From e2b98d0b3153bc96a51b6402dc8fa82c598b5ee7 Mon Sep 17 00:00:00 2001 From: Ajin Abraham Date: Sun, 20 Sep 2026 18:25:47 -0700 Subject: [PATCH 1/3] Bump yara-python-dex to 2.0.0 and fix wheel publishing Unique per-job artifact names are required after upload-artifact v4, which is why 1.0.9 never reached PyPI. Enable CPython prereleases and Dependabot so new Python versions land with cibuildwheel updates. Co-authored-by: Cursor --- .github/dependabot.yml | 6 ++ .github/workflows/build_arm.yml | 66 --------------------- .github/workflows/build_publish.yml | 91 +++++++++++++---------------- .github/workflows/build_test.yml | 37 ++++-------- .github/workflows/test.yml | 34 ++++++----- pyproject.toml | 9 +++ setup.py | 2 +- 7 files changed, 87 insertions(+), 158 deletions(-) create mode 100644 .github/dependabot.yml delete mode 100644 .github/workflows/build_arm.yml create mode 100644 pyproject.toml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..ca79ca5 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,6 @@ +version: 2 +updates: + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly diff --git a/.github/workflows/build_arm.yml b/.github/workflows/build_arm.yml deleted file mode 100644 index 1a4d3e6..0000000 --- a/.github/workflows/build_arm.yml +++ /dev/null @@ -1,66 +0,0 @@ -name: Build & Publish aarch64 Linux -on: - release: - types: [created] -jobs: - build_wheels: - name: Build wheels on ${{ matrix.os }} - runs-on: ${{ matrix.os }} - strategy: - matrix: - include: - # - os: ubuntu-latest - # cibw_archs: "native" - - os: ubuntu-latest - cibw_archs: "aarch64" - # - os: windows-latest - # cibw_archs: "native ARM64" - # - os: macos-latest - # cibw_archs: "native arm64" - - steps: - - name: Set up QEMU - if: matrix.cibw_archs == 'aarch64' - uses: docker/setup-qemu-action@v2 - with: - platforms: arm64 - - uses: actions/checkout@v5.0.0 - - uses: actions/setup-python@v5.3.0 - name: Install Python - - name: Get submodules - run: git submodule update --init --recursive - - name: Build wheels - uses: pypa/cibuildwheel@v4.2.1 - env: - CIBW_ARCHS: ${{ matrix.cibw_archs }} - CIBW_SKIP: "pp*" - CIBW_ENABLE: "pypy pypy-eol" - - uses: actions/upload-artifact@v4.6.2 - with: - name: wheels - path: ./wheelhouse/*.whl - - publish: - needs: build_wheels - name: Publish to PyPI - runs-on: ubuntu-latest - - steps: - - name: Set up Python - uses: actions/setup-python@v5.6.0 - with: - python-version: '3.x' - - name: Install twine - run: | - python -m pip install --upgrade pip - pip install twine - - name: Download Artifacts - uses: actions/download-artifact@v5.0.0 - with: - name: wheels - path: ./wheelhouse - - name: Publish - env: - TWINE_USERNAME: ${{ secrets.PYPI_USERNAME }} - TWINE_PASSWORD: ${{ secrets.PYPI_PASSWORD }} - run: twine upload ./wheelhouse/* --skip-existing diff --git a/.github/workflows/build_publish.yml b/.github/workflows/build_publish.yml index 1d844a6..b68ed0b 100644 --- a/.github/workflows/build_publish.yml +++ b/.github/workflows/build_publish.yml @@ -4,69 +4,58 @@ on: release: types: [created] +permissions: + contents: read + jobs: build: name: Build wheels on ${{ matrix.os }} runs-on: ${{ matrix.os }} strategy: + fail-fast: false matrix: - os: [ubuntu-latest, windows-latest, macOS-latest] + os: [ubuntu-latest, ubuntu-24.04-arm, windows-latest, macos-latest] steps: - - uses: actions/checkout@v5.0.0 + - uses: actions/checkout@v7.0.1 + with: + submodules: recursive + persist-credentials: false - - uses: actions/setup-python@v5.6.0 - name: Install Python + - name: Build wheels + uses: pypa/cibuildwheel@v4.2.1 - - name: Install cibuildwheel - run: python -m pip install cibuildwheel==4.2.1 - - - name: Get submodules - run: git submodule update --init --recursive + - uses: actions/upload-artifact@v7.0.1 + with: + name: wheels-${{ matrix.os }} + path: ./wheelhouse/*.whl + if-no-files-found: error - - name: Build wheels for Windows - if: startsWith(matrix.os, 'windows') - run: | - python -m cibuildwheel --output-dir wheels - env: - CIBW_SKIP: "cp27-* pp27-*" # skip Python 2.7 wheels - CIBW_ENABLE: "pypy pypy-eol" - - - name: Build wheels for mac and manylinux - if: "!startsWith(matrix.os, 'windows')" - run: | - python -m cibuildwheel --output-dir wheels - env: - CIBW_ARCHS_MACOS: "auto auto32 x86_64 universal2 arm64" - CIBW_ENABLE: "pypy pypy-eol" + publish: + needs: build + name: Publish to PyPI + runs-on: ubuntu-latest - - uses: actions/upload-artifact@v4.6.2 - name: Upload wheels + steps: + - name: Set up Python + uses: actions/setup-python@v7.0.0 with: - name: wheels - path: ./wheels/*.whl + python-version: "3.x" - publish: - needs: build - name: Publish to PyPI - runs-on: ubuntu-latest + - name: Install twine + run: | + python -m pip install --upgrade pip + pip install twine - steps: - - name: Set up Python - uses: actions/setup-python@v5.3.0 - with: - python-version: '3.x' - - name: Install twine - run: | - python -m pip install --upgrade pip - pip install twine - - name: Download Artifacts - uses: actions/download-artifact@v5.0.0 - with: - name: wheels - path: ./wheels - - name: Publish - env: - TWINE_USERNAME: ${{ secrets.PYPI_USERNAME }} - TWINE_PASSWORD: ${{ secrets.PYPI_PASSWORD }} - run: twine upload ./wheels/* --skip-existing + - name: Download Artifacts + uses: actions/download-artifact@v8.0.1 + with: + pattern: wheels-* + path: ./wheels + merge-multiple: true + + - name: Publish + env: + TWINE_USERNAME: ${{ secrets.PYPI_USERNAME }} + TWINE_PASSWORD: ${{ secrets.PYPI_PASSWORD }} + run: twine upload ./wheels/* --skip-existing diff --git a/.github/workflows/build_test.yml b/.github/workflows/build_test.yml index 236dbbc..674066b 100644 --- a/.github/workflows/build_test.yml +++ b/.github/workflows/build_test.yml @@ -2,38 +2,23 @@ name: Build Test on: [push, pull_request] +permissions: + contents: read + jobs: build: name: Build wheels on ${{ matrix.os }} runs-on: ${{ matrix.os }} strategy: + fail-fast: false matrix: - os: [ubuntu-latest, windows-latest, macOS-latest] + os: [ubuntu-latest, ubuntu-24.04-arm, windows-latest, macos-latest] steps: - - uses: actions/checkout@v5.0.0 - - - uses: actions/setup-python@v5.6.0 - name: Install Python - - - name: Install cibuildwheel - run: python -m pip install cibuildwheel==4.2.1 - - - name: Get submodules - run: git submodule update --init --recursive + - uses: actions/checkout@v7.0.1 + with: + submodules: recursive + persist-credentials: false - - name: Build wheels for Windows - if: startsWith(matrix.os, 'windows') - run: | - python -m cibuildwheel --output-dir wheels - env: - CIBW_SKIP: "cp27-* pp27-*" # skip Python 2.7 wheels - CIBW_ENABLE: "pypy pypy-eol" - - - name: Build wheels for mac and manylinux - if: "!startsWith(matrix.os, 'windows')" - run: | - python -m cibuildwheel --output-dir wheels - env: - CIBW_ARCHS_MACOS: "auto auto32 x86_64 universal2 arm64" - CIBW_ENABLE: "pypy pypy-eol" + - name: Build wheels + uses: pypa/cibuildwheel@v4.2.1 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 27c07cf..9a0024c 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -2,22 +2,28 @@ name: Test on: [push, pull_request] +permissions: + contents: read + jobs: test: - runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5.0.0 - - name: Set up Python - uses: actions/setup-python@v5.6.0 - with: - python-version: '3.x' - - name: Install dependencies - run: | - python -m pip install --upgrade pip - pip install setuptools wheel - - name: Build - run: | - git submodule update --init --recursive - python setup.py bdist_wheel + - uses: actions/checkout@v7.0.1 + with: + submodules: recursive + persist-credentials: false + + - name: Set up Python + uses: actions/setup-python@v7.0.0 + with: + python-version: "3.x" + + - name: Install dependencies + run: | + python -m pip install --upgrade pip + pip install setuptools wheel + + - name: Build + run: python setup.py bdist_wheel diff --git a/pyproject.toml b/pyproject.toml new file mode 100644 index 0000000..8e12c1d --- /dev/null +++ b/pyproject.toml @@ -0,0 +1,9 @@ +[tool.cibuildwheel] +# Build CPython betas/RCs when cibuildwheel ships them. Stable new CPython +# versions land automatically once Dependabot bumps pypa/cibuildwheel. +enable = ["cpython-prerelease", "pypy", "pypy-eol"] +# 32-bit is no longer in the default manylinux images used by cibuildwheel 4. +skip = ["*-win32", "*_i686"] + +[tool.cibuildwheel.macos] +archs = ["x86_64", "arm64"] diff --git a/setup.py b/setup.py index d2833a9..d5ecfcc 100644 --- a/setup.py +++ b/setup.py @@ -315,7 +315,7 @@ def run(self): setup( name='yara-python-dex', - version='1.0.9', + version='2.0.0', description='Python interface for YARA', long_description=readme, long_description_content_type='text/markdown', From 05544dfacd43111e25b5209e7cd714355131bc25 Mon Sep 17 00:00:00 2001 From: Ajin Abraham Date: Sun, 20 Sep 2026 18:27:59 -0700 Subject: [PATCH 2/3] Version 1.1.0 and switch PyPI uploads to trusted publishing Drop long-lived PyPI credentials in favor of OIDC via gh-action-pypi-publish and a dedicated pypi environment. Co-authored-by: Cursor --- .github/workflows/build_publish.yml | 31 ++++++++++++++--------------- setup.py | 2 +- 2 files changed, 16 insertions(+), 17 deletions(-) diff --git a/.github/workflows/build_publish.yml b/.github/workflows/build_publish.yml index b68ed0b..af0a441 100644 --- a/.github/workflows/build_publish.yml +++ b/.github/workflows/build_publish.yml @@ -35,27 +35,26 @@ jobs: needs: build name: Publish to PyPI runs-on: ubuntu-latest + environment: + name: pypi + url: https://pypi.org/project/yara-python-dex/ + permissions: + id-token: write + contents: read + actions: read steps: - - name: Set up Python - uses: actions/setup-python@v7.0.0 - with: - python-version: "3.x" - - - name: Install twine - run: | - python -m pip install --upgrade pip - pip install twine - - name: Download Artifacts uses: actions/download-artifact@v8.0.1 with: pattern: wheels-* - path: ./wheels + path: dist merge-multiple: true - - name: Publish - env: - TWINE_USERNAME: ${{ secrets.PYPI_USERNAME }} - TWINE_PASSWORD: ${{ secrets.PYPI_PASSWORD }} - run: twine upload ./wheels/* --skip-existing + - name: Publish package distributions to PyPI + uses: pypa/gh-action-pypi-publish@v1.14.2 + with: + # Many native wheels plus Sigstore attestations can exceed GitHub's + # ~5 minute OIDC token lifetime. + attestations: false + skip-existing: true diff --git a/setup.py b/setup.py index d5ecfcc..ae99655 100644 --- a/setup.py +++ b/setup.py @@ -315,7 +315,7 @@ def run(self): setup( name='yara-python-dex', - version='2.0.0', + version='1.1.0', description='Python interface for YARA', long_description=readme, long_description_content_type='text/markdown', From c28983cf4ba559c7d81f612a795dfbe738d8b8a5 Mon Sep 17 00:00:00 2001 From: Ajin Abraham Date: Sun, 20 Sep 2026 18:37:57 -0700 Subject: [PATCH 3/3] Pin GitHub Actions to immutable commit SHAs Tags already matched the latest releases; pinning the commit hashes stops a retagged action from changing under us while Dependabot can still bump the SHA and version comment. Co-authored-by: Cursor --- .github/workflows/build_publish.yml | 10 +++++----- .github/workflows/build_test.yml | 4 ++-- .github/workflows/test.yml | 4 ++-- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/workflows/build_publish.yml b/.github/workflows/build_publish.yml index af0a441..e5d2c30 100644 --- a/.github/workflows/build_publish.yml +++ b/.github/workflows/build_publish.yml @@ -17,15 +17,15 @@ jobs: os: [ubuntu-latest, ubuntu-24.04-arm, windows-latest, macos-latest] steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive persist-credentials: false - name: Build wheels - uses: pypa/cibuildwheel@v4.2.1 + uses: pypa/cibuildwheel@e090b81e30c4d855ea63bf4b6e59204c09a101ae # v4.2.1 - - uses: actions/upload-artifact@v7.0.1 + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: wheels-${{ matrix.os }} path: ./wheelhouse/*.whl @@ -45,14 +45,14 @@ jobs: steps: - name: Download Artifacts - uses: actions/download-artifact@v8.0.1 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: pattern: wheels-* path: dist merge-multiple: true - name: Publish package distributions to PyPI - uses: pypa/gh-action-pypi-publish@v1.14.2 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 with: # Many native wheels plus Sigstore attestations can exceed GitHub's # ~5 minute OIDC token lifetime. diff --git a/.github/workflows/build_test.yml b/.github/workflows/build_test.yml index 674066b..c359a60 100644 --- a/.github/workflows/build_test.yml +++ b/.github/workflows/build_test.yml @@ -15,10 +15,10 @@ jobs: os: [ubuntu-latest, ubuntu-24.04-arm, windows-latest, macos-latest] steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive persist-credentials: false - name: Build wheels - uses: pypa/cibuildwheel@v4.2.1 + uses: pypa/cibuildwheel@e090b81e30c4d855ea63bf4b6e59204c09a101ae # v4.2.1 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 9a0024c..43ed995 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -10,13 +10,13 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: recursive persist-credentials: false - name: Set up Python - uses: actions/setup-python@v7.0.0 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.x"