From bc21cd3d3f3052e87fea95f2c8dbed9e447fb391 Mon Sep 17 00:00:00 2001 From: Ryan Ahearn Date: Tue, 3 Jan 2023 09:43:32 -0500 Subject: [PATCH 1/2] Remove restart: always from devcontainer --- docker-compose.devcontainer.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/docker-compose.devcontainer.yml b/docker-compose.devcontainer.yml index 62bdfad51..d08ca2972 100644 --- a/docker-compose.devcontainer.yml +++ b/docker-compose.devcontainer.yml @@ -48,7 +48,6 @@ services: - redis links: - db - restart: always worker: container_name: worker image: dev-notification-api From 7e02e6b33d5629cc097a6e299d6da825bcd4d958 Mon Sep 17 00:00:00 2001 From: Ryan Ahearn Date: Tue, 3 Jan 2023 09:44:53 -0500 Subject: [PATCH 2/2] Update to most recent pip-audit action --- .github/workflows/checks.yml | 2 +- .github/workflows/daily_checks.yml | 2 +- Makefile | 4 ++-- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/checks.yml b/.github/workflows/checks.yml index 9143504a4..0d3ca945a 100644 --- a/.github/workflows/checks.yml +++ b/.github/workflows/checks.yml @@ -60,7 +60,7 @@ jobs: - uses: ./.github/actions/setup-project - name: Create requirements.txt run: pipenv requirements > requirements.txt - - uses: trailofbits/gh-action-pip-audit@v1.0.0 + - uses: pypa/gh-action-pip-audit@v1.0.4 with: inputs: requirements.txt ignore-vulns: PYSEC-2022-237 diff --git a/.github/workflows/daily_checks.yml b/.github/workflows/daily_checks.yml index c0b981b7c..34cef2173 100644 --- a/.github/workflows/daily_checks.yml +++ b/.github/workflows/daily_checks.yml @@ -29,7 +29,7 @@ jobs: - uses: ./.github/actions/setup-project - name: Create requirements.txt run: pipenv requirements > requirements.txt - - uses: trailofbits/gh-action-pip-audit@v1.0.0 + - uses: pypa/gh-action-pip-audit@v1.0.4 with: inputs: requirements.txt ignore-vulns: PYSEC-2022-237 diff --git a/Makefile b/Makefile index 9ced0aaa5..9b22547bc 100644 --- a/Makefile +++ b/Makefile @@ -66,8 +66,8 @@ freeze-requirements: ## Pin all requirements including sub dependencies into req audit: pipenv requirements > requirements.txt pipenv requirements --dev > requirements_for_test.txt - pipenv run pip-audit -r requirements.txt -l --ignore-vuln PYSEC-2022-237 - -pipenv run pip-audit -r requirements_for_test.txt -l + pipenv run pip-audit -r requirements.txt --ignore-vuln PYSEC-2022-237 + -pipenv run pip-audit -r requirements_for_test.txt .PHONY: static-scan static-scan: