Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/breaking-change-alert.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -124,7 +124,7 @@ jobs:
fi

- name: Send Slack notification
uses: slackapi/slack-github-action@v2.0.0
uses: slackapi/slack-github-action@485a9d42d3a73031f12ec201c457e2162c45d02d # v2.0.0
with:
payload: |
{
Expand Down
16 changes: 10 additions & 6 deletions .github/workflows/build-in-devcontainer.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,7 @@ jobs:
repository: ${{ inputs.repo }}
ref: ${{ inputs.sha }}
fetch-depth: 0
persist-credentials: true

# This provides an initial set of metadata tags. Jobs are free to add to the RAPIDS_JOB_ATTRIBUTES
# environment variable as they see fit - but remember to export the variable to ${GITHUB_ENV}
Expand All @@ -87,15 +88,18 @@ jobs:
extra_attributes: "rapids.PACKAGER=${{ matrix.PACKAGER }},rapids.CUDA_VER=${{ matrix.CUDA_VER }},rapids.ARCH=${{ matrix.ARCH }}"

- name: Check if repo has devcontainer
env:
CUDA_VER: ${{ matrix.CUDA_VER }}
PACKAGER: ${{ matrix.PACKAGER }}
run: |
echo "REPOSITORY=$(basename "$(pwd)")" | tee -a "${GITHUB_ENV}"
if test -f .devcontainer/cuda${{ matrix.CUDA_VER }}-${{ matrix.PACKAGER }}/devcontainer.json; then
if test -f ".devcontainer/cuda${CUDA_VER}-${PACKAGER}/devcontainer.json"; then
echo "HAS_DEVCONTAINER=true" >> "${GITHUB_ENV}"
else
echo "HAS_DEVCONTAINER=false" >> "${GITHUB_ENV}"
fi
- if: ${{ env.HAS_DEVCONTAINER == 'true' }}
uses: aws-actions/configure-aws-credentials@v4
uses: aws-actions/configure-aws-credentials@b47578312673ae6fa5b5096b330d9fbac3d116df # v4.2.1
with:
role-to-assume: ${{ vars.AWS_ROLE_ARN }}
aws-region: ${{ vars.AWS_REGION }}
Expand All @@ -112,7 +116,7 @@ jobs:

- if: ${{ env.HAS_DEVCONTAINER == 'true' }}
name: Run build in devcontainer
uses: devcontainers/ci@v0.3
uses: devcontainers/ci@8bf61b26e9c3a98f69cb6ce2f88d24ff59b785c6 # v0.3.1900000417
with:
push: never
configFile: .devcontainer/cuda${{ matrix.CUDA_VER }}-${{ matrix.PACKAGER }}/devcontainer.json
Expand All @@ -124,7 +128,7 @@ jobs:
AWS_ACCESS_KEY_ID=${{ env.AWS_ACCESS_KEY_ID }}
AWS_SESSION_TOKEN=${{ env.AWS_SESSION_TOKEN }}
AWS_SECRET_ACCESS_KEY=${{ env.AWS_SECRET_ACCESS_KEY }}
RAPIDS_AUX_SECRET_1=${{ inputs.rapids-aux-secret-1 != '' && secrets[inputs.rapids-aux-secret-1] || '' }}
RAPIDS_AUX_SECRET_1=${{ inputs.rapids-aux-secret-1 != '' && secrets[inputs.rapids-aux-secret-1] || '' }} # zizmor: ignore[overprovisioned-secrets]
TRACEPARENT=${{ env.TRACEPARENT }}
OTEL_SERVICE_NAME=${{ env.OTEL_SERVICE_NAME }}
