From e4112920e6fd32938684b1975d9edaf7468ba1e3 Mon Sep 17 00:00:00 2001 From: Gil Forsyth Date: Fri, 15 May 2026 16:22:56 -0400 Subject: [PATCH 1/7] feat(ci): add zizmor config and pre-commit Signed-off-by: Gil Forsyth --- .pre-commit-config.yaml | 4 ++++ zizmor.yml | 9 +++++++++ 2 files changed, 13 insertions(+) create mode 100644 zizmor.yml diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 61abdaf1..22199bf1 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -87,6 +87,10 @@ repos: hooks: - id: rapids-dependency-file-generator args: ["--clean"] + - repo: https://github.com/zizmorcore/zizmor-pre-commit + rev: v1.24.1 + hooks: + - id: zizmor default_language_version: python: python3 diff --git a/zizmor.yml b/zizmor.yml new file mode 100644 index 00000000..1b6ea1e5 --- /dev/null +++ b/zizmor.yml @@ -0,0 +1,9 @@ +rules: + unpinned-uses: + config: + policies: + # We require SHA-pinning for all workflows and actions _except_ for those from + # rapidsai/shared-workflows and rapidsai/shared-actions + "rapidsai/shared-workflows/*": any + "rapidsai/shared-actions/*": any + "*": hash-pin From 6a3eccd21ceb6fbfb5a157ca6e377316bcc1fe91 Mon Sep 17 00:00:00 2001 From: Gil Forsyth Date: Fri, 15 May 2026 16:23:06 -0400 Subject: [PATCH 2/7] fix(ci): hash-pin all third-party actions Signed-off-by: Gil Forsyth --- .github/workflows/conda-python-build.yaml | 6 +++--- .github/workflows/conda-upload-packages.yaml | 4 ++-- .github/workflows/docs-build.yaml | 8 ++++---- .github/workflows/pr.yaml | 12 ++++++------ 4 files changed, 15 insertions(+), 15 deletions(-) diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index d88f3aa1..02121558 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -52,18 +52,18 @@ jobs: container: image: "rapidsai/ci-conda:cuda${{ matrix.CUDA_VER }}-ubuntu24.04-py${{ matrix.PY_VER }}" steps: - - uses: aws-actions/configure-aws-credentials@v4 + - uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4.3.1 with: role-to-assume: ${{ vars.AWS_ROLE_ARN }} aws-region: ${{ vars.AWS_REGION }} role-duration-seconds: 14400 # 4h - - uses: actions/checkout@v4 + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 - name: build run: "${{ inputs.script }}" - name: upload - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: legate-dataframe-conda-cuda${{ matrix.CUDA_VER }}-${{ matrix.ARCH }}-py${{ matrix.PY_VER }} path: ${{ env.RAPIDS_CONDA_BLD_OUTPUT_DIR }} diff --git a/.github/workflows/conda-upload-packages.yaml b/.github/workflows/conda-upload-packages.yaml index 46fe5470..77ce4061 100644 --- a/.github/workflows/conda-upload-packages.yaml +++ b/.github/workflows/conda-upload-packages.yaml @@ -19,11 +19,11 @@ jobs: container: image: rapidsai/ci-conda:latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 - name: download conda packages - uses: actions/download-artifact@v4 + uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: # omitting 'name' here means "download all artifacts from this run"... useful to # avoid having to list the matrix of CUDA / Python versions here diff --git a/.github/workflows/docs-build.yaml b/.github/workflows/docs-build.yaml index 39d76caf..aa5ddbf4 100644 --- a/.github/workflows/docs-build.yaml +++ b/.github/workflows/docs-build.yaml @@ -37,11 +37,11 @@ jobs: env: NVIDIA_VISIBLE_DEVICES: ${{ env.NVIDIA_VISIBLE_DEVICES }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 - name: download conda packages - uses: actions/download-artifact@v4 + uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: name: legate-dataframe-conda-cuda${{ matrix.CUDA_VER }}-${{ matrix.ARCH }}-py${{ matrix.PY_VER }} path: ${{ env.RAPIDS_LOCAL_CONDA_CHANNEL }} @@ -50,7 +50,7 @@ jobs: run-id: ${{ github.run_id }} - name: build docs run: "${{ inputs.script }}" - - uses: actions/upload-pages-artifact@v3 + - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1 with: path: docs/build/html @@ -73,4 +73,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@v4 + uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5 diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml index d0da70a0..5f4f8da6 100644 --- a/.github/workflows/pr.yaml +++ b/.github/workflows/pr.yaml @@ -28,8 +28,8 @@ jobs: pre-commit: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: pre-commit/action@v3.0.1 + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + - uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd # v3.0.1 conda-python-build: needs: @@ -58,11 +58,11 @@ jobs: container: image: "rapidsai/ci-conda:cuda${{ matrix.CUDA_VER }}-ubuntu24.04-py${{ matrix.PY_VER }}" steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 - name: download conda packages - uses: actions/download-artifact@v4 + uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: name: legate-dataframe-conda-cuda${{ matrix.CUDA_VER }}-${{ matrix.ARCH }}-py${{ matrix.PY_VER }} path: ${{ env.RAPIDS_LOCAL_CONDA_CHANNEL }} @@ -100,11 +100,11 @@ jobs: env: NVIDIA_VISIBLE_DEVICES: ${{ env.NVIDIA_VISIBLE_DEVICES }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 - name: download conda packages - uses: actions/download-artifact@v4 + uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: name: legate-dataframe-conda-cuda${{ matrix.CUDA_VER }}-${{ matrix.ARCH }}-py${{ matrix.PY_VER }} path: ${{ env.RAPIDS_LOCAL_CONDA_CHANNEL }} From 6872b446c2040d542534459d2cf5cd9138439dfe Mon Sep 17 00:00:00 2001 From: Gil Forsyth Date: Fri, 15 May 2026 16:24:10 -0400 Subject: [PATCH 3/7] fix(ci): use explicit permissions per-job Signed-off-by: Gil Forsyth --- .github/workflows/build.yaml | 4 +--- .github/workflows/conda-python-build.yaml | 6 ------ .github/workflows/conda-upload-packages.yaml | 3 +-- .github/workflows/docs-build.yaml | 14 +++----------- .github/workflows/pr.yaml | 20 +++++++++----------- 5 files changed, 14 insertions(+), 33 deletions(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 5b0365f6..7fab3ff0 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -1,9 +1,7 @@ name: build - concurrency: group: ci-on-${{ github.event_name }}-from-${{ github.ref_name }} cancel-in-progress: true - on: # run on pushes to certain branches push: @@ -20,7 +18,7 @@ on: description: 'Update the docs site?' required: true type: boolean - +permissions: {} jobs: conda-python-build: uses: ./.github/workflows/conda-python-build.yaml diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 02121558..e27855b7 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -1,9 +1,7 @@ name: conda-python-build - concurrency: group: conda-python-build-on-${{ github.event_name }}-from-${{ github.ref_name }} cancel-in-progress: true - on: # run only when called by other workflows workflow_call: @@ -12,12 +10,10 @@ on: required: true type: string description: "relative path to a script that builds conda packages" - # override default permissions permissions: # needed to auth with AWS for sccache id-token: write - env: # CUDA architectures to build for CUDAARCHS: "all-major" @@ -26,9 +22,7 @@ env: GH_TOKEN: ${{ github.token }} # where conda-python-build puts files it creates RAPIDS_CONDA_BLD_OUTPUT_DIR: /tmp/conda-bld-output - jobs: - build: strategy: fail-fast: false diff --git a/.github/workflows/conda-upload-packages.yaml b/.github/workflows/conda-upload-packages.yaml index 77ce4061..389b1b87 100644 --- a/.github/workflows/conda-upload-packages.yaml +++ b/.github/workflows/conda-upload-packages.yaml @@ -8,11 +8,10 @@ on: # run only when called by other workflows workflow_call: - env: # where jobs that download conda packages store the local channel RAPIDS_LOCAL_CONDA_CHANNEL: /tmp/local-conda-packages - +permissions: {} jobs: upload: runs-on: linux-amd64-cpu4 diff --git a/.github/workflows/docs-build.yaml b/.github/workflows/docs-build.yaml index aa5ddbf4..28aab379 100644 --- a/.github/workflows/docs-build.yaml +++ b/.github/workflows/docs-build.yaml @@ -1,9 +1,7 @@ name: docs-build - concurrency: group: docs-build-on-${{ github.event_name }}-from-${{ github.ref_name }} cancel-in-progress: true - on: # run only when called by other workflows workflow_call: @@ -17,13 +15,11 @@ on: required: true type: string description: "relative path to a script that builds conda packages" - env: # where jobs that download conda packages store the local channel RAPIDS_LOCAL_CONDA_CHANNEL: /tmp/local-conda-packages - +permissions: {} jobs: - build: strategy: matrix: @@ -53,22 +49,18 @@ jobs: - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1 with: path: docs/build/html - deploy: needs: - build if: inputs.deploy - # Grant GITHUB_TOKEN the permissions required to make a Pages deployment permissions: - pages: write # to deploy to Pages - id-token: write # to verify the deployment originates from an appropriate source - + pages: write # to deploy to Pages + id-token: write # to verify the deployment originates from an appropriate source # Deploy to the github-pages environment environment: name: github-pages url: ${{ steps.deployment.outputs.page_url }} - runs-on: ubuntu-latest steps: - name: Deploy to GitHub Pages diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml index 5f4f8da6..3a5c7f5c 100644 --- a/.github/workflows/pr.yaml +++ b/.github/workflows/pr.yaml @@ -1,20 +1,16 @@ name: pr - concurrency: group: ci-on-${{ github.event_name }}-from-${{ github.ref_name }} cancel-in-progress: true - on: push: branches: - "pull-request/[0-9]+" - env: # where jobs that download conda packages store the local channel RAPIDS_LOCAL_CONDA_CHANNEL: /tmp/local-conda-packages - +permissions: {} jobs: - # group together all jobs that must pass for a PR to be merged # (for use by branch protections) pr-builder: @@ -24,13 +20,17 @@ jobs: - conda-python-cpu-tests - conda-python-gpu-tests uses: rapidsai/shared-workflows/.github/workflows/pr-builder.yaml@branch-25.08 - + permissions: + actions: read + contents: read + id-token: write + packages: read + pull-requests: read pre-commit: runs-on: ubuntu-latest steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 - - uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd # v3.0.1 - + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + - uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd # v3.0.1 conda-python-build: needs: - pre-commit @@ -38,7 +38,6 @@ jobs: with: script: "ci/build_all.sh" secrets: inherit - conda-python-cpu-tests: needs: - pre-commit @@ -72,7 +71,6 @@ jobs: - name: test python and C++ interface run: | ci/test_cpu.sh - conda-python-gpu-tests: needs: - pre-commit From 254a5832fb729e39a150ff0918c71e3064022fbe Mon Sep 17 00:00:00 2001 From: Gil Forsyth Date: Fri, 15 May 2026 16:29:19 -0400 Subject: [PATCH 4/7] fix(ci): don't persist credentials Signed-off-by: Gil Forsyth --- .github/workflows/conda-python-build.yaml | 1 + .github/workflows/conda-upload-packages.yaml | 1 + .github/workflows/docs-build.yaml | 1 + .github/workflows/pr.yaml | 6 ++++-- 4 files changed, 7 insertions(+), 2 deletions(-) diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index e27855b7..fb11b7a0 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -54,6 +54,7 @@ jobs: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 + persist-credentials: false - name: build run: "${{ inputs.script }}" - name: upload diff --git a/.github/workflows/conda-upload-packages.yaml b/.github/workflows/conda-upload-packages.yaml index 389b1b87..72e04593 100644 --- a/.github/workflows/conda-upload-packages.yaml +++ b/.github/workflows/conda-upload-packages.yaml @@ -21,6 +21,7 @@ jobs: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 + persist-credentials: false - name: download conda packages uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: diff --git a/.github/workflows/docs-build.yaml b/.github/workflows/docs-build.yaml index 28aab379..8a3a9b25 100644 --- a/.github/workflows/docs-build.yaml +++ b/.github/workflows/docs-build.yaml @@ -36,6 +36,7 @@ jobs: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 + persist-credentials: false - name: download conda packages uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml index 3a5c7f5c..d7840e16 100644 --- a/.github/workflows/pr.yaml +++ b/.github/workflows/pr.yaml @@ -30,6 +30,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + with: + persist-credentials: false - uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd # v3.0.1 conda-python-build: needs: @@ -37,7 +39,6 @@ jobs: uses: ./.github/workflows/conda-python-build.yaml with: script: "ci/build_all.sh" - secrets: inherit conda-python-cpu-tests: needs: - pre-commit @@ -59,6 +60,7 @@ jobs: steps: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: + persist-credentials: false fetch-depth: 0 - name: download conda packages uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 @@ -101,6 +103,7 @@ jobs: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: fetch-depth: 0 + persist-credentials: false - name: download conda packages uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 with: @@ -119,4 +122,3 @@ jobs: with: script: "ci/build_docs.sh" deploy: false - secrets: inherit From 7a9ed0e8fb29594c54f50af4af134ec586dea6b7 Mon Sep 17 00:00:00 2001 From: Gil Forsyth