Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
contents: read
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: 🦪 ✔ 🧼🧼🧼
Expand All @@ -26,27 +26,27 @@
with:
enable-cache: false
- name: Install dependencies
run: uv sync --extra dev

Check warning on line 29 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zB-&open=AZ-IO0nCYbPyYEUn2zB-&pullRequest=564

Check warning on line 29 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zB9&open=AZ-IO0nCYbPyYEUn2zB9&pullRequest=564
working-directory: xtest
- name: Lint xtest python
run: |
uv run ruff check .

Check warning on line 33 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCA&open=AZ-IO0nCYbPyYEUn2zCA&pullRequest=564

Check warning on line 33 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zB_&open=AZ-IO0nCYbPyYEUn2zB_&pullRequest=564
uv run ruff format --check .

Check warning on line 34 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCB&open=AZ-IO0nCYbPyYEUn2zCB&pullRequest=564

Check warning on line 34 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCC&open=AZ-IO0nCYbPyYEUn2zCC&pullRequest=564
uv run pyright

Check warning on line 35 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCD&open=AZ-IO0nCYbPyYEUn2zCD&pullRequest=564

Check warning on line 35 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCE&open=AZ-IO0nCYbPyYEUn2zCE&pullRequest=564
working-directory: xtest
- name: Lint and test otdf-local
run: |
uv sync

Check warning on line 39 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCF&open=AZ-IO0nCYbPyYEUn2zCF&pullRequest=564

Check warning on line 39 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCG&open=AZ-IO0nCYbPyYEUn2zCG&pullRequest=564
uv run ruff check .

Check warning on line 40 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCH&open=AZ-IO0nCYbPyYEUn2zCH&pullRequest=564

Check warning on line 40 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCI&open=AZ-IO0nCYbPyYEUn2zCI&pullRequest=564
uv run ruff format --check .

Check warning on line 41 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCK&open=AZ-IO0nCYbPyYEUn2zCK&pullRequest=564

Check warning on line 41 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCJ&open=AZ-IO0nCYbPyYEUn2zCJ&pullRequest=564
uv run pyright

Check warning on line 42 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCM&open=AZ-IO0nCYbPyYEUn2zCM&pullRequest=564

Check warning on line 42 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCL&open=AZ-IO0nCYbPyYEUn2zCL&pullRequest=564
uv run pytest --maxfail=1 --disable-warnings -v --tb=short -m "not integration"

Check warning on line 43 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCN&open=AZ-IO0nCYbPyYEUn2zCN&pullRequest=564
working-directory: otdf-local
- name: Lint and test otdf-sdk-mgr
run: |
uv sync

Check warning on line 47 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCP&open=AZ-IO0nCYbPyYEUn2zCP&pullRequest=564

Check warning on line 47 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCO&open=AZ-IO0nCYbPyYEUn2zCO&pullRequest=564
uv run ruff check .

Check warning on line 48 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCR&open=AZ-IO0nCYbPyYEUn2zCR&pullRequest=564

Check warning on line 48 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCQ&open=AZ-IO0nCYbPyYEUn2zCQ&pullRequest=564
uv run ruff format --check .

Check warning on line 49 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCS&open=AZ-IO0nCYbPyYEUn2zCS&pullRequest=564

Check warning on line 49 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCT&open=AZ-IO0nCYbPyYEUn2zCT&pullRequest=564
uv run pyright

Check warning on line 50 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCV&open=AZ-IO0nCYbPyYEUn2zCV&pullRequest=564

Check warning on line 50 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCU&open=AZ-IO0nCYbPyYEUn2zCU&pullRequest=564
uv run pytest --maxfail=1 --disable-warnings -v --tb=short -m "not integration"

Check warning on line 51 in .github/workflows/check.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0nCYbPyYEUn2zCW&open=AZ-IO0nCYbPyYEUn2zCW&pullRequest=564
working-directory: otdf-sdk-mgr
2 changes: 1 addition & 1 deletion .github/workflows/dependency-review.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ jobs:

- name: Checkout
if: ${{ github.event_name != 'merge_group' }}
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/vulnerability.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@
contents: read
packages: read
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e
Expand All @@ -33,14 +33,14 @@
registry-url: https://npm.pkg.github.com
- name: Install dependencies
run: |-
npm ci

