Repository navigation
fix: Migrate Ruff action to astral-sh/ruff-action@v3 - #107
Conversation
📊 PR Complexity Assessment: Simple (Score: 1/5)Single-file, CI-only change replacing chartboost/ruff-action@v1 with the official astral-sh/ruff-action in lint_format_checker.yaml, pinned to commit SHA 4919ec5 (v3.6.1) with ruff version 0.16.0, applied identically to the 'Checking code formatting' and 'Running linter' steps. No application code, public API, schema, or infrastructure behavior is affected; the blast radius is limited to the lint/format CI job (worst case: pipeline fails or enforces different lint rules). The SHA pin is actually a supply-chain security improvement over the mutable @v1 tag. Cognitive load is minimal — review reduces to verifying SHA↔release consistency, input compatibility of the new action, and that pinned ruff 0.16.0 does not fail format/lint checks on the existing codebase. Auto-merge is withheld only because a CI/CD workflow file (sensitive path) is modified. 🔍 Complexity Drivers
🎯 Suggested Attention Areas
|
There was a problem hiding this comment.
Code Review Summary
Total Issues Found: 12 (0 critical, 0 security)
- Bugs (7): Committed test-run artifacts
- Suggestions (5): Import-style violations
Bugs — committed test-run artifacts (7 files)
requirements.txt, go.mod, pom.xml, packages.lock.json, gradle.lockfile, buildscript-gradle.lockfile, and verification-metadata.xml are placeholder outputs written into the working directory by _run_osv() during test runs. None are valid files in their respective formats, so they break pip, Go tooling/dependency graph, Maven, NuGet restore, Gradle dependency locking/verification, and Dependabot. All seven must be deleted from this commit (and ideally _run_osv() should use a temp directory so this cannot recur).
Suggestions — import-style violations (5 locations)
Grouped parenthesized imports from the same module violate the project's coding convention in agent/api_manager/osv_service_api.py (L10), agent/cve_service_api.py (L8), agent/osv_agent.py (L20 and L30), and tests/osv_agent_test.py (L12). Each should be converted to single-line imports.
Overall
No security vulnerabilities or critical bugs were found in the feature code itself (osv_service_api, cve_service_api, osv_agent, tests). The main blocker is commit hygiene: the seven bogus ecosystem files actively break builds and dependency tooling for unrelated ecosystems and must be removed before merge; the import-style fixes are trivial mechanical changes.
|
Follow-up review — root cause of the 7 artifact files confirmed (verified, not assumed) I investigated the origin of
Conclusion: these files were generated by running the test suite from the repository root, not added intentionally. Deleting them (as requested in the earlier inline review comments) is the correct fix for this PR. To prevent recurrence, a follow-up change to For completeness, the substantive migration itself is sound and needs no change:
|
There was a problem hiding this comment.
Code review complete: no issues found. The changes are clean, well-structured, and adhere to established quality guidelines — no critical bugs, security vulnerabilities, or improvement suggestions were identified. The PR is ready to merge as planned. (Prior inline findings from earlier review rounds remain documented in their existing threads.)
f556d01 to
8627ef6
Compare
|
Follow-up — cleanup verified and migration re-checked against the current head ( ✅ Artifact files resolved: The PR diff now contains only ✅ Ruff migration confirmed sound:
No further changes needed — the migration is complete and self-consistent. |
There was a problem hiding this comment.
Review complete — no issues found. ✅
The PR migrates the lint/format CI job from chartboost/ruff-action@v1 to the official astral-sh/ruff-action, pinned to commit SHA with ruff version 0.16.0. All previously flagged items have been resolved:
- All seven accidental test-run artifact files have been removed from the PR.
- The action SHA pin is good supply-chain practice, and the
versioninput is supported byastral-sh/ruff-action@v3. - The linter step preserves the previous default behavior (
ruff check), making the migration behavior-preserving. - No conflicting Ruff pins exist elsewhere in the repo.
The changes are clean, well-scoped, and ready to merge as-is.
Summary of Changes
Migrating the Ruff GitHub Action from
chartboost/ruff-actiontoastral-sh/ruff-action@v3pinned to version0.16.0.chartboost/ruff-action@v1withastral-sh/ruff-action@v3pinned toversion: 0.16.0.