Date: Fri, 15 May 2026 16:31:47 -0400 Subject: [PATCH 5/7] fix(ci): pass secrets explicitly Signed-off-by: Gil Forsyth --- .github/workflows/build.yaml | 6 +++--- .github/workflows/conda-upload-packages.yaml | 3 +++ 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 7fab3ff0..41505733 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -24,12 +24,13 @@ jobs: uses: ./.github/workflows/conda-python-build.yaml with: script: "ci/build_all.sh" - secrets: inherit upload-conda: needs: - conda-python-build uses: ./.github/workflows/conda-upload-packages.yaml - secrets: inherit + secrets: + CONDA_LEGATE_TOKEN: ${{ secrets.CONDA_LEGATE_TOKEN }} + docs-build: needs: - conda-python-build @@ -38,4 +39,3 @@ jobs: script: "ci/build_docs.sh" # only deploy docs on tag pushes or when someone manually runs the workflow with "update docs" selected deploy: ${{ (github.event_name == 'push' && startsWith(github.ref, 'refs/tags')) || (github.event_name == 'workflow_dispatch' && inputs.deploy-docs == true) }} - secrets: inherit diff --git a/.github/workflows/conda-upload-packages.yaml b/.github/workflows/conda-upload-packages.yaml index 72e04593..a349f8e1 100644 --- a/.github/workflows/conda-upload-packages.yaml +++ b/.github/workflows/conda-upload-packages.yaml @@ -8,6 +8,9 @@ on: # run only when called by other workflows workflow_call: + secrets: + CONDA_LEGATE_TOKEN: + required: false env: # where jobs that download conda packages store the local channel RAPIDS_LOCAL_CONDA_CHANNEL: /tmp/local-conda-packages From efb771d37259095ffd8959d623303809dfec4855 Mon Sep 17 00:00:00 2001 From: Gil Forsyth Date: Fri, 15 May 2026 16:33:49 -0400 Subject: [PATCH 6/7] fix(ci): only allow scripts present in `ci/` Signed-off-by: Gil Forsyth --- .github/workflows/conda-python-build.yaml | 15 ++++++++++++++- .github/workflows/docs-build.yaml | 15 ++++++++++++++- 2 files changed, 28 insertions(+), 2 deletions(-) diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index fb11b7a0..ec9b9550 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -56,7 +56,20 @@ jobs: fetch-depth: 0 persist-credentials: false - name: build - run: "${{ inputs.script }}" + env: + SCRIPT: ${{ inputs.script }} + run: | + script_path="$(realpath "$SCRIPT")" + ci_dir="$(realpath ci)" + + # Use `realpath` to expand out both the script path and the ci path and compare to make sure + # that user isn't giving a relative path to a file outside of `ci/` + if [[ "$script_path" != "$ci_dir"/*.sh ]]; then + echo "::error::Invalid script path '$SCRIPT'. Expected an existing ci/*.sh script inside the checkout" + exit 1 + fi + + bash "$script_path" - name: upload uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: diff --git a/.github/workflows/docs-build.yaml b/.github/workflows/docs-build.yaml index 8a3a9b25..5b8a0cbe 100644 --- a/.github/workflows/docs-build.yaml +++ b/.github/workflows/docs-build.yaml @@ -46,7 +46,20 @@ jobs: repository: ${{ github.repository }} run-id: ${{ github.run_id }} - name: build docs - run: "${{ inputs.script }}" + env: + SCRIPT: ${{ inputs.script }} + run: | + script_path="$(realpath "$SCRIPT")" + ci_dir="$(realpath ci)" + + # Use `realpath` to expand out both the script path and the ci path and compare to make sure + # that user isn't giving a relative path to a file outside of `ci/` + if [[ "$script_path" != "$ci_dir"/*.sh ]]; then + echo "::error::Invalid script path '$SCRIPT'. Expected an existing ci/*.sh script inside the checkout" + exit 1 + fi + + bash "$script_path" - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1 with: path: docs/build/html From 37bc1ce0f0e9d9043af77e43398efdbbff4cb7ad Mon Sep 17 00:00:00 2001 From: Gil Forsyth Date: Fri, 15 May 2026 16:34:23 -0400 Subject: [PATCH 7/7] fix(ci): suppress warning abotu unpinned rapids image Signed-off-by: Gil Forsyth --- .github/workflows/conda-upload-packages.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/conda-upload-packages.yaml b/.github/workflows/conda-upload-packages.yaml index a349f8e1..84383e1e 100644 --- a/.github/workflows/conda-upload-packages.yaml +++ b/.github/workflows/conda-upload-packages.yaml @@ -19,7 +19,7 @@ jobs: upload: runs-on: linux-amd64-cpu4 container: - image: rapidsai/ci-conda:latest + image: rapidsai/ci-conda:latest # zizmor: ignore[unpinned-images] steps: - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: