
# with:
# ref: ${{ inputs.ref }}
# fetch-depth: 0
# - name: Set up Python
# uses: actions/setup-python@0b93645e9fea7318ecaed2b359559ac225c90a2b # v5.3.0
# with:
# python-version: '3.11'
# cache: 'pip'
# - name: Install dependencies
# run: |
# python -m pip install --upgrade pip
# python -m pip install -r requirements.txt -r requirements-dev.txt
# - name: Ensure that the Peer/weft tools are available
# run: |
# curl -sSL https://raw.githubusercontent.com/hyperledger/fabric/main/scripts/install-fabric.sh | bash -s -- binary
# npm install -g @hyperledger-labs/weft
# echo "FABRIC_CFG_PATH=$GITHUB_WORKSPACE/config" >> $GITHUB_ENV
# echo "$GITHUB_WORKSPACE/bin" >> $GITHUB_PATH
# - name: versions
# run: |
# peer version
# weft --version
# - name: Integration Tests
# run: python -m pytest -q integration_test/

# TODO: If you publish a base Docker image for Python chaincode,
# uncomment this job. It is the equivalent of the Java `docker` job.
# docker:
# name: Build Docker image
# runs-on: ubuntu-latest
# timeout-minutes: 30
# permissions:
# contents: read
# packages: write
# steps:
# - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
# with:
# ref: ${{ inputs.ref }}
# - name: Set up Docker Buildx
# uses: docker/setup-buildx-action@c7c853bb5d3c0d0de6c775bda84e8f9be9bed9339 # v3.10.0
# - name: Build image
# uses: docker/build-push-action@v6
# with:
# context: .
# file: ./Dockerfile
# push: false
# tags: fabric-pythonenv:latest
Loading