Skip to content

ci: add uv audit workflow for automated vulnerability patching - #1105

Merged
MvLieshout merged 16 commits into
mainfrom
ci/uv-audit-workflow
Sep 28, 2026
Merged

MvLieshout merged 16 commits into
mainfrom
ci/uv-audit-workflow

Conversation

@MvLieshout

@MvLieshout MvLieshout commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

What does this PR do?

Adds a scheduled uv audit workflow so vulnerable dependencies with a known fix get patched automatically. It runs uv audit, extracts packages that have a fix_versions entry, upgrades them via uv lock --upgrade-package, and opens a PR with the resulting uv.lock diff (labeled security, dependencies, automated).

  • _job_uv_audit.yaml: reusable workflow_call job. Uses astral-sh/setup-uv and plain PyPI — no Artifactory or Alliander-specific actions.
  • uv-audit.yaml: daily scheduled trigger (06:00 UTC) + manual workflow_dispatch.

Closes #

Type of change

  • Bug fix
  • New feature
  • Breaking change (see checklist below)
  • Documentation
  • Refactor / chore / CI

Breaking changes checklist

N/A — CI-only change, no public API/config/serialized object impact.

Migration path for existing users (e.g. "old pickled XScaler objects auto-migrate on load", "users must now pass X explicitly"):

N/A

AI disclosure

  • No AI assistance was used (beyond grammar/spelling)
  • AI assistance was used — tool(s): GitHub Copilot
    • I have reviewed, understand, and can explain all AI-generated code in this PR
    • This is disclosed in a commit message (e.g. Assisted-by: <tool name>)

Checklist

  • poe all --check passes locally (not applicable — no Python source changed)
  • Tests added/updated for the change (not applicable — CI workflow only)
  • Documentation updated (docstrings, user guide, examples) if needed (not applicable)
  • Commits are signed off per our DCO (git commit -s)
  • PR title follows Conventional Commits

@MvLieshout
MvLieshout requested a review from a team September 28, 2026 07:56
@MvLieshout
MvLieshout force-pushed the ci/uv-audit-workflow branch 2 times, most recently from cfc145f to f811807 Compare September 28, 2026 07:59
MvLieshout and others added 15 commits September 28, 2026 13:07
Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…rsions group across 1 directory (#1104)

Bumps the python-versions group with 1 update in the / directory:
[holidays](https://github.com/vacanza/holidays).