Check warning on line 36 in .github/workflows/vulnerability.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0h9YbPyYEUn2zB7&open=AZ-IO0h9YbPyYEUn2zB7&pullRequest=564
- name: Check out and start up platform with deps/containers
id: run-platform
uses: opentdf/platform/test/start-up-with-containers@11af44a5d4826ed281bf2e0e4e31d6ff6154b393 # pqc-enabled
with:
platform-ref: ${{ inputs.platform-ref }}
- name: Get grpcurl
run: go install github.com/fullstorydev/grpcurl/cmd/grpcurl@v1.8.9

Check warning on line 43 in .github/workflows/vulnerability.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Dependency versions are not predictable. Use a lock-file enforcing command instead.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0h9YbPyYEUn2zB8&open=AZ-IO0h9YbPyYEUn2zB8&pullRequest=564
- name: Make sure that the platform is up
run: |
grpcurl -plaintext localhost:8080 list && \
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/xtest.yml
Original file line number Diff line number Diff line change
Expand Up @@ -118,7 +118,7 @@
CRON_NIGHTLY: ${{ github.event.schedule == '30 6 * * *' }}
CRON_MONDAY_WEDNESDAY: ${{ github.event.schedule == '0 5 * * 1,3' }}
CRON_WEEKLY: ${{ github.event.schedule == '0 18 * * 0' }}
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
path: otdf-sdk
persist-credentials: false
Expand Down Expand Up @@ -273,7 +273,7 @@
platform-tag: ${{ fromJSON(needs.resolve-versions.outputs.platform-tag-list) }}
sdk-version: ${{ fromJSON(needs.resolve-versions.outputs.sdk-version-list) }}
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: opentdf/tests
path: otdftests # use different name bc other repos might have tests directories
Expand Down Expand Up @@ -324,7 +324,7 @@
version: "1.56.0"

- name: Set up JDK
uses: actions/setup-java@ad2b38190b15e4d6bdf0c97fb4fca8412226d287
uses: actions/setup-java@03ad4de0992f5dab5e18fcb136590ce7c4a0ac95
with:
java-version: "11"
distribution: "adopt"
Expand Down Expand Up @@ -371,7 +371,7 @@

- name: Cache npm
if: fromJson(steps.configure-js.outputs.heads)[0] != null
uses: actions/cache@2c8a9bd7457de244a408f35966fab2fb45fda9c8 # v6.0.0
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ~/.npm
key: npm-${{ runner.os }}-${{ hashFiles('otdftests/xtest/sdk/js/src/**/package-lock.json') }}
Expand Down Expand Up @@ -399,7 +399,7 @@

- name: Cache Go modules
if: fromJson(steps.configure-go.outputs.heads)[0] != null
uses: actions/cache@2c8a9bd7457de244a408f35966fab2fb45fda9c8 # v6.0.0
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
~/.cache/go-build
Expand Down Expand Up @@ -434,7 +434,7 @@

- name: Cache Maven repository
if: fromJson(steps.configure-java.outputs.heads)[0] != null
uses: actions/cache@2c8a9bd7457de244a408f35966fab2fb45fda9c8 # v6.0.0
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ~/.m2/repository
key: maven-${{ runner.os }}-${{ hashFiles('otdftests/xtest/sdk/java/src/**/pom.xml') }}
Expand Down Expand Up @@ -525,12 +525,12 @@
working-directory: ${{ steps.run-platform.outputs.platform-working-dir }}

- name: Install test dependencies
run: uv sync

Check warning on line 528 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCY&open=AZ-IO0oRYbPyYEUn2zCY&pullRequest=564

Check warning on line 528 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCX&open=AZ-IO0oRYbPyYEUn2zCX&pullRequest=564
working-directory: otdftests/xtest
- name: Validate xtest helper library (tests of the test harness and its utilities)
if: ${{ !inputs }}
run: |-
uv run pytest --html=test-results/helper-${FOCUS_SDK}-${PLATFORM_TAG}.html --self-contained-html --sdks-encrypt "${ENCRYPT_SDK}" test_self.py test_audit_logs.py

Check warning on line 533 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCa&open=AZ-IO0oRYbPyYEUn2zCa&pullRequest=564