OTEL_EXPORTER_OTLP_ENDPOINT=${{ env.OTEL_EXPORTER_OTLP_ENDPOINT }}
Expand All @@ -145,10 +149,10 @@ jobs:
|| test -n '${{ inputs.extra-repo-deploy-key-2 }}'; then
if ! pgrep ssh-agent >/dev/null 2>&1; then eval "$(ssh-agent -s)"; fi;
if test -n '${{ inputs.extra-repo-deploy-key }}'; then
ssh-add - <<< '${{ secrets[inputs.extra-repo-deploy-key] }}';
ssh-add - <<< '${{ secrets[inputs.extra-repo-deploy-key] }}'; # zizmor: ignore[overprovisioned-secrets]
fi
if test -n '${{ inputs.extra-repo-deploy-key-2 }}'; then
ssh-add - <<< '${{ secrets[inputs.extra-repo-deploy-key-2] }}';
ssh-add - <<< '${{ secrets[inputs.extra-repo-deploy-key-2] }}'; # zizmor: ignore[overprovisioned-secrets]
fi
devcontainer-utils-init-ssh-deploy-keys || true;
fi
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/checks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -40,12 +40,14 @@ jobs:
other-checks:
runs-on: ubuntu-latest
container:
image: rapidsai/ci-conda:25.08-latest
image: rapidsai/ci-conda:25.08-latest # zizmor: ignore[unpinned-images]
env:
RAPIDS_GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
persist-credentials: true
- name: Telemetry setup
uses: rapidsai/shared-actions/telemetry-dispatch-setup@main
continue-on-error: true
Expand Down Expand Up @@ -76,12 +78,13 @@ jobs:
if: ${{ inputs.enable_check_style }}
runs-on: ubuntu-latest
container:
image: rapidsai/ci-conda:25.08-latest
image: rapidsai/ci-conda:25.08-latest # zizmor: ignore[unpinned-images]
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 0
persist-credentials: true
- name: Telemetry setup
uses: rapidsai/shared-actions/telemetry-dispatch-setup@main
continue-on-error: true
Expand Down
13 changes: 8 additions & 5 deletions .github/workflows/conda-cpp-build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,7 @@ jobs:
env:
RAPIDS_BUILD_TYPE: ${{ inputs.build_type }}
steps:
- uses: aws-actions/configure-aws-credentials@v4
- uses: aws-actions/configure-aws-credentials@b47578312673ae6fa5b5096b330d9fbac3d116df # v4.2.1
with:
role-to-assume: ${{ vars.AWS_ROLE_ARN }}
aws-region: ${{ vars.AWS_REGION }}
Expand All @@ -117,6 +117,7 @@ jobs:
repository: ${{ inputs.repo }}
ref: ${{ inputs.sha }}
fetch-depth: 0
persist-credentials: true
- name: Standardize repository information
env:
RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }}
Expand Down Expand Up @@ -160,13 +161,13 @@ jobs:
fi
env:
# NEEDS alternative-gh-token-secret-name - API limits need to be for whatever token is used for upload/download. Repo token may be a different pool for rate limits.
