Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions .bandit
Original file line number Diff line number Diff line change
@@ -1,2 +1,19 @@
# Bandit configuration. This file — not the pre-commit hook's args — is the
# single source of truth for bandit's scope, because it is the only part any
# other runner can see. CodeFactor, IDE plugins and a contributor typing
# `bandit -r .` all read `.bandit` and none of them read our hook args, so
# scope kept in the args made every external analyser disagree with CI (#1493).
#
# Both spellings of each path are listed deliberately. Bandit matches an
# exclude entry against the path string it is handed, and that string depends on
# how it was invoked: a recursive `bandit -r .` discovers `./tests/foo.py`,
# whereas pre-commit passes `tests/foo.py`. So `./tests` alone silently covers
# only the recursive case and `tests` alone only the pre-commit case — a
# one-spelling list looks correct and half-works. Verified in
# tests/security/test_security_patterns.py, which runs bandit both ways.
#
# Note these are *added* to bandit's own defaults (.git, __pycache__, .tox,
# .eggs, …), so those need no repeating here.
[bandit]
exclude = tests,./tests,.venv,./.venv
skips = B101
17 changes: 17 additions & 0 deletions .github/CONFIG.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,3 +61,20 @@ optional depending on which release features you use:
| `UV_EXTRA_INDEX_URL` | Extra package index URL (with credentials) for private dependencies. |

`GITHUB_TOKEN` is provided automatically by GitHub Actions and needs no configuration.

`GH_PAT` and `UV_EXTRA_INDEX_URL` are read by the CI, benchmark, CodeQL, marimo, book,
weekly and docker workflows too. The stubs that call those reusable workflows forward each secret by
name rather than with `secrets: inherit`, because GitHub only honours `inherit` when the
caller sits in the same organisation or enterprise as `jebel-quant/rhiza` — from any other
organisation the secrets simply never arrived, and private dependencies failed to install
with `could not read Password for 'https://***@github.com'` (#1689). A secret that is not
defined is forwarded empty and the workflow falls back to `github.token`, so nothing is
required for a project with no private dependencies. Pull requests from forks never receive
secrets at all, so a fork PR that needs a private dependency fails at install; that is
GitHub's rule rather than a rhiza setting.

The docker workflow is the one place the runner's git configuration cannot reach, because
`uv sync` runs inside the image build. It passes both secrets to `docker buildx build` as
BuildKit secrets instead, which exist only for that one instruction and are written into no
layer; a build argument would be readable with `docker history` (#1691). See
`docs/development/DOCKER.md` for building such an image locally.
25 changes: 0 additions & 25 deletions .github/DISCUSSION_TEMPLATE/q-and-a.yml

This file was deleted.

57 changes: 0 additions & 57 deletions .github/ISSUE_TEMPLATE/bug_report.yml

This file was deleted.

41 changes: 0 additions & 41 deletions .github/ISSUE_TEMPLATE/feature_request.yml

This file was deleted.

24 changes: 0 additions & 24 deletions .github/pull_request_template.md

This file was deleted.

1 change: 0 additions & 1 deletion .github/secret_scanning.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,6 @@

paths-ignore:
# Ignore test fixtures that may contain example/fake secrets
- ".rhiza/tests/**"
- "tests/**"
# Ignore documentation that references example tokens/keys
- "docs/**/*.md"
Expand Down
9 changes: 7 additions & 2 deletions .github/workflows/rhiza_benchmark.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,5 +20,10 @@ on:

jobs:
benchmark:
uses: jebel-quant/rhiza/.github/workflows/rhiza_benchmark.yml@v0.19.9
secrets: inherit
uses: jebel-quant/rhiza/.github/workflows/rhiza_benchmark.yml@v1.9.0
# Forwarded explicitly: `secrets: inherit` only reaches a reusable workflow in the
# caller's own organisation or enterprise (#1689). A secret this repository has not
# defined arrives empty and the workflow falls back to `github.token`.
secrets:
GH_PAT: ${{ secrets.GH_PAT }}
UV_EXTRA_INDEX_URL: ${{ secrets.UV_EXTRA_INDEX_URL }}
27 changes: 22 additions & 5 deletions .github/workflows/rhiza_book.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,10 @@
# It combines API documentation, test coverage reports, test results, and
# interactive notebooks into a single GitHub Pages site.
#
# Trigger: This workflow runs on every push to the main or master branch
# Trigger: This workflow runs on every push (any branch), so every commit
# validates that the book still builds. The reusable workflow deploys
# to GitHub Pages only from the repository's default branch and never
# from a fork; other branches build and upload an artifact only.
#
# Components:
# - 📓 Process Marimo notebooks
Expand All @@ -19,14 +22,28 @@ name: "(RHIZA) BOOK"
on:
push:
branches:
- main
- master
- '**'

permissions:
contents: read

jobs:
book:
uses: jebel-quant/rhiza/.github/workflows/rhiza_book.yml@v0.19.9
secrets: inherit
uses: jebel-quant/rhiza/.github/workflows/rhiza_book.yml@v1.9.0
# Forwarded explicitly: `secrets: inherit` only reaches a reusable workflow in the
# caller's own organisation or enterprise (#1689). A secret this repository has not
# defined arrives empty and the workflow falls back to `github.token`.
secrets:
GH_PAT: ${{ secrets.GH_PAT }}
UV_EXTRA_INDEX_URL: ${{ secrets.UV_EXTRA_INDEX_URL }}
permissions:
contents: read
pages: write
id-token: write
# Set `deploy-pages: false` for artifact-only mode -- the reusable workflow
# still uploads the generic `book` artifact, and a consumer-owned job below
# can download it and deploy to Cloudflare Pages, Azure Static Web Apps,
# S3/CloudFront, an internal web server, etc. See docs/guides/BOOK.md for a
# full Cloudflare Pages example.
# with:
# deploy-pages: false
14 changes: 12 additions & 2 deletions .github/workflows/rhiza_ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,11 @@
# pre-commit hooks, verify documentation coverage, validate the
# project, run security scans, and check license compliance.
#
# Python version matrix source of truth:
# - Implemented in the reusable workflow called below
# - Generated from `Programming Language :: Python :: 3.x` classifiers in pyproject.toml
# - Adding/removing classifiers updates CI Python coverage automatically
#
# Trigger: On push and pull_request.

name: "(RHIZA) CI"
Expand All @@ -21,5 +26,10 @@ on:

jobs:
ci:
uses: jebel-quant/rhiza/.github/workflows/rhiza_ci.yml@v0.19.9
secrets: inherit
uses: jebel-quant/rhiza/.github/workflows/rhiza_ci.yml@v1.9.0
# Forwarded explicitly: `secrets: inherit` only reaches a reusable workflow in the
# caller's own organisation or enterprise (#1689). A secret this repository has not
# defined arrives empty and the workflow falls back to `github.token`.
secrets:
GH_PAT: ${{ secrets.GH_PAT }}
UV_EXTRA_INDEX_URL: ${{ secrets.UV_EXTRA_INDEX_URL }}
16 changes: 11 additions & 5 deletions .github/workflows/rhiza_codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,6 @@
name: "(RHIZA) CODEQL"

permissions:
security-events: write
packages: read
actions: read
contents: read

on:
Expand All @@ -29,5 +26,14 @@ on:

jobs:
codeql:
uses: jebel-quant/rhiza/.github/workflows/rhiza_codeql.yml@v0.19.9
secrets: inherit
uses: jebel-quant/rhiza/.github/workflows/rhiza_codeql.yml@v1.9.0
# Forwarded explicitly: `secrets: inherit` only reaches a reusable workflow in the
# caller's own organisation or enterprise (#1689). A secret this repository has not
# defined arrives empty and the workflow falls back to `github.token`.
secrets:
GH_PAT: ${{ secrets.GH_PAT }}
permissions:
security-events: write # Upload CodeQL results to code scanning
packages: read
actions: read
contents: read
9 changes: 7 additions & 2 deletions .github/workflows/rhiza_marimo.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,5 +28,10 @@ on:

jobs:
marimo:
uses: jebel-quant/rhiza/.github/workflows/rhiza_marimo.yml@v0.19.9
secrets: inherit
uses: jebel-quant/rhiza/.github/workflows/rhiza_marimo.yml@v1.9.0
# Forwarded explicitly: `secrets: inherit` only reaches a reusable workflow in the
# caller's own organisation or enterprise (#1689). A secret this repository has not
# defined arrives empty and the workflow falls back to `github.token`.
secrets:
GH_PAT: ${{ secrets.GH_PAT }}
UV_EXTRA_INDEX_URL: ${{ secrets.UV_EXTRA_INDEX_URL }}
Loading
Loading