Updates `holidays` from 0.104 to 0.105
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vacanza/holidays/releases">holidays's
releases</a>.</em></p>
<blockquote>
<h2>v0.105</h2>
<h2>Version 0.105</h2>
<p>Released September 21, 2026</p>
<ul>
<li>Refactor German School Holidays generator (<a
href="https://redirect.github.com/vacanza/holidays/issues/3808">#3808</a>
by <a
href="https://github.com/PPsyrius"><code>@​PPsyrius</code></a>)</li>
<li>Refactor imports in tests (<a
href="https://redirect.github.com/vacanza/holidays/issues/3819">#3819</a>
by <a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update Australia holidays: add school holidays support (<a
href="https://redirect.github.com/vacanza/holidays/issues/3821">#3821</a>
by <a href="https://github.com/gheydon"><code>@​gheydon</code></a>)</li>
<li>Update Canada holidays: remove Boxing Day from optional holidays in
QC (<a
href="https://redirect.github.com/vacanza/holidays/issues/3807">#3807</a>
by <a
href="https://github.com/arbazkhan971"><code>@​arbazkhan971</code></a>)</li>
<li>Update India holidays: subdiv holidays improvement (East, North-East
&amp; South regions - I) (<a
href="https://redirect.github.com/vacanza/holidays/issues/3784">#3784</a>
by <a
href="https://github.com/ankushhKapoor"><code>@​ankushhKapoor</code></a>,
<a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update Indonesia holidays: add 2027 special holidays (<a
href="https://redirect.github.com/vacanza/holidays/issues/3828">#3828</a>
by <a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update Malaysia holidays (<a
href="https://redirect.github.com/vacanza/holidays/issues/3814">#3814</a>
by <a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update Philippines holidays: add 2027 holidays (<a
href="https://redirect.github.com/vacanza/holidays/issues/3817">#3817</a>
by <a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update South Africa holidays: add Nov 4, 2026 holiday (<a
href="https://redirect.github.com/vacanza/holidays/issues/3809">#3809</a>
by <a
href="https://github.com/lispwarez"><code>@​lispwarez</code></a>)</li>
<li>Add support for special holidays inheritance from parent entity (<a
href="https://redirect.github.com/vacanza/holidays/issues/3830">#3830</a>
by <a href="https://github.com/KJhellico"><code>@​KJhellico</code></a>,
<a href="https://github.com/arkid15r"><code>@​arkid15r</code></a>)</li>
</ul>
<p><strong>New Contributors</strong>:</p>
<ul>
<li><a
href="https://github.com/arbazkhan971"><code>@​arbazkhan971</code></a>
made their first contribution in <a
href="https://redirect.github.com/vacanza/holidays/pull/3807">vacanza/holidays#3807</a></li>
<li><a href="https://github.com/gheydon"><code>@​gheydon</code></a> made
their first contribution in <a
href="https://redirect.github.com/vacanza/holidays/pull/3821">vacanza/holidays#3821</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/vacanza/holidays/compare/v0.104...v0.105">https://github.com/vacanza/holidays/compare/v0.104...v0.105</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vacanza/holidays/blob/dev/CHANGES.md">holidays's
changelog</a>.</em></p>
<blockquote>
<h2>Version 0.105</h2>
<p>Released September 21, 2026</p>
<ul>
<li>Refactor German School Holidays generator (<a
href="https://redirect.github.com/vacanza/holidays/issues/3808">#3808</a>
by <a
href="https://github.com/PPsyrius"><code>@​PPsyrius</code></a>)</li>
<li>Refactor imports in tests (<a
href="https://redirect.github.com/vacanza/holidays/issues/3819">#3819</a>
by <a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update Australia holidays: add school holidays support (<a
href="https://redirect.github.com/vacanza/holidays/issues/3821">#3821</a>
by <a href="https://github.com/gheydon"><code>@​gheydon</code></a>)</li>
<li>Update Canada holidays: remove Boxing Day from optional holidays in
QC (<a
href="https://redirect.github.com/vacanza/holidays/issues/3807">#3807</a>
by <a
href="https://github.com/arbazkhan971"><code>@​arbazkhan971</code></a>)</li>
<li>Update India holidays: subdiv holidays improvement (East, North-East
&amp; South regions - I) (<a
href="https://redirect.github.com/vacanza/holidays/issues/3784">#3784</a>
by <a
href="https://github.com/ankushhKapoor"><code>@​ankushhKapoor</code></a>,
<a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update Indonesia holidays: add 2027 special holidays (<a
href="https://redirect.github.com/vacanza/holidays/issues/3828">#3828</a>
by <a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update Malaysia holidays (<a
href="https://redirect.github.com/vacanza/holidays/issues/3814">#3814</a>
by <a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update Philippines holidays: add 2027 holidays (<a
href="https://redirect.github.com/vacanza/holidays/issues/3817">#3817</a>
by <a
href="https://github.com/KJhellico"><code>@​KJhellico</code></a>)</li>
<li>Update South Africa holidays: add Nov 4, 2026 holiday (<a
href="https://redirect.github.com/vacanza/holidays/issues/3809">#3809</a>
by <a
href="https://github.com/lispwarez"><code>@​lispwarez</code></a>)</li>
<li>Add support for special holidays inheritance from parent entity (<a
href="https://redirect.github.com/vacanza/holidays/issues/3830">#3830</a>
by <a href="https://github.com/KJhellico"><code>@​KJhellico</code></a>,
<a href="https://github.com/arkid15r"><code>@​arkid15r</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vacanza/holidays/commit/532c3cedf7a5af36fee4aadea80b8e59ab6e5bf3"><code>532c3ce</code></a>
Merge pull request <a
href="https://redirect.github.com/vacanza/holidays/issues/3833">#3833</a>
from vacanza/dev</li>
<li><a
href="https://github.com/vacanza/holidays/commit/4ca8b83c972bb3e7d98074fca03e2e9ac45bc34c"><code>4ca8b83</code></a>
Finalize v0.105</li>
<li><a
href="https://github.com/vacanza/holidays/commit/cc9c9bcbb43eee2b9da09b04ce904de3e2ef7578"><code>cc9c9bc</code></a>
Add support for special holidays inheritance from parent entity (<a
href="https://redirect.github.com/vacanza/holidays/issues/3830">#3830</a>)</li>
<li><a
href="https://github.com/vacanza/holidays/commit/636ac52250ad2736d8b7effa837054d7c5c73b34"><code>636ac52</code></a>
chore: Update snapshots (<a
href="https://redirect.github.com/vacanza/holidays/issues/3831">#3831</a>)</li>
<li><a
href="https://github.com/vacanza/holidays/commit/bd3114d4a8e6bda41f135503ddbf996fbd245b58"><code>bd3114d</code></a>
Update India holidays: subdiv holidays improvement (East, North-East
&amp; South ...</li>
<li><a
href="https://github.com/vacanza/holidays/commit/9490dfe5a531e7ec45166c9214ab5be7a130c58f"><code>9490dfe</code></a>
Update Indonesia holidays: add 2027 special holidays (<a
href="https://redirect.github.com/vacanza/holidays/issues/3828">#3828</a>)</li>
<li><a
href="https://github.com/vacanza/holidays/commit/ba5f6b9a47eedcb0dcba779518fc41feb2b499c5"><code>ba5f6b9</code></a>
Bump the version-updates group with 3 updates (<a
href="https://redirect.github.com/vacanza/holidays/issues/3824">#3824</a>)</li>
<li><a
href="https://github.com/vacanza/holidays/commit/a85303a9f6c5b51f628925e2c9f8c3170a425226"><code>a85303a</code></a>
Bump the version-updates group with 2 updates (<a
href="https://redirect.github.com/vacanza/holidays/issues/3825">#3825</a>)</li>
<li><a
href="https://github.com/vacanza/holidays/commit/899cfe4999f40748e6c020c4b04b60898b5293b1"><code>899cfe4</code></a>
Bump the version-updates group with 2 updates (<a
href="https://redirect.github.com/vacanza/holidays/issues/3826">#3826</a>)</li>
<li><a
href="https://github.com/vacanza/holidays/commit/efab764993dc67e9b7ea932ede5cbd3e275e8621"><code>efab764</code></a>
chore: Update snapshots (<a
href="https://redirect.github.com/vacanza/holidays/issues/3823">#3823</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vacanza/holidays/compare/v0.104...v0.105">compare
view</a></li>
</ul>
</details>
<br />