Check warning on line 533 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCZ&open=AZ-IO0oRYbPyYEUn2zCZ&pullRequest=564
working-directory: otdftests/xtest
env:
PLATFORM_TAG: ${{ matrix.platform-tag }}
Expand All @@ -539,8 +539,8 @@
- name: Validate otdf-local integration tests
if: ${{ !inputs }}
run: |-
uv sync

Check warning on line 542 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCc&open=AZ-IO0oRYbPyYEUn2zCc&pullRequest=564

Check warning on line 542 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Omitting "--no-build" can lead to the execution of setup scripts. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCb&open=AZ-IO0oRYbPyYEUn2zCb&pullRequest=564
uv run pytest --maxfail=1 --disable-warnings -v --tb=short -m integration

Check warning on line 543 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCd&open=AZ-IO0oRYbPyYEUn2zCd&pullRequest=564
working-directory: otdftests/otdf-local
env:
OTDF_LOCAL_PLATFORM_DIR: ${{ github.workspace }}/${{ steps.run-platform.outputs.platform-working-dir }}
Expand All @@ -549,7 +549,7 @@
- name: Run legacy decryption tests
run: |-
skip_flag=$([[ "$SKIP_RELEASED_PAIRS" == "true" ]] && echo "--skip-released-pairs" || echo "")
uv run pytest -n auto --dist worksteal --html=test-results/sdk-${FOCUS_SDK}-${PLATFORM_TAG}.html --self-contained-html --sdks-decrypt "${ENCRYPT_SDK}" -ra -v --focus "$FOCUS_SDK" $skip_flag test_legacy.py

Check warning on line 552 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCe&open=AZ-IO0oRYbPyYEUn2zCe&pullRequest=564
working-directory: otdftests/xtest
env:
PLATFORM_DIR: "../../${{ steps.run-platform.outputs.platform-working-dir }}"
Expand All @@ -560,7 +560,7 @@
if: ${{ env.FOCUS_SDK == 'all' }}
run: |-
skip_flag=$([[ "$SKIP_RELEASED_PAIRS" == "true" ]] && echo "--skip-released-pairs" || echo "")
uv run pytest -n auto --dist loadscope --html=test-results/sdk-${FOCUS_SDK}-${PLATFORM_TAG}.html --self-contained-html --sdks-encrypt "${ENCRYPT_SDK}" -ra -v $skip_flag test_tdfs.py test_policytypes.py

Check warning on line 563 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCf&open=AZ-IO0oRYbPyYEUn2zCf&pullRequest=564
working-directory: otdftests/xtest
env:
PLATFORM_DIR: "../../${{ steps.run-platform.outputs.platform-working-dir }}"
Expand All @@ -572,7 +572,7 @@
if: ${{ env.FOCUS_SDK != 'all' }}
run: |-
skip_flag=$([[ "$SKIP_RELEASED_PAIRS" == "true" ]] && echo "--skip-released-pairs" || echo "")
uv run pytest -n auto --dist loadscope --html=test-results/sdk-${FOCUS_SDK}-${PLATFORM_TAG}.html --self-contained-html --sdks-encrypt "${ENCRYPT_SDK}" -ra -v --focus "$FOCUS_SDK" $skip_flag test_tdfs.py test_policytypes.py

Check warning on line 575 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCg&open=AZ-IO0oRYbPyYEUn2zCg&pullRequest=564
working-directory: otdftests/xtest
env:
PLATFORM_DIR: "../../${{ steps.run-platform.outputs.platform-working-dir }}"
Expand Down Expand Up @@ -682,7 +682,7 @@
if: ${{ steps.multikas.outputs.supported == 'true' }}
run: |-
skip_flag=$([[ "$SKIP_RELEASED_PAIRS" == "true" ]] && echo "--skip-released-pairs" || echo "")
uv run pytest -ra -v --numprocesses auto --dist loadscope \

Check warning on line 685 in .github/workflows/xtest.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Using dependencies without locking resolved versions is security-sensitive.

See more on https://sonarcloud.io/project/issues?id=opentdf_tests&issues=AZ-IO0oRYbPyYEUn2zCh&open=AZ-IO0oRYbPyYEUn2zCh&pullRequest=564
--html test-results/attributes-${FOCUS_SDK}-${PLATFORM_TAG}.html \
--self-contained-html \
--audit-log-dir test-results/audit-logs \
Expand Down
Loading