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
- name: C++ build
run: ${{ inputs.script }}
run: ${{ inputs.script }} # zizmor: ignore[template-injection]
env:
STEP_NAME: "C++ build"
# NEEDS alternative-gh-token-secret-name - may require a token with more permissions
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
- name: Get Package Name and Location
if: ${{ inputs.upload-artifacts }}
run: |
Expand All @@ -175,9 +176,11 @@ jobs:
id: package-name
- name: Show files to be uploaded
if: ${{ inputs.upload-artifacts }}
env:
CONDA_OUTPUT_DIR: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }}
run: |
echo "Contents of directory to be uploaded:"
ls -R ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }}
ls -R "${CONDA_OUTPUT_DIR}"
- uses: actions/upload-artifact@v4
if: ${{ inputs.upload-artifacts }}
with:
Expand Down
6 changes: 4 additions & 2 deletions .github/workflows/conda-cpp-post-build-checks.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -55,11 +55,11 @@ jobs:
if: ${{ inputs.enable_check_symbols }}
runs-on: linux-amd64-cpu4
container:
image: rapidsai/ci-wheel:25.08-latest
image: rapidsai/ci-wheel:25.08-latest # zizmor: ignore[unpinned-images]
env:
RAPIDS_BUILD_TYPE: ${{ inputs.build_type }}
steps:
- uses: aws-actions/configure-aws-credentials@v4
- uses: aws-actions/configure-aws-credentials@b47578312673ae6fa5b5096b330d9fbac3d116df # v4.2.1
with:
role-to-assume: ${{ vars.AWS_ROLE_ARN }}
aws-region: ${{ vars.AWS_REGION }}
Expand All @@ -70,6 +70,7 @@ jobs:
ref: ${{ inputs.sha }}
path: "./src/"
fetch-depth: 0
persist-credentials: true
- name: Telemetry setup
uses: rapidsai/shared-actions/telemetry-dispatch-setup@main
continue-on-error: true
Expand Down Expand Up @@ -113,6 +114,7 @@ jobs:
ref: refs/heads/main
path: "./tool/"
fetch-depth: 0
persist-credentials: true
- name: Verify CUDA libraries have no public kernel entry points
env:
SYMBOL_EXCLUSIONS: ${{ inputs.symbol_exclusions }}
Expand Down
11 changes: 6 additions & 5 deletions .github/workflows/conda-cpp-tests.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -155,7 +155,7 @@ jobs:
RAPIDS_BUILD_TYPE: ${{ inputs.build_type }}
NVIDIA_VISIBLE_DEVICES: ${{ env.NVIDIA_VISIBLE_DEVICES }}
steps:
- uses: aws-actions/configure-aws-credentials@v4
- uses: aws-actions/configure-aws-credentials@b47578312673ae6fa5b5096b330d9fbac3d116df # v4.2.1
with:
role-to-assume: ${{ vars.AWS_ROLE_ARN }}
aws-region: ${{ vars.AWS_REGION }}
Expand All @@ -166,6 +166,7 @@ jobs:
repository: ${{ inputs.repo }}
ref: ${{ inputs.sha }}
fetch-depth: 0
persist-credentials: true
# This has to be AFTER the checkout step. It creates a telemetry-artifacts directory,
# and the checkout step would destroy it.
- name: Telemetry setup
Expand Down Expand Up @@ -204,14 +205,14 @@ jobs:
fi
env:
# NEEDS alternative-gh-token-secret_name - API limits need to be for whatever token is used for upload/download. Repo token may be a different pool for rate limits.
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
- name: C++ tests
run: ${{ inputs.script }}
run: ${{ inputs.script }} # zizmor: ignore[template-injection]
env:
# NEEDS alternative-gh-token-secret-name - may require a token with more permissions
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
- name: Generate test report
uses: test-summary/action@v2.4
uses: test-summary/action@31493c76ec9e7aa675f1585d3ed6f1da69269a86 # v2.4
with:
paths: "${{ env.RAPIDS_TESTS_DIR }}/*.xml"
if: always()
Expand Down
13 changes: 8 additions & 5 deletions .github/workflows/conda-python-build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -112,7 +112,7 @@ jobs:
env:
RAPIDS_BUILD_TYPE: ${{ inputs.build_type }}
steps:
- uses: aws-actions/configure-aws-credentials@v4
- uses: aws-actions/configure-aws-credentials@b47578312673ae6fa5b5096b330d9fbac3d116df # v4.2.1
with:
role-to-assume: ${{ vars.AWS_ROLE_ARN }}
aws-region: ${{ vars.AWS_REGION }}
Expand All @@ -122,6 +122,7 @@ jobs:
repository: ${{ inputs.repo }}
ref: ${{ inputs.sha }}
fetch-depth: 0
persist-credentials: true
- name: Standardize repository information
env:
RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }}
Expand Down Expand Up @@ -158,12 +159,12 @@ jobs:
fi
env:
# NEEDS alternative-gh-token-secret_name - API limits need to be for whatever token is used for upload/download. Repo token may be a different pool for rate limits.
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
- name: Python build
run: ${{ inputs.script }}
run: ${{ inputs.script }} # zizmor: ignore[template-injection]
env:
# NEEDS alternative-gh-token-secret-name - may require a token with more permissions
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
- name: Get Package Name and Location
if: ${{ inputs.upload-artifacts }}
run: |
Expand All @@ -172,9 +173,11 @@ jobs:
id: package-name
- name: Show files to be uploaded
if: ${{ inputs.upload-artifacts }}
env:
CONDA_OUTPUT_DIR: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }}
run: |
echo "Contents of directory to be uploaded:"
ls -R ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }}
ls -R "${CONDA_OUTPUT_DIR}"
- uses: actions/upload-artifact@v4
if: ${{ inputs.upload-artifacts }}
with:
Expand Down
11 changes: 6 additions & 5 deletions .github/workflows/conda-python-tests.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -159,7 +159,7 @@ jobs:
RAPIDS_BUILD_TYPE: ${{ inputs.build_type }}
NVIDIA_VISIBLE_DEVICES: ${{ env.NVIDIA_VISIBLE_DEVICES }}
steps:
- uses: aws-actions/configure-aws-credentials@v4
- uses: aws-actions/configure-aws-credentials@b47578312673ae6fa5b5096b330d9fbac3d116df # v4.2.1
with:
role-to-assume: ${{ vars.AWS_ROLE_ARN }}
aws-region: ${{ vars.AWS_REGION }}
Expand All @@ -170,6 +170,7 @@ jobs:
repository: ${{ inputs.repo }}
ref: ${{ inputs.sha }}
fetch-depth: 0
persist-credentials: true

- name: Standardize repository information
uses: rapidsai/shared-actions/rapids-github-info@main
Expand Down Expand Up @@ -209,14 +210,14 @@ jobs:
fi
env:
# NEEDS alternative-gh-token-secret_name - API limits need to be for whatever token is used for upload/download. Repo token may be a different pool for rate limits.
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
- name: Python tests
run: ${{ inputs.script }}
run: ${{ inputs.script }} # zizmor: ignore[template-injection]
env:
# NEEDS alternative-gh-token-secret-name - may require a token with more permissions
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
- name: Generate test report
uses: test-summary/action@v2.4
uses: test-summary/action@31493c76ec9e7aa675f1585d3ed6f1da69269a86 # v2.4
with:
paths: "${{ env.RAPIDS_TESTS_DIR }}/*.xml"
if: always()
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/conda-upload-packages.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ jobs:
upload:
runs-on: linux-amd64-cpu4
container:
image: rapidsai/ci-conda:25.08-latest
image: rapidsai/ci-conda:25.08-latest # zizmor: ignore[unpinned-images]
env:
RAPIDS_BUILD_TYPE: ${{ inputs.build_type }}
steps:
Expand All @@ -59,12 +59,12 @@ jobs:
if: ${{ vars.TELEMETRY_ENABLED == 'true' }}
env:
GH_TOKEN: ${{ github.token }}

- uses: actions/checkout@v4
with:
repository: ${{ inputs.repo }}
ref: ${{ inputs.sha }}
fetch-depth: 0
persist-credentials: true

- name: Standardize repository information
env:
Expand Down
14 changes: 8 additions & 6 deletions .github/workflows/custom-job.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -80,12 +80,12 @@ jobs:
runs-on: "linux-${{ inputs.arch }}-${{ inputs.node_type }}"
continue-on-error: ${{ inputs.continue-on-error }}
container:
image: ${{ inputs.container_image }}
image: ${{ inputs.container_image }} # zizmor: ignore[unpinned-images]
env:
RAPIDS_BUILD_TYPE: ${{ inputs.build_type }}
NVIDIA_VISIBLE_DEVICES: ${{ env.NVIDIA_VISIBLE_DEVICES }}
steps:
- uses: aws-actions/configure-aws-credentials@v4
- uses: aws-actions/configure-aws-credentials@b47578312673ae6fa5b5096b330d9fbac3d116df # v4.2.1
with:
role-to-assume: ${{ vars.AWS_ROLE_ARN }}
aws-region: ${{ vars.AWS_REGION }}
Expand All @@ -95,6 +95,7 @@ jobs:
repository: ${{ inputs.repo }}
ref: ${{ inputs.sha }}
fetch-depth: 0
persist-credentials: true
- name: Telemetry setup
uses: rapidsai/shared-actions/telemetry-dispatch-setup@main
continue-on-error: true
Expand All @@ -108,7 +109,7 @@ jobs:
uses: nv-gha-runners/get-pr-info@main
- name: Add PR Info
if: startsWith(github.ref_name, 'pull-request/')
run: |
run: | # zizmor: ignore[template-injection]
echo "RAPIDS_BASE_BRANCH=${{ fromJSON(steps.get-pr-info.outputs.pr-info).base.ref }}" >> "${GITHUB_ENV}"
- name: Standardize repository information
uses: rapidsai/shared-actions/rapids-github-info@main
Expand All @@ -131,12 +132,13 @@ jobs:
fi
env:
# NEEDS alternative-gh-token-secret_name - API limits need to be for whatever token is used for upload/download. Repo token may be a different pool for rate limits.
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
- name: Run script
run: ${{ inputs.script }}
run: ${INPUTS_SCRIPT}
env:
# NEEDS alternative-gh-token-secret-name - may require a token with more permissions
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }}
GH_TOKEN: ${{ inputs.alternative-gh-token-secret-name && secrets[inputs.alternative-gh-token-secret-name] || github.token }} # zizmor: ignore[overprovisioned-secrets]
INPUTS_SCRIPT: ${{ inputs.script }}
- name: Upload file to GitHub Artifact
uses: actions/upload-artifact@v4
with:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/pr-builder.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ jobs:
uses: actions/checkout@v4
with:
fetch-depth: 1
persist-credentials: false
- name: Check for private token usage
env:
ERROR_MSG: "PR validation failed: Private token access is not allowed to be merged onto the development branch. Remove any uses of input 'alternative-gh-token-secret-name'."
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/project-get-set-iteration-field.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -142,4 +142,5 @@ jobs:
UPDATE_FIELD_TYPE: "iteration"
UPDATE_FIELD_ID: ${{ inputs.ITERATION_FIELD_ID }}
UPDATE_FIELD_VALUE: ${{ needs.get_set_iteration_option_id.outputs.ITERATION_OPTION_ID }}
secrets: inherit
secrets:
ADD_TO_PROJECT_GITHUB_TOKEN: ${{ secrets.ADD_TO_PROJECT_GITHUB_TOKEN }}
Original file line number Diff line number Diff line change
Expand Up @@ -164,4 +164,5 @@ jobs:
UPDATE_FIELD_TYPE: "single_select"
UPDATE_FIELD_ID: ${{ inputs.SINGLE_SELECT_FIELD_ID }}
UPDATE_FIELD_VALUE: ${{ needs.get_set_single_select_option_id.outputs.SINGLE_SELECT_OPTION_ID }}
secrets: inherit
secrets:
ADD_TO_PROJECT_GITHUB_TOKEN: ${{ secrets.ADD_TO_PROJECT_GITHUB_TOKEN }}
Original file line number Diff line number Diff line change
Expand Up @@ -134,4 +134,5 @@ jobs:
UPDATE_FIELD_TYPE: ${{inputs.FIELD_TYPE}}
UPDATE_FIELD_ID: ${{ inputs.FIELD_ID }}
UPDATE_FIELD_VALUE: ${{ inputs.SET_VALUE }}
secrets: inherit
secrets:
ADD_TO_PROJECT_GITHUB_TOKEN: ${{ secrets.ADD_TO_PROJECT_GITHUB_TOKEN }}
Loading