Copilot commented on code in PR #838:
URL: https://github.com/apache/iceberg-cpp/pull/838#discussion_r3636953503
##########
.github/workflows/cpp-linter.yml:
##########
@@ -91,24 +96,40 @@ jobs:
with:
path: ${{ github.workspace }}/.sccache
key: sccache-cpp-linter-ubuntu-${{ github.run_id }}
- - uses:
cpp-linter/cpp-linter-action@0f6d1b8d7e38b584cbee606eb23d850c217d54f8 # v2.15.1
+ - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 #
v6.3.0
+ if: github.event_name == 'pull_request'
+ with:
+ python-version: '3.13'
+ - name: Install cpp-linter and clang tools
+ if: github.event_name == 'pull_request'
+ run: |
+ python -m pip install --upgrade pip
+ python -m pip install "cpp-linter==${CPP_LINTER_VERSION}"
"clang-format==${CLANG_FORMAT_VERSION}" "clang-tidy==${CLANG_TIDY_VERSION}"
Review Comment:
This introduces new runtime supply-chain dependencies via PyPI downloads in
CI. If your project’s security posture requires tighter controls, consider
adding a constraints/lock approach (e.g., a `requirements.txt`/constraints file
with hashes and `--require-hashes`) so CI installs are reproducible and
resistant to dependency substitution.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]