ci: add uv audit workflow for automated vulnerability patching - #1105
Merged
Merged
Conversation
MvLieshout
force-pushed
the
ci/uv-audit-workflow
branch
2 times, most recently
from
September 28, 2026 07:59
cfc145f to
f811807
Compare
Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…rsions group across 1 directory (#1104) Bumps the python-versions group with 1 update in the / directory: [holidays](https://github.com/vacanza/holidays). Updates `holidays` from 0.104 to 0.105 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vacanza/holidays/releases">holidays's releases</a>.</em></p> <blockquote> <h2>v0.105</h2> <h2>Version 0.105</h2> <p>Released September 21, 2026</p> <ul> <li>Refactor German School Holidays generator (<a href="https://redirect.github.com/vacanza/holidays/issues/3808">#3808</a> by <a href="https://github.com/PPsyrius"><code>@PPsyrius</code></a>)</li> <li>Refactor imports in tests (<a href="https://redirect.github.com/vacanza/holidays/issues/3819">#3819</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update Australia holidays: add school holidays support (<a href="https://redirect.github.com/vacanza/holidays/issues/3821">#3821</a> by <a href="https://github.com/gheydon"><code>@gheydon</code></a>)</li> <li>Update Canada holidays: remove Boxing Day from optional holidays in QC (<a href="https://redirect.github.com/vacanza/holidays/issues/3807">#3807</a> by <a href="https://github.com/arbazkhan971"><code>@arbazkhan971</code></a>)</li> <li>Update India holidays: subdiv holidays improvement (East, North-East & South regions - I) (<a href="https://redirect.github.com/vacanza/holidays/issues/3784">#3784</a> by <a href="https://github.com/ankushhKapoor"><code>@ankushhKapoor</code></a>, <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update Indonesia holidays: add 2027 special holidays (<a href="https://redirect.github.com/vacanza/holidays/issues/3828">#3828</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update Malaysia holidays (<a href="https://redirect.github.com/vacanza/holidays/issues/3814">#3814</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update Philippines holidays: add 2027 holidays (<a href="https://redirect.github.com/vacanza/holidays/issues/3817">#3817</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update South Africa holidays: add Nov 4, 2026 holiday (<a href="https://redirect.github.com/vacanza/holidays/issues/3809">#3809</a> by <a href="https://github.com/lispwarez"><code>@lispwarez</code></a>)</li> <li>Add support for special holidays inheritance from parent entity (<a href="https://redirect.github.com/vacanza/holidays/issues/3830">#3830</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>, <a href="https://github.com/arkid15r"><code>@arkid15r</code></a>)</li> </ul> <p><strong>New Contributors</strong>:</p> <ul> <li><a href="https://github.com/arbazkhan971"><code>@arbazkhan971</code></a> made their first contribution in <a href="https://redirect.github.com/vacanza/holidays/pull/3807">vacanza/holidays#3807</a></li> <li><a href="https://github.com/gheydon"><code>@gheydon</code></a> made their first contribution in <a href="https://redirect.github.com/vacanza/holidays/pull/3821">vacanza/holidays#3821</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/vacanza/holidays/compare/v0.104...v0.105">https://github.com/vacanza/holidays/compare/v0.104...v0.105</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/vacanza/holidays/blob/dev/CHANGES.md">holidays's changelog</a>.</em></p> <blockquote> <h2>Version 0.105</h2> <p>Released September 21, 2026</p> <ul> <li>Refactor German School Holidays generator (<a href="https://redirect.github.com/vacanza/holidays/issues/3808">#3808</a> by <a href="https://github.com/PPsyrius"><code>@PPsyrius</code></a>)</li> <li>Refactor imports in tests (<a href="https://redirect.github.com/vacanza/holidays/issues/3819">#3819</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update Australia holidays: add school holidays support (<a href="https://redirect.github.com/vacanza/holidays/issues/3821">#3821</a> by <a href="https://github.com/gheydon"><code>@gheydon</code></a>)</li> <li>Update Canada holidays: remove Boxing Day from optional holidays in QC (<a href="https://redirect.github.com/vacanza/holidays/issues/3807">#3807</a> by <a href="https://github.com/arbazkhan971"><code>@arbazkhan971</code></a>)</li> <li>Update India holidays: subdiv holidays improvement (East, North-East & South regions - I) (<a href="https://redirect.github.com/vacanza/holidays/issues/3784">#3784</a> by <a href="https://github.com/ankushhKapoor"><code>@ankushhKapoor</code></a>, <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update Indonesia holidays: add 2027 special holidays (<a href="https://redirect.github.com/vacanza/holidays/issues/3828">#3828</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update Malaysia holidays (<a href="https://redirect.github.com/vacanza/holidays/issues/3814">#3814</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update Philippines holidays: add 2027 holidays (<a href="https://redirect.github.com/vacanza/holidays/issues/3817">#3817</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>)</li> <li>Update South Africa holidays: add Nov 4, 2026 holiday (<a href="https://redirect.github.com/vacanza/holidays/issues/3809">#3809</a> by <a href="https://github.com/lispwarez"><code>@lispwarez</code></a>)</li> <li>Add support for special holidays inheritance from parent entity (<a href="https://redirect.github.com/vacanza/holidays/issues/3830">#3830</a> by <a href="https://github.com/KJhellico"><code>@KJhellico</code></a>, <a href="https://github.com/arkid15r"><code>@arkid15r</code></a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vacanza/holidays/commit/532c3cedf7a5af36fee4aadea80b8e59ab6e5bf3"><code>532c3ce</code></a> Merge pull request <a href="https://redirect.github.com/vacanza/holidays/issues/3833">#3833</a> from vacanza/dev</li> <li><a href="https://github.com/vacanza/holidays/commit/4ca8b83c972bb3e7d98074fca03e2e9ac45bc34c"><code>4ca8b83</code></a> Finalize v0.105</li> <li><a href="https://github.com/vacanza/holidays/commit/cc9c9bcbb43eee2b9da09b04ce904de3e2ef7578"><code>cc9c9bc</code></a> Add support for special holidays inheritance from parent entity (<a href="https://redirect.github.com/vacanza/holidays/issues/3830">#3830</a>)</li> <li><a href="https://github.com/vacanza/holidays/commit/636ac52250ad2736d8b7effa837054d7c5c73b34"><code>636ac52</code></a> chore: Update snapshots (<a href="https://redirect.github.com/vacanza/holidays/issues/3831">#3831</a>)</li> <li><a href="https://github.com/vacanza/holidays/commit/bd3114d4a8e6bda41f135503ddbf996fbd245b58"><code>bd3114d</code></a> Update India holidays: subdiv holidays improvement (East, North-East & South ...</li> <li><a href="https://github.com/vacanza/holidays/commit/9490dfe5a531e7ec45166c9214ab5be7a130c58f"><code>9490dfe</code></a> Update Indonesia holidays: add 2027 special holidays (<a href="https://redirect.github.com/vacanza/holidays/issues/3828">#3828</a>)</li> <li><a href="https://github.com/vacanza/holidays/commit/ba5f6b9a47eedcb0dcba779518fc41feb2b499c5"><code>ba5f6b9</code></a> Bump the version-updates group with 3 updates (<a href="https://redirect.github.com/vacanza/holidays/issues/3824">#3824</a>)</li> <li><a href="https://github.com/vacanza/holidays/commit/a85303a9f6c5b51f628925e2c9f8c3170a425226"><code>a85303a</code></a> Bump the version-updates group with 2 updates (<a href="https://redirect.github.com/vacanza/holidays/issues/3825">#3825</a>)</li> <li><a href="https://github.com/vacanza/holidays/commit/899cfe4999f40748e6c020c4b04b60898b5293b1"><code>899cfe4</code></a> Bump the version-updates group with 2 updates (<a href="https://redirect.github.com/vacanza/holidays/issues/3826">#3826</a>)</li> <li><a href="https://github.com/vacanza/holidays/commit/efab764993dc67e9b7ea932ede5cbd3e275e8621"><code>efab764</code></a> chore: Update snapshots (<a href="https://redirect.github.com/vacanza/holidays/issues/3823">#3823</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vacanza/holidays/compare/v0.104...v0.105">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…check flag Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…with new PRs Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…abot-style) Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…er on push for branch testing Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…th mutually exclusive cpu/gpu extras uv audit and uv lock both work directly from uv.lock/pyproject.toml without needing a synced venv. Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…ts in this repo security/automated labels don't exist in OpenSTEF/openstef, causing gh pr create to fail. Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…/log files, capture uv lock output uv lock prints progress to stderr, so uv_audit_upgrade.txt was ending up empty. Also uv_audit_report.json and uv_audit_upgrade.txt are transient working files and shouldn't be committed to the repo alongside uv.lock. Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
- /uv-audit rebase: regenerates the fix and replays any manual commits on top (git rebase --onto), matching @dependabot rebase semantics. - /uv-audit recreate: discards manual edits and regenerates from scratch, matching @dependabot recreate semantics. Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
Verified via a real local test: 'github-actions[bot]' as an --author regex treats [bot] as a character class, matching zero commits. Switched to an exact email match instead. Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
Assisted-by: GitHub Copilot Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
…e 3 (#1108) ## What does this PR do? Fixes `poe licensecheck --check` (and thus the `Quality Checks` CI job) failing on `main` with exit code 3 ("No packages"). Root cause (verified by reading `licensecheck` 2026.0.8's source directly): - `licensecheck`'s CLI unconditionally resets `requirements_paths` back to `["pyproject.toml"]` whenever `--requirements-paths` isn't passed explicitly on the command line, silently discarding `[tool.licensecheck].requirements_paths` set in `pyproject.toml`. - Our root `pyproject.toml`'s only direct dependencies are our own workspace packages, all of which are listed in `skip_dependencies` (needed to avoid a crash on the editable `-e file://` entries `uv` emits for them). With only `pyproject.toml` as the entry point, every discovered top-level requirement gets filtered out by `skip_dependencies` before its transitive (real, third-party) dependencies are ever walked — so licensecheck resolves zero packages and exits 3. Fix: pass `--requirements-paths` explicitly in `poe_tasks.toml`, including each workspace member's own `pyproject.toml` (their real, non-internal dependencies), so licensecheck always has real packages to walk regardless of this CLI quirk. Also: - Point `licensecheck-third-party`'s `--file` at `THIRD_PARTY_NOTICES.md`, the actual tracked doc (the task was writing to a different, untracked filename, `THIRD_PARTY_LICENSES.md`). - Regenerate `THIRD_PARTY_NOTICES.md` with current, accurate data — it was stale, last generated by `licensecheck` 2025.1.0 against long-outdated package versions. Verified locally: `poe licensecheck --check` now scans 55 packages and exits 0; `poe reuse` and `poe format-pyproject --check` still pass. Closes # ## Type of change - [x] Bug fix - [ ] New feature - [ ] Breaking change (see checklist below) - [ ] Documentation - [ ] Refactor / chore / CI ## Breaking changes checklist - [ ] Public API, config schema, or serialized/pickled objects changed in a way that affects existing users ## AI disclosure - [ ] No AI assistance was used (beyond grammar/spelling) - [x] AI assistance was used — tool(s): GitHub Copilot - [x] I have reviewed, understand, and can explain all AI-generated code in this PR - [x] This is disclosed in a commit message (e.g. `Assisted-by: <tool name>`) ## Checklist - [x] `poe all --check` passes locally (verified the affected tasks: `licensecheck --check`, `reuse`, `format-pyproject --check`) - [ ] Tests added/updated for the change - [ ] Documentation updated (docstrings, user guide, examples) if needed - [x] Commits are signed off per our DCO (`git commit -s`) - [x] PR title follows Conventional Commits Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
MvLieshout
force-pushed
the
ci/uv-audit-workflow
branch
from
September 28, 2026 11:07
58ddbb3 to
1a6bbaf
Compare
|
egordm
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What does this PR do?
Adds a scheduled
uv auditworkflow so vulnerable dependencies with a known fix get patched automatically. It runsuv audit, extracts packages that have afix_versionsentry, upgrades them viauv lock --upgrade-package, and opens a PR with the resultinguv.lockdiff (labeledsecurity,dependencies,automated)._job_uv_audit.yaml: reusableworkflow_calljob. Usesastral-sh/setup-uvand plain PyPI — no Artifactory or Alliander-specific actions.uv-audit.yaml: daily scheduled trigger (06:00 UTC) + manualworkflow_dispatch.Closes #
Type of change
Breaking changes checklist
N/A — CI-only change, no public API/config/serialized object impact.
Migration path for existing users (e.g. "old pickled
XScalerobjects auto-migrate on load", "users must now passXexplicitly"):N/A
AI disclosure
Assisted-by: <tool name>)Checklist
poe all --checkpasses locally (not applicable — no Python source changed)git commit -s)