Conversation
Each workflow can and should set their permissions on the GITHUB_TOKEN as necessary.
pedro-psb
left a comment
There was a problem hiding this comment.
What do you think of adding the cool-off period, since uvx are unconstrained calls?
Something like the following for a job:
- name: Set UV cool-off period
run: |
COOL_OFF_DATE=$(date -d "2 weeks ago" +%Y-%m-%d)
echo "UV_EXCLUDE_NEWER=$COOL_OFF_DATE" >> $GITHUB_ENV
I'm not so sure what exact problem that will solve. I think we can however add development dependencies to pyproject.toml and change all "uvx" calls to "uv run". This way we can use version specifiers. |
|
These tools run in jobs with priviledged access. This reduces the chance of us getting a compromised package right after it's released. But yeah, specifying explicitly in pyproject.toml sounds an improvement (in this case, better control/stability). |
📜 Checklist
See: Pull Request Walkthrough