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=holidays&package-manager=uv&previous-version=0.104&new-version=0.105)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…check flag

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…with new PRs

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…abot-style)

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…er on push for branch testing

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…th mutually exclusive cpu/gpu extras

uv audit and uv lock both work directly from uv.lock/pyproject.toml without needing a synced venv.

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…ts in this repo

security/automated labels don't exist in OpenSTEF/openstef, causing gh pr create to fail.

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…/log files, capture uv lock output

uv lock prints progress to stderr, so uv_audit_upgrade.txt was ending up empty. Also uv_audit_report.json and uv_audit_upgrade.txt are transient working files and shouldn't be committed to the repo alongside uv.lock.

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
- /uv-audit rebase: regenerates the fix and replays any manual commits on top (git rebase --onto), matching @dependabot rebase semantics.
- /uv-audit recreate: discards manual edits and regenerates from scratch, matching @dependabot recreate semantics.

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
Verified via a real local test: 'github-actions[bot]' as an --author regex treats [bot] as a character class, matching zero commits. Switched to an exact email match instead.

Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
Assisted-by: GitHub Copilot
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…e 3 (#1108)

## What does this PR do?

Fixes `poe licensecheck --check` (and thus the `Quality Checks` CI job)
failing on `main` with exit code 3 ("No packages").

Root cause (verified by reading `licensecheck` 2026.0.8's source
directly):
- `licensecheck`'s CLI unconditionally resets `requirements_paths` back
to `["pyproject.toml"]` whenever `--requirements-paths` isn't passed
explicitly on the command line, silently discarding
`[tool.licensecheck].requirements_paths` set in `pyproject.toml`.
- Our root `pyproject.toml`'s only direct dependencies are our own
workspace packages, all of which are listed in `skip_dependencies`
(needed to avoid a crash on the editable `-e file://` entries `uv` emits
for them). With only `pyproject.toml` as the entry point, every
discovered top-level requirement gets filtered out by
`skip_dependencies` before its transitive (real, third-party)
dependencies are ever walked — so licensecheck resolves zero packages
and exits 3.

Fix: pass `--requirements-paths` explicitly in `poe_tasks.toml`,
including each workspace member's own `pyproject.toml` (their real,
non-internal dependencies), so licensecheck always has real packages to
walk regardless of this CLI quirk.

Also:
- Point `licensecheck-third-party`'s `--file` at
`THIRD_PARTY_NOTICES.md`, the actual tracked doc (the task was writing
to a different, untracked filename, `THIRD_PARTY_LICENSES.md`).
- Regenerate `THIRD_PARTY_NOTICES.md` with current, accurate data — it
was stale, last generated by `licensecheck` 2025.1.0 against
long-outdated package versions.

Verified locally: `poe licensecheck --check` now scans 55 packages and
exits 0; `poe reuse` and `poe format-pyproject --check` still pass.

Closes #

## Type of change

- [x] Bug fix
- [ ] New feature
- [ ] Breaking change (see checklist below)
- [ ] Documentation
- [ ] Refactor / chore / CI

## Breaking changes checklist

- [ ] Public API, config schema, or serialized/pickled objects changed
in a way that affects existing users

## AI disclosure

- [ ] No AI assistance was used (beyond grammar/spelling)
- [x] AI assistance was used — tool(s): GitHub Copilot
- [x] I have reviewed, understand, and can explain all AI-generated code
in this PR
- [x] This is disclosed in a commit message (e.g. `Assisted-by: <tool
name>`)

## Checklist

- [x] `poe all --check` passes locally (verified the affected tasks:
`licensecheck --check`, `reuse`, `format-pyproject --check`)
- [ ] Tests added/updated for the change
- [ ] Documentation updated (docstrings, user guide, examples) if needed
- [x] Commits are signed off per our DCO (`git commit -s`)
- [x] PR title follows Conventional Commits

Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
@sonarqubecloud

Copy link
Copy Markdown

@MvLieshout
MvLieshout merged commit 02743e5 into main Sep 28, 2026
6 checks passed
@MvLieshout
MvLieshout deleted the ci/uv-audit-workflow branch September 28, 2026 11:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants